Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Auf Rechnung im Mailanhang geklickt (Zip + doc)

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 15.04.2016, 14:58   #16
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-15 15:46:17) Run:1
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKLM-x32\...\Run: [ReCycle Patch] => C:\Users\hauptaccount\Downloads\ReasonPatch(1).exe [184320 2016-02-18] ()
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chipaware] => C:\Users\hauptaccount\AppData\Local\Temp\Chip_cas\chip-concert.exe [166912 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [killingmidnight] => C:\Users\hauptaccount\AppData\Local\Temp\Killing-atomic\killing-inspection.exe [223744 2016-04-15] (Kerr-McGee company) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [kniteffect] => C:\Users\hauptaccount\AppData\Local\Temp\Knit-degree\knit_capture.exe [181248 2016-04-15] (NetZero APS) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe [205824 2016-04-13] (Walgreens Teams ) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [litigationattending] => C:\Users\hauptaccount\AppData\Local\Temp\Litigation-celebrity\litigationbrochure.exe [226296 2016-04-14] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [ltddirection] => C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe [242176 2016-04-14] (Rent-A-Wreck Soft) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [inrush-81] => C:\ProgramData\inrush-11\inrush-59.exe [797056 2016-04-15] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [influenceentrance] => C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe [191152 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [ltddirection] => C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe [242176 2016-04-14] (Rent-A-Wreck Soft) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe [205824 2016-04-13] (Walgreens Teams ) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [influenceentrance] => C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe [191152 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [kilobits-54] => C:\Users\hauptaccount\AppData\Roaming\kilobits-8\kilobits-58.exe [700416 2016-04-15] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: [] 
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\switcher-7.lnk [2016-04-15]
ShortcutTarget: switcher-7.lnk -> C:\Users\hauptaccount\AppData\Roaming\switcher-58\switcher-6.exe (IvoSoft)
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 07 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\System32\winrnr.dll"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "type", 1
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
HR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
C:\Users\hauptaccount\AppData\Roaming\kilobits-8
C:\Users\hauptaccount\AppData\Roaming\switcher-58
C:\ProgramData\hsupa-95
C:\ProgramData\inrush-11
C:\ProgramData\Avira
C:\Users\hauptaccount\AppData\Roaming\IObit
C:\ProgramData\IObit
C:\Program Files (x86)\IObit
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
cmd: netsh winsock reset
removeproxy:
emptytemp:
         
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ReCycle Patch => Wert erfolgreich entfernt
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 9 => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\chipaware => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\killingmidnight => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\kniteffect => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\manchesterbeastality => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\litigationattending => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\ltddirection => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\inrush-81 => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\influenceentrance => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ltddirection => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\manchesterbeastality => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\influenceentrance => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\kilobits-54 => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Wert erfolgreich entfernt
C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\switcher-7.lnk => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\switcher-58\switcher-6.exe => nicht gefunden.
Winsock: Catalog5 000000000001\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\system32\NLAapi.dll)
Winsock: Catalog5 000000000002\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\system32\napinsp.dll)
Winsock: Catalog5 000000000003\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\system32\pnrpnsp.dll)
Winsock: Catalog5 000000000004\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\system32\pnrpnsp.dll)
Winsock: Catalog5 000000000006\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\System32\mswsock.dll)
Winsock: Catalog5 000000000007\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\System32\winrnr.dll)
Firefox Proxy-Einstellungen wurden zurückgesetzt
FF NetworkProxy: "type", 1 => nicht gefunden
C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com => nicht gefunden.
HR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13] => Fehler: Kein automatisierter Fix für diesen Eintrag gefunden.
"C:\Users\hauptaccount\AppData\Roaming\kilobits-8" => nicht gefunden.
"C:\Users\hauptaccount\AppData\Roaming\switcher-58" => nicht gefunden.
"C:\ProgramData\hsupa-95" => nicht gefunden.
C:\ProgramData\inrush-11 => erfolgreich verschoben
C:\ProgramData\Avira => erfolgreich verschoben
"C:\Users\hauptaccount\AppData\Roaming\IObit" => nicht gefunden.

"C:\ProgramData\IObit" Ordner verschieben:

Konnte nicht verschoben werden "C:\ProgramData\IObit" => ist geplant bei Neustart verschoben zu werden.

C:\Program Files (x86)\IObit => erfolgreich verschoben

=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

15.04.2016  15:46    <DIR>          ..
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  15:46    <DIR>          .
15.04.2016  14:50    <DIR>          tdscdma-8
15.04.2016  14:23    <DIR>          kilobits-8
15.04.2016  14:20    <DIR>          IObit
15.04.2016  14:09    <DIR>          Wise Care 365
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
11.04.2016  21:14    <DIR>          Spotify
24.03.2016  16:09    <DIR>          vlc
22.03.2016  08:49    <DIR>          Dropbox
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
               0 Datei(en),              0 Bytes
              60 Verzeichnis(se), 110.443.196.416 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

15.04.2016  14:50    <DIR>          ..
15.04.2016  14:50    <DIR>          .
15.04.2016  14:50             1.030 tdscdma-00.lnk
               1 Datei(en),          1.030 Bytes
               2 Verzeichnis(se), 110.443.196.416 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

15.04.2016  15:46    <DIR>          ..
15.04.2016  15:46    <DIR>          .
15.04.2016  15:15    <DIR>          {BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:47    <DIR>          linear-0
15.04.2016  14:15    <DIR>          IObit
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
15.04.2016  10:41    <DIR>          Package Cache
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
30.03.2016  06:01    <DIR>          Origin
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:42    <DIR>          {FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11               133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
               2 Datei(en),            190 Bytes
              65 Verzeichnis(se), 110.443.192.320 Bytes frei

========= Ende von CMD: =========


=========  netsh winsock reset =========


Der Winsock-Katalog wurde zur�ckgesetzt.
Sie m�ssen den Computer neu starten, um den Vorgang abzuschlie�en.


========= Ende von CMD: =========


========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt


========= Ende von RemoveProxy: =========

EmptyTemp: => 6.4 GB temporäre Dateien entfernt.

Ergebnis der geplanten Datei-Verschiebungen (Start-Modus: Normal) (Datum&Uhrzeit: 2016-04-15 15:51:25)

C:\ProgramData\IObit => ist erfolgreich verschoben

==== Ende von Fixlog 15:51:26 ====
         

Alt 15.04.2016, 20:38   #17
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

__________________

__________________

Alt 16.04.2016, 12:37   #18
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (16-04-2016 13:31:38)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
() C:\Windows\SysWOW64\WinService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler64.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [523144 2015-09-07] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [doublers-63] => C:\ProgramData\doublers-9\doublers-80.exe [704688 2016-04-16] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [tempco-65] => C:\Users\hauptaccount\AppData\Roaming\tempco-5\tempco-23.exe [813056 2016-04-16] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe" 
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jugfet-9.lnk [2016-04-16]
ShortcutTarget: jugfet-9.lnk -> C:\Users\hauptaccount\AppData\Roaming\jugfet-7\jugfet-9.exe (IvoSoft)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S: 
FF SearchEngineOrder.1: 
FF SearchEngineOrder.1,S: 
FF SelectedSearchEngine,S: 
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome: 
=======
CHR HomePage: Default -> hxxp://feed.helperbar.com/?publisher=QuickOC&dpid=QuickOC&co=DE&userid=35e67f97-7787-40cf-897d-5c56a5625e15&searchtype=hp&installDate=
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1136520 2015-09-07] (Autodesk Inc.)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
R3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-16 12:41 - 2016-04-16 12:41 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\jugfet-7
2016-04-16 12:38 - 2016-04-16 12:38 - 00000000 ____D C:\ProgramData\gravity-7
2016-04-16 12:24 - 2016-04-16 12:24 - 00000000 ____D C:\ProgramData\doublers-9
2016-04-16 01:23 - 2016-04-16 01:23 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\tempco-5
2016-04-16 00:55 - 2016-04-16 12:41 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\sinad-4
2016-04-15 15:46 - 2016-04-15 15:51 - 00018131 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:15 - 2016-04-15 15:15 - 00000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-16 00:55 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\tdscdma-8
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:35 - 2016-04-15 14:36 - 00023394 _____ C:\Users\hauptaccount\Desktop\er (V.txt
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-16 13:31 - 00027518 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-12 12:40 - 2016-04-16 01:05 - 00082415 _____ C:\Users\hauptaccount\Desktop\Addition.txt
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-16 13:31 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:31 - 2016-04-12 12:31 - 02375168 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-03-24 16:09 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM(1).pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega
2016-03-21 22:52 - 2016-03-28 00:40 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt
2016-03-21 22:52 - 2016-03-21 22:52 - 00000208 _____ C:\Users\hauptaccount\Desktop\c.txt
2016-03-21 17:49 - 2016-03-21 17:50 - 00000000 ____D C:\Users\hauptaccount\Desktop\CYBERGAUNER
2016-03-21 17:35 - 2016-03-21 17:35 - 01596260 _____ C:\Users\hauptaccount\Downloads\flyer.pdf
2016-03-21 14:27 - 2016-03-21 14:28 - 08186625 _____ C:\Users\hauptaccount\Downloads\wordpress-4.4.2-de_DE.zip
2016-03-19 16:25 - 2016-03-19 16:25 - 00000000 ____D C:\Users\hauptaccount\Desktop\Neuer Ordner


==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-16 12:48 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-16 12:48 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-16 12:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-16 12:29 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-16 02:07 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-16 02:07 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-16 02:07 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-15 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-15 23:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-15 20:48 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-15 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:51 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-15 15:50 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-15 15:49 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 11:30 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-15 10:41 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-15 10:37 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-15 10:37 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-15 10:37 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-15 10:37 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-14 01:45 - 2010-11-17 16:33 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 22:46 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-11 21:14 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 21:26 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-21 15:35 - 2011-01-17 18:08 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Paint.NET

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-11 12:08

==================== Ende von FRST.txt ============================
         
__________________

Alt 16.04.2016, 12:38   #19
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-16 13:32:37)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.5 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {0549C0DB-913F-4411-B577-6A5D9C5D6CEB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {06AD79CF-3049-4E43-A011-BABF6A39B4DF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {0FE5D209-B132-4972-B77D-AC0A78A3FF06} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {11DDFDAD-C35F-4461-90F9-16E92773139F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {15EE9EF4-3824-44CA-8DE2-6C81AD1785D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {242E14E3-E262-42F4-8B7B-A16CC962477C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {29CA4BA7-9156-431C-88C7-69741974F3CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {406C9318-4C8B-41DE-8D30-9294CF6DC20F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {6B7FC54F-AB46-4C0A-BB70-AC855322E160} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {CDDBBD48-0D3F-480D-8456-4181DB66F45F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FE8EB787-034F-4677-8391-7FCC25426EED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-10-28 19:19 - 2015-09-07 05:33 - 00055688 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-10-28 19:19 - 2015-09-07 05:33 - 00104328 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 01675928 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libglesv2.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 00086168 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe

==================== Wiederherstellungspunkte =========================

24-03-2016 18:56:48 Windows Update
03-04-2016 15:49:10 Geplanter Prüfpunkt
12-04-2016 15:59:21 Geplanter Prüfpunkt
15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Renesas USB 3.0 eXtensible-Hostcontroller – 0.96 (Microsoft)
Description: USB-xHCI-kompatibler Hostcontroller
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Generischer USB-xHCI-Hostcontroller
Service: USBXHCI
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/16/2016 12:24:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: drypack-45.exe, Version: 0.0.0.0, Zeitstempel: 0x55614f0d
Name des fehlerhaften Moduls: drypack-45.exe, Version: 0.0.0.0, Zeitstempel: 0x55614f0d
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000046d3
ID des fehlerhaften Prozesses: 0x1750
Startzeit der fehlerhaften Anwendung: 0xdrypack-45.exe0
Pfad der fehlerhaften Anwendung: drypack-45.exe1
Pfad des fehlerhaften Moduls: drypack-45.exe2
Berichtskennung: drypack-45.exe3
Vollständiger Name des fehlerhaften Pakets: drypack-45.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: drypack-45.exe5

Error: (04/16/2016 01:38:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: drypack-45.exe, Version: 0.0.0.0, Zeitstempel: 0x55614f0d
Name des fehlerhaften Moduls: drypack-45.exe, Version: 0.0.0.0, Zeitstempel: 0x55614f0d
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000046d3
ID des fehlerhaften Prozesses: 0x2808
Startzeit der fehlerhaften Anwendung: 0xdrypack-45.exe0
Pfad der fehlerhaften Anwendung: drypack-45.exe1
Pfad des fehlerhaften Moduls: drypack-45.exe2
Berichtskennung: drypack-45.exe3
Vollständiger Name des fehlerhaften Pakets: drypack-45.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: drypack-45.exe5

Error: (04/16/2016 01:22:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: vacuole-71.exe, Version: 9.1.1.0, Zeitstempel: 0x55a6d806
Name des fehlerhaften Moduls: vacuole-71.exe, Version: 9.1.1.0, Zeitstempel: 0x55a6d806
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000033a3
ID des fehlerhaften Prozesses: 0xf4c
Startzeit der fehlerhaften Anwendung: 0xvacuole-71.exe0
Pfad der fehlerhaften Anwendung: vacuole-71.exe1
Pfad des fehlerhaften Moduls: vacuole-71.exe2
Berichtskennung: vacuole-71.exe3
Vollständiger Name des fehlerhaften Pakets: vacuole-71.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: vacuole-71.exe5

Error: (04/15/2016 03:55:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x177c
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5

Error: (04/15/2016 02:20:14 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/15/2016 02:15:02 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/15/2016 11:30:04 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/14/2016 05:48:07 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (04/14/2016 05:26:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm avscan.exe, Version 15.0.16.276 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1f08

Startzeit: 01d195846f8a0745

Beendigungszeit: 60000

Anwendungspfad: C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe

Berichts-ID: 15d47d51-0255-11e6-9bd6-001f3f0bea1d

Vollständiger Name des fehlerhaften Pakets: 

Auf das fehlerhafte Paket bezogene Anwendungs-ID:

Error: (04/14/2016 05:11:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 48222797


Systemfehler:
=============
Error: (04/16/2016 12:20:36 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.

Error: (04/16/2016 02:07:42 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_5e780" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/15/2016 03:50:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (04/15/2016 03:50:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (04/15/2016 03:50:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (04/15/2016 03:49:14 PM) (Source: DCOM) (EventID: 10010) (User: hauptaccount-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (04/15/2016 03:49:14 PM) (Source: DCOM) (EventID: 10010) (User: hauptaccount-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (04/15/2016 03:49:14 PM) (Source: DCOM) (EventID: 10010) (User: hauptaccount-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (04/15/2016 03:49:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_6793b" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/15/2016 03:18:32 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{3185A766-B338-11E4-A71E-12E3F512A338}{7006698D-2974-4091-A424-85DD0B909E23}NT-AUTORITÄTNetzwerkdienstS-1-5-20LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar


CodeIntegrity:
===================================
  Date: 2016-04-16 13:26:47.952
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:39.735
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.919
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.794
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.681
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.565
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.467
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.341
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.231
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.096
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen =========================== 

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 53%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 1921.65 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 5688.25 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:106.37 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.69 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================
         

Alt 17.04.2016, 10:55   #20
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [doublers-63] => C:\ProgramData\doublers-9\doublers-80.exe [704688 2016-04-16] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [tempco-65] => C:\Users\hauptaccount\AppData\Roaming\tempco-5\tempco-23.exe [813056 2016-04-16] ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jugfet-9.lnk [2016-04-16]
ShortcutTarget: jugfet-9.lnk -> C:\Users\hauptaccount\AppData\Roaming\jugfet-7\jugfet-9.exe (IvoSoft)
CHR HomePage: Default -> hxxp://feed.helperbar.com/?publisher=QuickOC&dpid=QuickOC&co=DE&userid=35e67f97-7787-40cf-897d-5c56a5625e15&searchtype=hp&installDate=
CHR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
Task: {0549C0DB-913F-4411-B577-6A5D9C5D6CEB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {06AD79CF-3049-4E43-A011-BABF6A39B4DF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {0FE5D209-B132-4972-B77D-AC0A78A3FF06} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {11DDFDAD-C35F-4461-90F9-16E92773139F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {15EE9EF4-3824-44CA-8DE2-6C81AD1785D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {242E14E3-E262-42F4-8B7B-A16CC962477C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {29CA4BA7-9156-431C-88C7-69741974F3CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {406C9318-4C8B-41DE-8D30-9294CF6DC20F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {6B7FC54F-AB46-4C0A-BB70-AC855322E160} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {CDDBBD48-0D3F-480D-8456-4181DB66F45F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {FE8EB787-034F-4677-8391-7FCC25426EED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
C:\Users\hauptaccount\AppData\Roaming\jugfet-7
C:\ProgramData\gravity-7
C:\ProgramData\doublers-9
C:\Users\hauptaccount\AppData\Roaming\tempco-5
C:\Users\hauptaccount\AppData\Roaming\sinad-4
C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
C:\Users\hauptaccount\AppData\Roaming\tempco-5
C:\ProgramData\doublers-9
C:\Users\hauptaccount\AppData\Roaming\tdscdma-8
C:\Users\hauptaccount\AppData\Roaming\kilobits-8
C:\ProgramData\linear-0
C:\ProgramData\IObit
cmd: del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


__________________
Logfiles bitte immer in CODE-Tags posten

Alt 17.04.2016, 16:10   #21
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-17 17:03:08) Run:2
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [doublers-63] => C:\ProgramData\doublers-9\doublers-80.exe [704688 2016-04-16] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [tempco-65] => C:\Users\hauptaccount\AppData\Roaming\tempco-5\tempco-23.exe [813056 2016-04-16] ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jugfet-9.lnk [2016-04-16]
ShortcutTarget: jugfet-9.lnk -> C:\Users\hauptaccount\AppData\Roaming\jugfet-7\jugfet-9.exe (IvoSoft)
CHR HomePage: Default -> hxxp://feed.helperbar.com/?publisher=QuickOC&dpid=QuickOC&co=DE&userid=35e67f97-7787-40cf-897d-5c56a5625e15&searchtype=hp&installDate=
CHR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
Task: {0549C0DB-913F-4411-B577-6A5D9C5D6CEB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {06AD79CF-3049-4E43-A011-BABF6A39B4DF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {0FE5D209-B132-4972-B77D-AC0A78A3FF06} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {11DDFDAD-C35F-4461-90F9-16E92773139F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {15EE9EF4-3824-44CA-8DE2-6C81AD1785D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {242E14E3-E262-42F4-8B7B-A16CC962477C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {29CA4BA7-9156-431C-88C7-69741974F3CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {406C9318-4C8B-41DE-8D30-9294CF6DC20F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {6B7FC54F-AB46-4C0A-BB70-AC855322E160} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {CDDBBD48-0D3F-480D-8456-4181DB66F45F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {FE8EB787-034F-4677-8391-7FCC25426EED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
C:\Users\hauptaccount\AppData\Roaming\jugfet-7
C:\ProgramData\gravity-7
C:\ProgramData\doublers-9
C:\Users\hauptaccount\AppData\Roaming\tempco-5
C:\Users\hauptaccount\AppData\Roaming\sinad-4
C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
C:\Users\hauptaccount\AppData\Roaming\tempco-5
C:\ProgramData\doublers-9
C:\Users\hauptaccount\AppData\Roaming\tdscdma-8
C:\Users\hauptaccount\AppData\Roaming\kilobits-8
C:\ProgramData\linear-0
C:\ProgramData\IObit
cmd: del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
         
*****************

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\doublers-63 => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\tempco-65 => Wert nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jugfet-9.lnk => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\jugfet-7\jugfet-9.exe => nicht gefunden.
Chrome HomePage => erfolgreich entfernt
C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0549C0DB-913F-4411-B577-6A5D9C5D6CEB}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0549C0DB-913F-4411-B577-6A5D9C5D6CEB}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06AD79CF-3049-4E43-A011-BABF6A39B4DF}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06AD79CF-3049-4E43-A011-BABF6A39B4DF}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0FE5D209-B132-4972-B77D-AC0A78A3FF06}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FE5D209-B132-4972-B77D-AC0A78A3FF06}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11DDFDAD-C35F-4461-90F9-16E92773139F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11DDFDAD-C35F-4461-90F9-16E92773139F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15EE9EF4-3824-44CA-8DE2-6C81AD1785D0}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15EE9EF4-3824-44CA-8DE2-6C81AD1785D0}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{242E14E3-E262-42F4-8B7B-A16CC962477C}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{242E14E3-E262-42F4-8B7B-A16CC962477C}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{29CA4BA7-9156-431C-88C7-69741974F3CE}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{29CA4BA7-9156-431C-88C7-69741974F3CE}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{406C9318-4C8B-41DE-8D30-9294CF6DC20F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{406C9318-4C8B-41DE-8D30-9294CF6DC20F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6B7FC54F-AB46-4C0A-BB70-AC855322E160}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6B7FC54F-AB46-4C0A-BB70-AC855322E160}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CDDBBD48-0D3F-480D-8456-4181DB66F45F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CDDBBD48-0D3F-480D-8456-4181DB66F45F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FE8EB787-034F-4677-8391-7FCC25426EED}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FE8EB787-034F-4677-8391-7FCC25426EED}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => Schlüssel erfolgreich entfernt
"C:\Users\hauptaccount\AppData\Roaming\jugfet-7" => nicht gefunden.
"C:\ProgramData\gravity-7" => nicht gefunden.
C:\ProgramData\doublers-9 => erfolgreich verschoben
"C:\Users\hauptaccount\AppData\Roaming\tempco-5" => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\sinad-4 => erfolgreich verschoben
C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98} => erfolgreich verschoben
C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705} => erfolgreich verschoben
"C:\Users\hauptaccount\AppData\Roaming\tempco-5" => nicht gefunden.
"C:\ProgramData\doublers-9" => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\tdscdma-8 => erfolgreich verschoben
"C:\Users\hauptaccount\AppData\Roaming\kilobits-8" => nicht gefunden.
"C:\ProgramData\linear-0" => nicht gefunden.
"C:\ProgramData\IObit" => nicht gefunden.

=========  del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q =========


========= Ende von CMD: =========


=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

17.04.2016  17:03    <DIR>          ..
17.04.2016  17:03    <DIR>          .
17.04.2016  16:56    <DIR>          Spotify
16.04.2016  18:21    <DIR>          quark-2
16.04.2016  15:45    <DIR>          amlcd-1
16.04.2016  12:48    <DIR>          Dropbox
15.04.2016  15:51    <DIR>          Wise Care 365
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  14:20    <DIR>          IObit
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
24.03.2016  16:09    <DIR>          vlc
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
               0 Datei(en),              0 Bytes
              60 Verzeichnis(se), 117.001.539.584 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

17.04.2016  17:03    <DIR>          ..
17.04.2016  17:03    <DIR>          .
               0 Datei(en),              0 Bytes
               2 Verzeichnis(se), 117.001.539.584 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

17.04.2016  17:03    <DIR>          ..
17.04.2016  17:03    <DIR>          .
16.04.2016  15:54    <DIR>          Package Cache
16.04.2016  15:42    <DIR>          analog-85
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
30.03.2016  06:01    <DIR>          Origin
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11               133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
               2 Datei(en),            190 Bytes
              62 Verzeichnis(se), 117.001.535.488 Bytes frei

========= Ende von CMD: =========

EmptyTemp: => 499.8 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 17:03:26 ====
         

Alt 17.04.2016, 20:38   #22
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Und wieder neue Logs bitte.
Sollte sich heraustellen, dass da wieder neuer schiet drin ist, müssen wir die nächsten Fixen offline durchführen.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 19.04.2016, 18:00   #23
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Sorry hatte etwas gedauert. Seit dem letzten Fix öffnet sich beim hochfahren immer ein Auswahlfenster das irgendwelche Einstellungen ändern will. Mache mal ein Foto davon. Muss das immer abbrechen damit der PC startet.

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (19-04-2016 18:50:42)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
() C:\Windows\SysWOW64\WinService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Mozilla Messaging) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Rocksteady Studios Ltd.) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chloride-51] => C:\ProgramData\chloride-13\chloride-96.exe [695808 2016-04-19] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [hoist-3] => C:\Users\hauptaccount\AppData\Roaming\hoist-77\hoist-47.exe [882688 2016-04-19] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe" 
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\amlcd-8.lnk [2016-04-19]
ShortcutTarget: amlcd-8.lnk -> C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe (IvoSoft)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S: 
FF SearchEngineOrder.1: 
FF SearchEngineOrder.1,S: 
FF SelectedSearchEngine,S: 
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome: 
=======
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.)
S2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
R3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-19 18:26 - 2016-04-19 18:26 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\amlcd-8
2016-04-19 18:24 - 2016-04-19 18:24 - 00000000 ____D C:\ProgramData\physics-6
2016-04-19 18:22 - 2016-04-19 18:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\hoist-77
2016-04-19 18:17 - 2016-04-19 18:17 - 00000000 ____D C:\ProgramData\chloride-13
2016-04-19 18:14 - 2016-04-19 18:14 - 00911540 _____ C:\WINDOWS\Minidump\041916-35562-01.dmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 18:13 - 2016-04-19 18:13 - 511780318 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 00:05 - 2016-04-19 00:05 - 00000000 _____ C:\Users\hauptaccount\Desktop\Danke.txt
2016-04-18 18:15 - 2016-04-18 18:16 - 00000000 ____D C:\Users\hauptaccount\Documents\Witcher 2
2016-04-18 18:15 - 2016-04-18 18:15 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\The Witcher 2
2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-15 15:46 - 2016-04-17 17:03 - 00017295 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:35 - 2016-04-15 14:36 - 00023394 _____ C:\Users\hauptaccount\Desktop\er (V.txt
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-19 18:51 - 00027909 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-12 12:40 - 2016-04-17 22:00 - 00083585 _____ C:\Users\hauptaccount\Desktop\Addition.txt
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-19 18:50 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:31 - 2016-04-12 12:31 - 02375168 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-03-24 16:09 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM (1).pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega
2016-03-21 22:52 - 2016-03-28 00:40 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt
2016-03-21 22:52 - 2016-03-21 22:52 - 00000208 _____ C:\Users\hauptaccount\Desktop\c.txt
2016-03-21 17:49 - 2016-03-21 17:50 - 00000000 ____D C:\Users\hauptaccount\Desktop\CYBERGAUNER
2016-03-21 17:35 - 2016-03-21 17:35 - 01596260 _____ C:\Users\hauptaccount\Downloads\flyer.pdf
2016-03-21 14:27 - 2016-03-21 14:28 - 08186625 _____ C:\Users\hauptaccount\Downloads\wordpress-4.4.2-de_DE.zip

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-19 18:48 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-19 18:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-19 18:43 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-19 18:34 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-19 18:19 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-19 18:15 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-19 18:15 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-19 18:14 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-19 05:18 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-19 05:18 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-19 05:18 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-19 02:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-19 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-18 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-18 18:16 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-18 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-17 17:03 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-17 17:03 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-17 16:56 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-16 15:54 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 10:37 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-15 10:37 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-15 10:37 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-15 10:37 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 01:45 - 2010-11-17 16:33 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-21 15:35 - 2011-01-17 18:08 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Paint.NET


==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-11 12:08

==================== Ende von FRST.txt ============================
         

Alt 19.04.2016, 18:08   #24
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-19 18:52:33)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-04-13 14:13 - 2016-04-02 05:00 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2012-05-15 16:40 - 2015-04-27 16:07 - 00291944 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-10-28 19:19 - 2016-02-24 06:47 - 00110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2015-10-28 19:19 - 2016-02-24 06:48 - 00062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00848536 _____ () C:\Program Files (x86)\Mozilla Thunderbird\js3250.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00161944 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00021656 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 01675928 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libglesv2.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 00086168 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{FCA69E9E-5F9C-4017-BA34-56A0990113DA}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [{21E0F41D-D786-4B74-8F22-DD034830B1A5}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{7773E817-0D95-4EA8-BCB4-0A3B29108ADF}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{DC163F1E-AF2F-4676-AC19-C9E3051B493F}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{EAC7F226-CCDC-4A17-AA64-697F87B2838D}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{162168E4-1F32-4512-BDC3-BCEF7BE949AB}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe

==================== Wiederherstellungspunkte =========================

15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal
16-04-2016 15:54:01 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
18-04-2016 18:13:19 DirectX wurde installiert

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Renesas USB 3.0 eXtensible-Hostcontroller – 0.96 (Microsoft)
Description: USB-xHCI-kompatibler Hostcontroller
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Generischer USB-xHCI-Hostcontroller
Service: USBXHCI
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/18/2016 06:13:38 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/17/2016 05:03:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: hauptaccount-PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.


Systemfehler:
=============
Error: (04/19/2016 06:20:05 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: {B91D5831-B1BD-4608-8198-D72E155020F7}

Error: (04/19/2016 06:17:12 PM) (Source: DCOM) (EventID: 10016) (User: hauptaccount-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}hauptaccount-PChauptaccountS-1-5-21-2403081755-137120475-2182785957-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/19/2016 06:17:09 PM) (Source: DCOM) (EventID: 10016) (User: hauptaccount-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}hauptaccount-PChauptaccountS-1-5-21-2403081755-137120475-2182785957-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/19/2016 06:17:05 PM) (Source: DCOM) (EventID: 10016) (User: hauptaccount-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}hauptaccount-PChauptaccountS-1-5-21-2403081755-137120475-2182785957-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/19/2016 06:15:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Autodesk Content Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (04/19/2016 06:15:09 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Autodesk Content Service erreicht.

Error: (04/19/2016 06:14:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (04/19/2016 06:14:39 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (04/19/2016 06:14:33 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000009f (0x0000000000000003, 0xffffe0017e0a7050, 0xfffff801edda3ad0, 0xffffe0017d456bd0)C:\WINDOWS\MEMORY.DMPb814ed29-9d8c-4dee-93ab-4df859885abd

Error: (04/19/2016 06:14:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2


CodeIntegrity:
===================================
  Date: 2016-04-18 16:26:37.711
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:37.692
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:37.672
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:33.599
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:33.524
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:33.428
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:33.329
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:13.756
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:13.648
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:10.547
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen =========================== 

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 55%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 1822.34 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 5326.81 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:108.12 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.66 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================
         

Alt 19.04.2016, 19:25   #25
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Es bringt nix, wir müssen das offline machen.

Lad dir FRST bitte neu runter. Danach ziehst du das Netzwerkkabel und trennst etwaige LAN-Verbindungen.

Die neuen FRST Logs und anschließenden Fixes müssen wir komplett OFFLINE machen. Es darf keine Verbindung zum Internet da sein.

Hast du einen zweiten Rechner und einen USB Stick parat? Wenn nicht muss ich mir was anderes überlegen.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 19.04.2016, 20:16   #26
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Habe alles parat. Können das auch gerne morgen machen wenn es heute schon zu spät ist. Richte mich ganz nach dir

Alt 19.04.2016, 22:28   #27
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Gut. Dann wieder einen FRST-Fix. Kopiere den Inhalt der CODE-Box aber in eine Textdatei auf einen Stick, diese dann auf den Desktop des Rechners kopieren, der gefixt werden muss. Und wie gesagt, lass den Rechner so lange offline, bis ich sage, dass du wieder einen Onlineversuch wagen kannst. Nach dem Fix auch bitte wieder neue FRST-Logs machen und posten. Wieder per Stick die Logs transportieren...


FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chloride-51] => C:\ProgramData\chloride-13\chloride-96.exe [695808 2016-04-19] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [hoist-3] => C:\Users\hauptaccount\AppData\Roaming\hoist-77\hoist-47.exe [882688 2016-04-19] ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\amlcd-8.lnk [2016-04-19]
ShortcutTarget: amlcd-8.lnk -> C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe (IvoSoft)
C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
C:\ProgramData\chloride-13
C:\ProgramData\SaveAs
C:\Users\hauptaccount\AppData\Roaming\hoist-77
C:\ProgramData\physics-6
cmd: del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 20.04.2016, 13:51   #28
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



So alles erledigt wie du gesagt hast. PC ist noch offline.
Hier nun Fixlog,FRST und Addition:

Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-20 14:29:55) Run:4
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chloride-51] => C:\ProgramData\chloride-13\chloride-96.exe [695808 2016-04-19] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [hoist-3] => C:\Users\hauptaccount\AppData\Roaming\hoist-77\hoist-47.exe [882688 2016-04-19] ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\amlcd-8.lnk [2016-04-19]
ShortcutTarget: amlcd-8.lnk -> C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe (IvoSoft)
C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
C:\ProgramData\chloride-13
C:\ProgramData\SaveAs
C:\Users\hauptaccount\AppData\Roaming\hoist-77
C:\ProgramData\physics-6
cmd: del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
*****************


=========  dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

19.04.2016  22:29    <DIR>          ..
19.04.2016  22:29    <DIR>          .
19.04.2016  22:29             1.002 dslam-6.lnk
               1 Datei(en),          1.002 Bytes
               2 Verzeichnis(se), 116.685.664.256 Bytes frei

========= Ende von CMD: =========

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\chloride-51 => Wert nicht gefunden.
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\hoist-3 => Wert nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\amlcd-8.lnk => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe => nicht gefunden.
"C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe" => nicht gefunden.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mkpibfnlcehjomacedckkofbpakaefbh => Schlüssel nicht gefunden. 
"C:\ProgramData\chloride-13" => nicht gefunden.
"C:\ProgramData\SaveAs" => nicht gefunden.
"C:\Users\hauptaccount\AppData\Roaming\hoist-77" => nicht gefunden.
"C:\ProgramData\physics-6" => nicht gefunden.

=========  del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q =========


========= Ende von CMD: =========


=========  dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
               0 Datei(en),              0 Bytes
               2 Verzeichnis(se), 116.685.668.352 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

20.04.2016  14:27    <DIR>          ..
20.04.2016  14:27    <DIR>          .
20.04.2016  14:27    <DIR>          Wise Care 365
20.04.2016  14:11    <DIR>          ampacity-56
19.04.2016  22:29    <DIR>          dslam-3
17.04.2016  16:56    <DIR>          Spotify
16.04.2016  12:48    <DIR>          Dropbox
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  14:20    <DIR>          IObit
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
24.03.2016  16:09    <DIR>          vlc
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
               0 Datei(en),              0 Bytes
              60 Verzeichnis(se), 116.685.664.256 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
               0 Datei(en),              0 Bytes
               2 Verzeichnis(se), 116.685.664.256 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

20.04.2016  14:27    <DIR>          ..
20.04.2016  14:27    <DIR>          .
20.04.2016  14:13    <DIR>          vacuole-6
20.04.2016  14:09    <DIR>          balanced-2
16.04.2016  15:54    <DIR>          Package Cache
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
30.03.2016  06:01    <DIR>          Origin
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11               133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
               2 Datei(en),            190 Bytes
              63 Verzeichnis(se), 116.685.660.160 Bytes frei

========= Ende von CMD: =========

EmptyTemp: => 23.2 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 14:30:14 ====
         
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (20-04-2016 14:38:24)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Windows\SysWOW64\WinService.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Spotify Ltd) C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [balanced-0] => C:\ProgramData\balanced-2\balanced-1.exe [784248 2016-04-20] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [ampacity-95] => C:\Users\hauptaccount\AppData\Roaming\ampacity-56\ampacity-57.exe [884736 2016-04-20] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe" 
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S: 
FF SearchEngineOrder.1: 
FF SearchEngineOrder.1,S: 
FF SelectedSearchEngine,S: 
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
S3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-20 14:38 - 2016-04-20 14:38 - 00026188 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-20 14:29 - 2016-04-20 14:37 - 00011183 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-20 14:13 - 2016-04-20 14:13 - 02375680 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-20 14:13 - 2016-04-20 14:13 - 00000000 ____D C:\ProgramData\vacuole-6
2016-04-20 14:11 - 2016-04-20 14:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ampacity-56
2016-04-20 14:09 - 2016-04-20 14:09 - 00000000 ____D C:\ProgramData\balanced-2
2016-04-19 22:29 - 2016-04-19 22:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\dslam-3
2016-04-19 20:49 - 2016-04-19 20:49 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00911540 _____ C:\WINDOWS\Minidump\041916-35562-01.dmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 18:13 - 2016-04-19 18:13 - 511780318 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 00:05 - 2016-04-19 00:05 - 00000000 _____ C:\Users\hauptaccount\Desktop\Danke.txt
2016-04-18 18:15 - 2016-04-18 18:16 - 00000000 ____D C:\Users\hauptaccount\Documents\Witcher 2
2016-04-18 18:15 - 2016-04-18 18:15 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\The Witcher 2
2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-20 14:38 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\verleihshop-ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-03-24 16:09 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM (1).pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega
2016-03-21 22:52 - 2016-03-28 00:40 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt
2016-03-21 22:52 - 2016-03-21 22:52 - 00000208 _____ C:\Users\hauptaccount\Desktop\c.txt
2016-03-21 17:49 - 2016-03-21 17:50 - 00000000 ____D C:\Users\hauptaccount\Desktop\CYBERGAUNER
2016-03-21 17:35 - 2016-03-21 17:35 - 01596260 _____ C:\Users\hauptaccount\Downloads\flyer.pdf
2016-03-21 14:27 - 2016-03-21 14:28 - 08186625 _____ C:\Users\hauptaccount\Downloads\wordpress-4.4.2-de_DE.zip

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-20 14:34 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-20 14:33 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-20 14:30 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-20 14:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-20 14:09 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-20 04:22 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-20 04:22 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 04:22 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 04:22 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 03:48 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-20 03:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-20 03:43 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-20 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-19 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-19 20:49 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-19 18:19 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-18 18:16 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-18 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-17 17:03 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-17 16:56 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-16 15:54 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 10:37 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-15 10:37 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-15 10:37 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 01:45 - 2010-11-17 16:33 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-21 15:35 - 2011-01-17 18:08 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Paint.NET


==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-11 12:08

==================== Ende von FRST.txt ============================
         

Alt 20.04.2016, 13:52   #29
Ikarius
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-20 14:39:44)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server 

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2012-05-15 16:40 - 2015-04-27 16:07 - 00291944 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-10-28 19:19 - 2016-02-24 06:48 - 00062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-10-28 19:19 - 2016-02-24 06:47 - 00110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: Datenträger ist nicht mit dem Internet verbunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{FCA69E9E-5F9C-4017-BA34-56A0990113DA}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [{21E0F41D-D786-4B74-8F22-DD034830B1A5}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{7773E817-0D95-4EA8-BCB4-0A3B29108ADF}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{DC163F1E-AF2F-4676-AC19-C9E3051B493F}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{EAC7F226-CCDC-4A17-AA64-697F87B2838D}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{162168E4-1F32-4512-BDC3-BCEF7BE949AB}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe

==================== Wiederherstellungspunkte =========================

15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal
16-04-2016 15:54:01 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
18-04-2016 18:13:19 DirectX wurde installiert

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/20/2016 02:28:07 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/20/2016 04:22:03 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: hauptaccount-PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5


Systemfehler:
=============
Error: (04/20/2016 02:33:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (04/20/2016 02:33:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (04/20/2016 02:33:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (04/20/2016 02:30:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_518d3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/20/2016 02:25:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (04/20/2016 02:25:34 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%1058

Error: (04/20/2016 02:25:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (04/20/2016 02:24:08 PM) (Source: DCOM) (EventID: 10010) (User: hauptaccount-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (04/20/2016 02:24:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_38696a6" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/20/2016 02:06:43 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.


CodeIntegrity:
===================================
  Date: 2016-04-20 14:38:51.950
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:38:51.930
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.350
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.335
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.277
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:15:12.978
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:15:12.962
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:15:12.926
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 01:12:28.021
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 01:12:28.005
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen =========================== 

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 36%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 2613.93 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 6636.01 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:108.68 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.66 GB) NTFS
Drive e: (Elements) (Fixed) (Total:465.73 GB) (Free:445.48 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 465.7 GB) (Disk ID: 10770C69)
Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================
         

Alt 20.04.2016, 19:40   #30
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Auf Rechnung im Mailanhang geklickt (Zip + doc) - Standard

Auf Rechnung im Mailanhang geklickt (Zip + doc)



Zitat:
2016-04-20 14:13 - 2016-04-20 14:13 - 02375680 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-20 14:13 - 2016-04-20 14:13 - 00000000 ____D C:\ProgramData\vacuole-6
2016-04-20 14:11 - 2016-04-20 14:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ampacity-56
2016-04-20 14:09 - 2016-04-20 14:09 - 00000000 ____D C:\ProgramData\balanced-2
2016-04-19 22:29 - 2016-04-19 22:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\dslam-3
Und der Rechner war wirklich komplett offline? Ziemlich genau mit FRST kam da nämlich wieder neuer Scheixx rein...
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Auf Rechnung im Mailanhang geklickt (Zip + doc)
adobe, akamai, antivir, avira, bluestacks, bonjour, defender, desktop, dnsapi.dll, flash player, google, home, homepage, mailanhang, malware, mozilla, netgear, prozesse, realtek, registry, scan, secure search, security, services.exe, software, stick, temp, usb, windows, windowsapps




Ähnliche Themen: Auf Rechnung im Mailanhang geklickt (Zip + doc)


  1. Mailanhang geöffnet
    Plagegeister aller Art und deren Bekämpfung - 16.03.2016 (5)
  2. Windows 7: TR/Emotet.A.116 aus Mailanhang Status_DHL_Sendungsverfolgung__29__04__2015.zip
    Log-Analyse und Auswertung - 01.05.2015 (3)
  3. WIN7 Pro -> ZIP-File aus dem Mailanhang ausgeführt
    Log-Analyse und Auswertung - 15.03.2015 (3)
  4. gefälschte Rechnung von Vodaphone mit falschem Link zur angeblichen .pdf-Rechnung
    Plagegeister aller Art und deren Bekämpfung - 18.12.2014 (9)
  5. (iPhone) Geklickt: Link geklickt
    Smartphone, Tablet & Handy Security - 15.11.2014 (2)
  6. ungewollter Mailanhang *cdjbdbj.png
    Plagegeister aller Art und deren Bekämpfung - 06.11.2014 (12)
  7. Telekom Rechnung geöffnet und auf gezippte EXE geklickt
    Plagegeister aller Art und deren Bekämpfung - 09.06.2014 (7)
  8. Versehentlich auf Mailanhang geklickt
    Plagegeister aller Art und deren Bekämpfung - 17.04.2014 (5)
  9. mailanhang untersuchen lassen
    Diskussionsforum - 08.04.2014 (2)
  10. Gefälschte Telekom Rechnung erhalten und auf Download Link geklickt - wahrscheinlich Trojaner
    Plagegeister aller Art und deren Bekämpfung - 03.02.2014 (14)
  11. Auf Link in angeblicher Telekom-Rechnung geklickt -> Postfach vom Provider gesperrt
    Log-Analyse und Auswertung - 22.01.2014 (10)
  12. 2x | Mydirtyhobby Trojaner TRFukjoor.B im Mailanhang
    Mülltonne - 15.04.2013 (1)
  13. FedEx Trojaner (Mailanhang) XP Defender Firewall
    Log-Analyse und Auswertung - 29.12.2012 (9)
  14. Trojaner im Mailanhang und zerstörte Dateien
    Log-Analyse und Auswertung - 06.06.2012 (2)
  15. Trojaner-Mailanhang
    Log-Analyse und Auswertung - 24.05.2012 (12)
  16. TR/Rootkit.Gen - Fund nach Öffnen Mailanhang
    Plagegeister aller Art und deren Bekämpfung - 19.05.2012 (9)
  17. Lieferschein.exe im Mailanhang geöffnet, Laptop infiziert?
    Log-Analyse und Auswertung - 17.07.2008 (7)

Zum Thema Auf Rechnung im Mailanhang geklickt (Zip + doc) - Code: Alles auswählen Aufklappen ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01 durchgeführt von hauptaccount (2016-04-15 15:46:17) Run:1 Gestartet von C:\Users\hauptaccount\Desktop Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & - Auf Rechnung im Mailanhang geklickt (Zip + doc)...
Archiv
Du betrachtest: Auf Rechnung im Mailanhang geklickt (Zip + doc) auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.