Johnnyluv | 24.04.2020 17:52 | Hallo Matthias,
vielen Dank für deine Hilfe und für die Tipps, ich werde in Zukunft darauf achten.
- "eine Rückmeldung bezüglich der Deinstallationen"
Hat ohne Probleme funktioniert, ist alles deinstalliert.
- "die Logdatei von MBAM" Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 24.04.20
Scan-Zeit: 18:28
Protokolldatei: 960fec9e-8648-11ea-bdd7-e09d31d14c2c.json
-Softwaredaten-
Version: 4.1.0.56
Komponentenversion: 1.0.875
Version des Aktualisierungspakets: 1.0.22882
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 18362.778)
CPU: x64
Dateisystem: NTFS
Benutzer: LAPTOP-09D6LV55\Johnny
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 310291
Erkannte Bedrohungen: 10
In die Quarantäne verschobene Bedrohungen: 10
Abgelaufene Zeit: 1 Min., 58 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 4
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{DECAED7B-7E72-4FDD-90EA-58E0DE621D14}, In Quarantäne, 3947, 396863, , , ,
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-566858545-3733993882-2579075607-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{DECAED7B-7E72-4FDD-90EA-58E0DE621D14}, In Quarantäne, 3947, 396863, 1.0.22882, , ame,
PUP.Optional.InstallCore, HKU\S-1-5-21-566858545-3733993882-2579075607-1001\SOFTWARE\CSASTATS\ic, In Quarantäne, 494, 586068, 1.0.22882, , ame,
PUP.Optional.StartPage, HKLM\SOFTWARE\Websuche, In Quarantäne, 241, 463409, 1.0.22882, , ame,
Registrierungswert: 4
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-566858545-3733993882-2579075607-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{DECAED7B-7E72-4FDD-90EA-58E0DE621D14}|FAVICONURL, In Quarantäne, 3947, 396863, 1.0.22882, , ame,
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-566858545-3733993882-2579075607-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{DECAED7B-7E72-4FDD-90EA-58E0DE621D14}|URL, In Quarantäne, 3947, 396863, 1.0.22882, , ame,
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{DECAED7B-7E72-4FDD-90EA-58E0DE621D14}|FAVICONURL, In Quarantäne, 3947, 396862, 1.0.22882, , ame,
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{DECAED7B-7E72-4FDD-90EA-58E0DE621D14}|URL, In Quarantäne, 3947, 396862, 1.0.22882, , ame,
Registrierungsdaten: 1
PUP.Optional.StartPage.ShrtCln, HKU\S-1-5-21-566858545-3733993882-2579075607-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Ersetzt, 3947, 395422, 1.0.22882, , ame,
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 1
PUP.Optional.ChipDe, C:\USERS\JOHNNY\DOWNLOADS\4K VIDEO DOWNLOADER - CHIP-INSTALLER.EXE, In Quarantäne, 584, 562568, 1.0.22882, , ame,
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) - "die Logdatei von AdwCleaner" Code:
# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build: 04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 04-24-2020
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 6
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Users\Johnny\AppData\Local\Temp\DMR
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\PRODUCTSETUP
Deleted HKCU\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G
Deleted HKCU\Software\ProductSetup\Uninstall\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F
Deleted HKCU\Software\csastats
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
Deleted banggood.com
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete IFEO
[+] Delete Prefetch
[+] Delete Tracing Keys
[+] Reset Chromium Policies
[+] Reset IE Policies
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [5876 octets] - [24/04/2020 18:36:36]
AdwCleaner[S01].txt - [5937 octets] - [24/04/2020 18:39:27]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ########## - "die beiden neuen Logdateien von FRST (FRST.txt und Addition.txt)"
FRST Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 24-04-2020
durchgeführt von Johnny (Administrator) auf LAPTOP-09D6LV55 (HP HP Laptop 15-bs1xx) (24-04-2020 18:45:06)
Gestartet von C:\Users\Johnny\Desktop
Geladene Profile: Johnny (Verfügbare Profile: Johnny)
Platform: Windows 10 Home Version 1903 18362.778 (X64) Sprache: Deutsch (Deutschland)
Standard-Browser: Chrome
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc. -> Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
(DigiDNA) [Datei ist nicht signiert] C:\Program Files\DigiDNA\iMazing\iMazing Mini.exe
(F.lux Software LLC -> f.lux Software LLC) C:\Users\Johnny\AppData\Local\FluxSoftware\Flux\flux.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <43>
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
(HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131191.inf_amd64_d668106cb6f2eae0\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131191.inf_amd64_d668106cb6f2eae0\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131191.inf_amd64_d668106cb6f2eae0\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131191.inf_amd64_d668106cb6f2eae0\IntelCpHeciSvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Kilonova LLC -> Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.4\Lightshot.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Malwarebytes Inc -> Malwarebytes) C:\Users\Johnny\Desktop\adwcleaner_8.0.4.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1910.0.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12624.20368.0_x64__8wekyb3d8bbwe\HxCalendarAppImm.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12624.20368.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\schtasks.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
(WildTangent Inc -> ) C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9277520 2019-06-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-12-09] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [703312 2017-07-21] (HP Inc. -> HP Inc.)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226728 2019-07-22] (Kilonova LLC -> )
HKU\S-1-5-21-566858545-3733993882-2579075607-1001\...\Run: [f.lux] => C:\Users\Johnny\AppData\Local\FluxSoftware\Flux\flux.exe [1385480 2019-08-30] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-566858545-3733993882-2579075607-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2019-01-15] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-566858545-3733993882-2579075607-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2019-01-15] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-566858545-3733993882-2579075607-1001\...\Run: [CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [144008 2019-10-22] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-566858545-3733993882-2579075607-1001\...\Run: [iMazing-Mini] => C:\Program Files\DigiDNA\iMazing\iMazing Mini.exe [1892352 2019-11-27] (DigiDNA) [Datei ist nicht signiert]
HKU\S-1-5-21-566858545-3733993882-2579075607-1001\...\Run: [GoogleChromeAutoLaunch_1C45F4B9BC0ED7C28760616498EACFD1] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
HKU\S-1-5-21-566858545-3733993882-2579075607-1001\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5 --flag-switches-begin --flag-switches-end --enable-audio-service-sandbox --flag-switches-begin --flag-switc (Der Dateneintrag hat 61 mehr Zeichen).
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.122\Installer\chrmstp.exe [2020-04-24] (Google LLC -> Google LLC)
Startup: C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2019-01-17]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar579.lnk [2019-12-04]
ShortcutTarget: Sidebar579.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) [Datei ist nicht signiert]
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {01FDB195-4556-44FA-8762-6EA79A138F00} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {0D99F6A8-AD60-47A5-8412-86DC65ECF584} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe
Task: {13EC595A-A6FC-4D05-A22D-43147190653D} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [468992 2019-06-12] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {161D3544-B477-4FB6-88E0-A9F89C02E046} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [816960 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {1A3A2F28-0D15-4BCF-93A5-99AB61AD50EA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [317816 2020-04-09] (HP Inc. -> HP Inc.)
Task: {1E81B93F-DC05-44B2-BCCB-3F4AB0265B7B} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [115448 2020-04-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {28B0CB0B-3CF9-4C93-A5A7-2F98E9017170} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1117048 2020-03-26] (HP Inc. -> HP Inc.)
Task: {2C79DD75-C0AB-4704-9489-AF0356143521} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24702832 2020-04-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {3786216A-0638-4489-9E45-2D1438B9383E} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs]
Task: {4006639C-1EAE-4321-853B-060809D1052A} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [468992 2019-06-12] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
Task: {46AC1570-B554-4742-BDA4-8F6707613CE3} - System32\Tasks\HPJumpStartLaunch => C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe [461824 2017-10-06] (HP Inc. -> HP Inc.)
Task: {4D91CF2F-77F6-49A2-B011-031F5E632886} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {4F37742E-46FC-45C9-92BA-60BCC61691EC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-06] (Google Inc -> Google Inc.)
Task: {5581BAB0-AE1D-456B-8A31-04F168656F87} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [52104 2017-05-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {56415A83-ACA9-4503-8725-84902D8D3525} - System32\Tasks\HPCeeScheduleForJohnny => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97656 2018-09-11] (HP Inc. -> HP Inc.)
Task: {5751B6E8-ADE2-4F4C-ADBE-A609E3C41110} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644472 2019-06-21] (HP Inc. -> HP Inc.)
Task: {5D8DDB7F-F368-4C8B-869E-5E63886F637D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1506680 2019-06-14] (HP Inc. -> HP Inc.)
Task: {6ACEE893-0AD4-43D7-B23C-C0950DD88194} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1660520 2020-02-27] (Avast Software s.r.o. -> Avast Software)
Task: {741A067C-146B-4068-9555-A945D5BFFCAC} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2017-09-27] (HP Inc. -> HP Inc.)
Task: {85B6548D-46C1-4C0A-9DB9-045F945F1E98} - System32\Tasks\update-S-1-5-21-566858545-3733993882-2579075607-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
Task: {8907DF49-C0A5-41E4-A5C8-B40C2FFD321D} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [115448 2020-04-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {8AC353A8-AD67-4C13-A844-FFA0BFC95C84} - System32\Tasks\G2MUpdateTask-S-1-5-21-566858545-3733993882-2579075607-1001 => C:\Users\Johnny\AppData\Local\GoToMeeting\17359\g2mupdate.exe [32256 2020-04-09] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {8B3C9AF1-6AF2-48B3-8D5A-7742A0F0D6EC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {8C8793AF-8316-46D0-B9D1-89154096F80D} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>)
Task: {A651DB92-0F30-4555-9FBA-BBC810088363} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [655736 2019-07-31] (HP Inc. -> HP Inc.)
Task: {A744720E-C757-4777-85EA-2330A79DEF49} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1506680 2019-06-14] (HP Inc. -> HP Inc.)
Task: {D4817824-3851-4EDD-8798-AD2EC49B2720} - System32\Tasks\G2MUploadTask-S-1-5-21-566858545-3733993882-2579075607-1001 => C:\Users\Johnny\AppData\Local\GoToMeeting\17359\g2mupload.exe [32256 2020-04-09] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {D836ABB4-C055-4C83-8C38-71E63FA27D85} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24702832 2020-04-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {DA5280AA-9047-4861-B4B2-A42C422F012C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-06-06] (Google Inc -> Google Inc.)
Task: {E1D2A683-199F-4A78-B4E3-55639EB00EA3} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1448320 2020-04-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {E5F70BE5-3D5B-4558-BD27-B73CF5AA3C15} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1117048 2020-03-26] (HP Inc. -> HP Inc.)
Task: {EBD5BC0E-45B0-44D2-89AD-3A4A1ABF0602} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [134008 2020-03-25] (HP Inc. -> HP Inc.)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-566858545-3733993882-2579075607-1001.job => C:\Users\Johnny\AppData\Local\GoToMeeting\17359\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-566858545-3733993882-2579075607-1001.job => C:\Users\Johnny\AppData\Local\GoToMeeting\17359\g2mupload.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForJohnny.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\update-S-1-5-21-566858545-3733993882-2579075607-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{359c2653-31bc-4e64-8556-72a08ca879ed}: [DhcpNameServer] 192.168.42.1
Tcpip\..\Interfaces\{91c2924f-f81c-4f1a-9f2f-f19b1ee68bc2}: [DhcpNameServer] 192.168.49.1
Tcpip\..\Interfaces\{ea970d57-9f33-42c0-96de-56b1292dc412}: [DhcpNameServer] 134.108.34.5 134.108.34.6
Tcpip\..\Interfaces\{fae6def0-23cd-4352-87c4-86ab5571028a}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-566858545-3733993882-2579075607-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
SearchScopes: HKLM -> DefaultScope {DECAED7B-7E72-4FDD-90EA-58E0DE621D14} URL =
SearchScopes: HKLM -> {D105352C-315B-4A94-8DA3-3A468030C9AE} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {D105352C-315B-4A94-8DA3-3A468030C9AE} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-566858545-3733993882-2579075607-1001 -> DefaultScope {DECAED7B-7E72-4FDD-90EA-58E0DE621D14} URL =
SearchScopes: HKU\S-1-5-21-566858545-3733993882-2579075607-1001 -> {D105352C-315B-4A94-8DA3-3A468030C9AE} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-11] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre-10.0.2\bin\ssv.dll => Keine Datei
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre-10.0.2\bin\jp2ssv.dll [2019-01-26] (Oracle America, Inc. -> Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2017-10-27] (HP Inc. -> HP Inc.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2017-10-27] (HP Inc. -> HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-10] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=13.0.2.0 -> C:\Program Files\Java\jre-10.0.2\bin\dtplugin\npDeployJava1.dll [2019-01-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=13.0.2.0 -> C:\Program Files\Java\jre-10.0.2\bin\plugin2\npjp2.dll [2019-01-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-11] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default [2020-04-24]
CHR Notifications: Default -> hxxps://app.spocket.co; hxxps://vidlox.tv; hxxps://www.youtube.com
CHR Extension: (Präsentationen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-06-06]
CHR Extension: (Docs) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-06-06]
CHR Extension: (Google Drive) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-06-06]
CHR Extension: (YouTube) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-06-06]
CHR Extension: (AliPrice Preis-Tracker - AliExpress) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccinledjceanimdkflfafdpoljflhbjf [2020-04-15]
CHR Extension: (Adobe Acrobat) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-03-04]
CHR Extension: (Facebook Pixel Helper) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgfkebogiimcoedlicjlajpkdmockpc [2020-02-11]
CHR Extension: (Tabellen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-06-06]
CHR Extension: (Google Docs Offline) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-22]
CHR Extension: (AdBlock*– der beste Ad-Blocker) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-04-14]
CHR Extension: (Pexgle - Hunt Winning Products Toolkit) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\gphjjfiadngdfchoeimfdlpnhhjmddid [2020-04-08]
CHR Extension: (Oberlo - Aliexpress.com Product Importer) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmanipjnbjnhoicdnooapcnfonebefel [2020-03-21]
CHR Extension: (SimilarWeb - Traffic Rank & Website Analysis) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoklmmgfnpapgjgcpechhaamimifchmp [2020-04-11]
CHR Extension: (Commerce Inspector) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\kefmekfmfacbdefimlancoccpocmgmpb [2020-04-11]
CHR Extension: (Remove YouTube Recommended Videos, Comments) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\khncfooichmfjbepaaaebmommgaepoid [2020-04-24]
CHR Extension: (Jungle Scout: Extension Lite) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfgpfhoadcpndoogjiogflmgegfbekec [2020-04-24]
CHR Extension: (Volume Booster) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpgdpmdfeoojlmnghobelcepkcmdiepf [2020-02-05]
CHR Extension: (Autofill) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmmgnhgdeffjkdckmikfpnddkbbfkkk [2018-10-31]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2020-04-22]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-05]
CHR Extension: (Ali Epacket) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\onanhgahgihhhhjppnopocjglpbplkbc [2019-11-27]
CHR Extension: (Google Mail) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-30]
CHR Extension: (Chrome Media Router) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-22]
CHR Profile: C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-10-18]
CHR Extension: (Präsentationen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-03]
CHR Extension: (Docs) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-10-03]
CHR Extension: (Google Drive) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-03]
CHR Extension: (YouTube) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-10-03]
CHR Extension: (Adobe Acrobat) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-10-03]
CHR Extension: (Tabellen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-10-03]
CHR Extension: (Google Docs Offline) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-08]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-10-03]
CHR Extension: (Google Mail) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-10-03]
CHR Extension: (Chrome Media Router) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-03]
CHR Profile: C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2 [2018-10-18]
CHR Extension: (Präsentationen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-18]
CHR Extension: (Docs) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2018-10-18]
CHR Extension: (Google Drive) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-18]
CHR Extension: (YouTube) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-10-18]
CHR Extension: (Adobe Acrobat) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-10-18]
CHR Extension: (Tabellen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-10-18]
CHR Extension: (Google Docs Offline) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-10-18]
CHR Extension: (Google Mail) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-10-18]
CHR Extension: (Chrome Media Router) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-18]
CHR Profile: C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-10-18]
CHR Extension: (Präsentationen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-18]
CHR Extension: (Docs) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2018-10-18]
CHR Extension: (Google Drive) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-18]
CHR Extension: (YouTube) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-10-18]
CHR Extension: (Adobe Acrobat) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-10-18]
CHR Extension: (Tabellen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-10-18]
CHR Extension: (Google Docs Offline) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-10-18]
CHR Extension: (Google Mail) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-10-18]
CHR Extension: (Chrome Media Router) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-18]
CHR Profile: C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4 [2018-10-18]
CHR Extension: (Präsentationen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-18]
CHR Extension: (Docs) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2018-10-18]
CHR Extension: (Google Drive) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-18]
CHR Extension: (YouTube) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-10-18]
CHR Extension: (Adobe Acrobat) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-10-18]
CHR Extension: (Tabellen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-10-18]
CHR Extension: (Google Docs Offline) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-10-18]
CHR Extension: (Google Mail) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-10-18]
CHR Extension: (Chrome Media Router) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-18]
CHR Profile: C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5 [2018-10-18]
CHR Extension: (Präsentationen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-18]
CHR Extension: (Docs) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\aohghmighlieiainnegkcijnfilokake [2018-10-18]
CHR Extension: (Google Drive) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-18]
CHR Extension: (YouTube) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-10-18]
CHR Extension: (Adobe Acrobat) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-10-18]
CHR Extension: (Tabellen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-10-18]
CHR Extension: (Google Docs Offline) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-10-18]
CHR Extension: (Google Mail) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-10-18]
CHR Extension: (Chrome Media Router) - C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-18]
CHR Profile: C:\Users\Johnny\AppData\Local\Google\Chrome\User Data\System Profile [2019-08-26]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
==================== Dienste (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3374160 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3103824 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [560528 2017-09-16] (Advanced Micro Devices, Inc. -> AMD)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-10-07] (Apple Inc. -> Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [10626648 2020-04-10] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [780928 2018-06-07] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 ElfoService; C:\Program Files (x86)\ElsterFormular Update Service\bin\elfoService.exe [1284360 2019-09-11] (Bayerisches Landesamt fuer Steuern -> )
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [1701480 2017-09-13] (Intel Corporation -> Intel Corporation)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1327400 2017-09-05] (HP Inc. -> HP Inc.)
R2 HPJumpStartBridge; c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [477184 2017-10-06] (HP Inc. -> HP Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (Hewlett-Packard Company -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [378744 2020-03-31] (HP Inc. -> HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 ibtsiva; C:\WINDOWS\System32\ibtsiva.exe [536864 2020-01-06] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [197264 2017-09-25] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-04-24] (Malwarebytes Inc -> Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2018-09-05] (Intel Corporation -> )
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [32384 2017-10-26] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [267552 2019-06-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 SynTPEnhService; C:\WINDOWS\System32\SynTPEnhService.exe [382008 2019-08-15] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\NisSrv.exe [3304992 2020-04-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [1642800 2020-04-02] (WildTangent Inc -> )
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2004.6-0\MsMpEng.exe [103376 2020-04-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4059744 2018-09-05] (Intel Corporation -> Intel® Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0316945.inf_amd64_6fec47b12068b77c\atikmdag.sys [36577168 2017-09-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0316945.inf_amd64_6fec47b12068b77c\atikmpag.sys [537992 2017-09-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [69560 2017-09-13] (Intel Corporation -> Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [382392 2017-09-13] (Intel Corporation -> Intel Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-04-24] (Malwarebytes Corporation -> Malwarebytes)
R0 iaStorAC; C:\WINDOWS\System32\drivers\iaStorAC.sys [1096192 2019-08-12] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R3 ibtusb; C:\WINDOWS\System32\drivers\ibtusb.sys [199192 2018-05-11] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-04-24] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-04-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [195432 2020-04-24] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2020-04-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-04-24] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [124560 2020-04-24] (Malwarebytes Inc -> Malwarebytes)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [8720384 2019-08-27] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1009128 2017-08-25] (Realtek Semiconductor Corp. -> Realtek )
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [420832 2017-09-21] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [45144 2017-10-20] (Synaptics Incorporated -> Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [49208 2019-08-15] (Synaptics Incorporated -> Synaptics Incorporated)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R3 VBAudioVACMME; C:\WINDOWS\System32\drivers\vbaudio_cable64_win7.sys [41192 2014-09-02] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win7.sys [41192 2018-11-05] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-04-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [394680 2020-04-21] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [64944 2020-04-21] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [35392 2019-11-15] (HP Inc. -> HP)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat (erstellte) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2020-04-24 18:43 - 2020-04-24 18:43 - 002282496 _____ (Farbar) C:\Users\Johnny\Desktop\Nicht bestätigt 559396.crdownload
2020-04-24 18:43 - 2020-04-24 18:43 - 000000000 ___DC C:\Users\Johnny\Desktop\FRST-OlderVersion
2020-04-24 18:40 - 2020-04-24 18:40 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-04-24 18:40 - 2020-04-24 18:40 - 000195432 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-04-24 18:40 - 2020-04-24 18:40 - 000124560 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-04-24 18:40 - 2020-04-24 18:40 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-04-24 18:40 - 2020-04-24 18:40 - 000000000 ___DC C:\Users\Johnny\AppData\LocalLow\IGDump
2020-04-24 18:35 - 2020-04-24 18:40 - 000000000 ____D C:\AdwCleaner
2020-04-24 18:35 - 2020-04-24 18:35 - 008196784 _____ (Malwarebytes) C:\Users\Johnny\Desktop\adwcleaner_8.0.4.exe
2020-04-24 18:34 - 2020-04-24 18:34 - 000003049 ____C C:\Users\Johnny\Desktop\mbam.txt
2020-04-24 18:26 - 2020-04-24 18:26 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-04-24 18:26 - 2020-04-24 18:26 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-04-24 18:26 - 2020-04-24 18:26 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-04-24 18:26 - 2020-04-24 18:26 - 000002040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-04-24 18:26 - 2020-04-24 18:26 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-04-24 18:26 - 2020-04-24 18:26 - 000002028 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-04-24 18:26 - 2020-04-24 18:26 - 000000000 ____D C:\Users\Johnny\AppData\Local\mbamtray
2020-04-24 18:26 - 2020-04-24 18:26 - 000000000 ____D C:\Users\Johnny\AppData\Local\mbam
2020-04-24 18:26 - 2020-04-24 18:26 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-04-24 18:25 - 2020-04-24 18:25 - 001980016 _____ (Malwarebytes) C:\Users\Johnny\Desktop\MBSetup.exe
2020-04-24 18:25 - 2020-04-24 18:25 - 000000000 ____D C:\Program Files\Malwarebytes
2020-04-24 18:17 - 2020-04-24 18:17 - 010651216 _____ (McAfee, LLC.) C:\Users\Johnny\Desktop\MCPR.exe
2020-04-23 19:34 - 2020-04-23 19:38 - 000000000 ___DC C:\Users\Johnny\Desktop\sparda bank konto auszug
2020-04-21 21:24 - 2020-04-21 21:24 - 000014594 _____ C:\Users\Johnny\AppData\Local\recently-used.xbel
2020-04-20 11:14 - 2020-04-20 11:18 - 000052236 ____C C:\Users\Johnny\Desktop\Addition.txt
2020-04-20 11:13 - 2020-04-24 18:45 - 000043481 ____C C:\Users\Johnny\Desktop\FRST.txt
2020-04-20 11:13 - 2020-04-24 18:45 - 000000000 ____D C:\FRST
2020-04-20 11:12 - 2020-04-24 18:43 - 002282496 _____ (Farbar) C:\Users\Johnny\Desktop\FRST64.exe
2020-04-20 11:07 - 2020-04-20 11:07 - 000000000 ___DC C:\Users\Johnny\Desktop\malware
2020-04-19 00:10 - 2020-04-19 00:10 - 000000000 ___DC C:\Users\Johnny\Desktop\hammock
2020-04-18 15:48 - 2020-04-23 22:03 - 000000000 ___DC C:\Users\Johnny\Desktop\Easysewy
2020-04-18 08:38 - 2020-04-18 08:38 - 000000000 ____D C:\WINDOWS\Panther
2020-04-17 17:00 - 2020-04-19 20:33 - 000000000 ___DC C:\Users\Johnny\Desktop\paw
2020-04-17 11:11 - 2020-04-17 11:11 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 004129624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 002951832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 002494744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 001870408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 001013000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 000420152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2020-04-17 11:11 - 2020-04-17 11:11 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2020-04-17 11:11 - 2020-04-17 11:11 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 022636544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 018027520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 017790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 014818816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 008013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 007849216 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 007756800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 007017472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 006523048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 005910016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 004611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 004563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 003802624 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 003753472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 003742544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 003708928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 003587384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 003547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 003512320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 003109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 002767928 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 002717184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 002453504 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 002180408 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 002131456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 002126144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 002114560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 002086656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001999960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001960448 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001764336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-04-17 11:10 - 2020-04-17 11:10 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001665216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001656904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001646048 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001612800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001603584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001545216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 001512832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 001497600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 001477112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001427456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001397576 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 001378528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001300280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 001263856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 001261808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001243648 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001153024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001136128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001127424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001077064 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001011200 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 001008128 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000982840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000974336 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000915192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000892416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000879616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000811320 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000785920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000775696 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000768528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000759272 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000684560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000673704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000673464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000638480 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000637240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000628616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000618296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2020-04-17 11:10 - 2020-04-17 11:10 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000538160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000515600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000513576 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000510792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000491008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000487784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-04-17 11:10 - 2020-04-17 11:10 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000459688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2020-04-17 11:10 - 2020-04-17 11:10 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000437560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000416016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\es.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000381440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000339304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\es.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000297272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000277864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000268008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000259776 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000251704 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrad.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000231912 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000190048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrad.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000185952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000178192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000151352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000147696 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000127280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000123952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000089912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000089336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasacct.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000066624 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasacct.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumapi.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudNotifications.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000059192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000058880 _____ C:\WINDOWS\system32\runexehelper.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumapi.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000050544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\iaspolcy.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iaspolcy.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcProxyStubs.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000033080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hwpolicy.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ias.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmintegrator.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\flpydisk.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ias.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.ps.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000021520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sfloppy.sys
2020-04-17 11:10 - 2020-04-17 11:10 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wksprtPS.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsunattend.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.ps.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2020-04-17 11:10 - 2020-04-17 11:10 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-04-17 11:10 - 2020-04-17 11:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-04-17 11:04 - 2020-04-17 11:04 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-04-17 11:04 - 2020-04-17 11:04 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-04-15 20:18 - 2020-04-15 20:19 - 000000000 ___DC C:\Users\Johnny\Desktop\Kette
2020-04-15 16:39 - 2020-04-15 16:39 - 001409045 _____ C:\Users\Johnny\Desktop\CJYDQTJM00127-Red.zip
2020-04-12 18:38 - 2020-04-12 18:38 - 005192280 _____ (Husdawg, LLC) C:\Users\Johnny\Downloads\Detection.exe
2020-04-11 20:39 - 2020-04-11 20:39 - 000014808 _____ C:\Users\Johnny\Desktop\2659205856_1765442121_720x.webp
2020-04-09 04:34 - 2020-04-09 04:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty Modern Warfare
2020-04-08 19:27 - 2020-04-08 19:27 - 000000000 ____D C:\Users\Johnny\AppData\Local\OneDrive
2020-04-08 19:18 - 2020-04-08 19:18 - 000000000 ____D C:\ProgramData\Blizzard Entertainment
2020-04-08 19:10 - 2020-04-08 19:15 - 000000000 ____D C:\Users\Johnny\AppData\Local\Blizzard Entertainment
2020-04-08 19:08 - 2020-04-08 19:08 - 004934824 _____ (Blizzard Entertainment) C:\Users\Johnny\Downloads\Modern-Warfare-Setup.exe
2020-04-08 19:08 - 2020-04-08 19:08 - 000000000 ____D C:\ProgramData\Battle.net
2020-04-04 11:38 - 2020-04-05 22:41 - 000000000 ___DC C:\Users\Johnny\Desktop\Ebay
2020-04-04 11:26 - 2020-04-04 11:27 - 000000000 ___DC C:\Users\Johnny\Desktop\adobe
2020-04-04 11:23 - 2020-04-04 11:24 - 000000000 ___DC C:\Users\Johnny\Desktop\Produkt versuche
2020-03-31 14:16 - 2020-04-20 22:11 - 000000000 ___DC C:\Users\Johnny\Desktop\Potenzielle Produkte
2020-03-27 18:11 - 2020-03-27 18:27 - 000001083 ____C C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\4K Video Downloader.lnk
2020-03-27 18:11 - 2020-03-27 18:11 - 000000936 ____C C:\Users\Johnny\Desktop\4K Video Downloader.lnk
2020-03-27 18:11 - 2020-03-27 18:11 - 000000000 ____D C:\Users\Johnny\AppData\Local\4kdownload.com
2020-03-27 18:11 - 2020-03-27 18:11 - 000000000 ____D C:\Program Files\4KDownload
2020-03-27 18:10 - 2020-03-27 18:10 - 000000000 ___DC C:\Users\Johnny\Desktop\4kvideodownloader_4.11.3
2020-03-27 18:09 - 2020-03-27 18:10 - 156228085 _____ C:\Users\Johnny\Downloads\4kvideodownloader_4.11.3.zip
2020-03-26 23:03 - 2020-04-23 22:45 - 000000000 ___DC C:\Users\Johnny\Desktop\Shopify Jewels
==================== Ein Monat (geänderte) ==================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2020-04-24 18:41 - 2019-12-25 14:20 - 000000000 ____D C:\Users\Johnny\AppData\Roaming\iMazing
2020-04-24 18:41 - 2019-03-06 12:51 - 000000000 ___RD C:\Users\Johnny\iCloudDrive
2020-04-24 18:41 - 2018-07-02 17:51 - 000000000 ___DC C:\Users\Johnny\AppData\Local\Adobe
2020-04-24 18:40 - 2019-12-04 13:22 - 000003114 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
2020-04-24 18:40 - 2019-12-04 13:22 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-24 18:40 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-24 18:40 - 2019-03-19 06:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2020-04-24 18:40 - 2018-06-06 20:22 - 000000000 __SHD C:\Users\Johnny\IntelGraphicsProfiles
2020-04-24 18:36 - 2019-12-04 13:22 - 001834716 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-24 18:36 - 2019-03-19 14:16 - 000788474 _____ C:\WINDOWS\system32\perfh007.dat
2020-04-24 18:36 - 2019-03-19 14:16 - 000168438 _____ C:\WINDOWS\system32\perfc007.dat
2020-04-24 18:36 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF
2020-04-24 18:26 - 2019-03-19 06:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-04-24 18:21 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-24 18:14 - 2018-06-07 16:54 - 000000368 _____ C:\WINDOWS\Tasks\HPCeeScheduleForJohnny.job
2020-04-24 18:13 - 2018-06-06 20:25 - 000002300 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-24 18:13 - 2018-06-06 20:25 - 000002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-24 18:13 - 2018-06-06 20:25 - 000002259 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-04-24 18:12 - 2019-12-04 13:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2020-04-24 18:12 - 2019-03-19 06:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-04-24 16:35 - 2019-12-04 13:11 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-24 16:27 - 2019-12-04 13:22 - 000003264 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForJohnny
2020-04-24 12:16 - 2019-10-03 09:43 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-04-23 23:58 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-22 08:09 - 2020-02-01 13:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2020-04-21 22:39 - 2019-06-19 17:26 - 000000000 ___DC C:\Users\Johnny\AppData\Local\babl-0.1
2020-04-21 21:24 - 2019-06-19 17:28 - 000000000 ___DC C:\Users\Johnny\AppData\Local\gtk-2.0
2020-04-21 08:17 - 2018-07-13 22:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-04-20 13:36 - 2018-07-10 16:35 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-04-19 15:29 - 2018-07-13 22:30 - 000000000 ___DC C:\Users\Johnny\AppData\Local\D3DSCache
2020-04-18 13:39 - 2020-02-28 16:51 - 000000000 ____D C:\Users\Johnny\AppData\Local\GoToMeeting
2020-04-18 08:38 - 2020-02-28 16:51 - 000000672 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-566858545-3733993882-2579075607-1001.job
2020-04-18 08:38 - 2020-02-28 16:51 - 000000576 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-566858545-3733993882-2579075607-1001.job
2020-04-18 08:38 - 2019-12-04 13:11 - 005136704 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-04-18 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-04-18 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-04-18 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-04-18 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-04-18 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\Provisioning
2020-04-18 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-04-17 11:13 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-04-16 13:21 - 2019-12-04 13:22 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-566858545-3733993882-2579075607-1001
2020-04-16 13:21 - 2019-12-04 13:15 - 000002389 ____C C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-04-16 13:21 - 2018-06-06 20:24 - 000000000 ___RD C:\Users\Johnny\OneDrive
2020-04-09 04:08 - 2020-02-28 16:51 - 000003842 _____ C:\WINDOWS\system32\Tasks\G2MUploadTask-S-1-5-21-566858545-3733993882-2579075607-1001
2020-04-09 04:08 - 2020-02-28 16:51 - 000003746 _____ C:\WINDOWS\system32\Tasks\G2MUpdateTask-S-1-5-21-566858545-3733993882-2579075607-1001
2020-04-06 21:31 - 2020-03-20 17:48 - 000000000 ___DC C:\Users\Johnny\Desktop\Fitness
2020-04-06 09:45 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-04-02 14:39 - 2020-01-28 12:23 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-03-27 19:00 - 2019-12-21 13:34 - 000000000 ____D C:\WINDOWS\Minidump
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ========
2018-11-05 17:12 - 2018-12-05 20:36 - 000004674 ____C () C:\Users\Johnny\AppData\Roaming\VoiceMeeterDefault.xml
2020-02-08 16:34 - 2020-02-08 16:35 - 000001456 _____ () C:\Users\Johnny\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2018-09-29 10:01 - 2018-11-14 13:04 - 000000820 ____C () C:\Users\Johnny\AppData\Local\oobelibMkey.log
2020-04-21 21:24 - 2020-04-21 21:24 - 000014594 _____ () C:\Users\Johnny\AppData\Local\recently-used.xbel
2020-01-13 20:45 - 2020-01-13 20:45 - 000000003 _____ () C:\Users\Johnny\AppData\Local\updater.log
2020-01-13 20:45 - 2020-01-13 20:45 - 000000424 _____ () C:\Users\Johnny\AppData\Local\UserProducts.xml
==================== SigCheck ============================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
==================== Ende von FRST.txt ======================== |