|
Überwachung, Datenschutz und Spam: Rechner versendet scheinbar SpammailsWindows 7 Fragen zu Verschlüsselung, Spam, Datenschutz & co. sind hier erwünscht. Hier geht es um Abwehr von Keyloggern oder aderen Spionagesoftware wie Spyware und Adware. Themen zum "Trojaner entfernen" oder "Malware Probleme" dürfen hier nur diskutiert werden. Benötigst du Hilfe beim Trojaner entfernen oder weil du dir einen Virus eingefangen hast, erstelle ein Thema in den oberen Bereinigungsforen. |
08.05.2016, 13:26 | #1 |
| Rechner versendet scheinbar Spammails Hallo Ihr Lieben, nachdem ich dank eurer Hilfe einigen Freunden helfen konnte, hat es mich scheinbar auch mal erwischt. In den letzten Tagen erhalte ich immer mehr Antwortmails auf Emails, die offensichtlich mit meiner Emailadresse Spam bzw. Fishing-Nachrichten enthalten. Ich nutze mein Notebook sowohl privat als auch geschäftlich, hab aber leider als freiberuflicher Berater und Einzelkämpfer keine IT-Abteilung, die mir helfen könnte, so dass ich hoffe, dass ihr mir trotzdem dabei helft, die scheinbare Zecke loszuwerden. Leider sind die Logfiles zu groß, um in einem Post eingefügt zu werden, daher hier zunächst die FRST.txt: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:07-05-2016 durchgeführt von re_000 (Administrator) auf RAINER_DELL (08-05-2016 14:00:23) Gestartet von C:\Users\re_000\Downloads\Trojaner Board Geladene Profile: re_000 (Verfügbare Profile: re_000 & Administrator) Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Check Point Software Technologies) C:\Program Files (x86)\CheckPoint\SSL Network Extender\slimsvc.exe (AVM Berlin) C:\Program Files\FRITZ!Fernzugang\certsrv.exe (Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKService.exe () C:\Windows\SysWOW64\spdsvc.exe (AVM Berlin) C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe () C:\Program Files (x86)\Paragon Software\Paragon ExtFS for Windows\extservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Dell Inc.) C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEService64.exe (Dell SonicWALL, Inc.) C:\Program Files\Dell SonicWALL\Global VPN Client\SWGVCSvc.exe (RealVNC Ltd) C:\Program Files\RealVNC\VNC Server\vncservice.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe (RealVNC Ltd) C:\Program Files\RealVNC\VNC Server\vncserver.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe (Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe (Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (RealVNC Ltd) C:\Program Files\RealVNC\VNC Server\vncserverui.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVKTray\AVKTray.exe (G DATA Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe () C:\Windows\System32\igfxTray.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEGui.exe (Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Fieldston Software) C:\Program Files (x86)\Fieldston Software\gSyncit\gsyncit.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (AVM Berlin) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_60ff6cdc6aeff8f9\fritzbox-usb-fernanschluss.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Logitech) C:\Program Files (x86)\Logitech\H800\H800.exe (SourceForge.net) C:\Program Files (x86)\Password Safe\pwsafe.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\AuthManager\AuthManSvr.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\SelfServicePlugin\SelfServicePlugin.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe (CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE (Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Toaster.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRSync.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe (Google) C:\Program Files (x86)\Google\Google Earth Pro\client\googleearth.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Windows\System32\mspaint.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.19761.0_x64__8wekyb3d8bbwe\Video.UI.exe (Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\SelfServicePlugin\SelfService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winamp.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.6927.23501.0_x64__8wekyb3d8bbwe\OHub.exe () C:\Program Files\WindowsApps\Microsoft.XboxApp_15.17.3003.0_x64__8wekyb3d8bbwe\XboxApp.exe (Aviata Inc) C:\Program Files (x86)\Dell Product Registration\prodreg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssist\uaclauncher.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe () C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe (Microsoft Corporation) C:\Windows\System32\DeviceCensus.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\ielowutil.exe (G Data Software AG) C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVK.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-12-28] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-12-28] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322712 2014-10-09] (Intel Corporation) HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3859968 2014-10-08] (Dell Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-24] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [SonicWALLNetExtender] => C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEGui.exe [1298448 2014-11-10] (Dell Inc.) HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [611248 2015-05-21] (Waves Audio Ltd.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] () HKLM-x32\...\Run: [DropboxOEM] => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [462160 2014-09-02] () HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [23248560 2016-04-08] (Dropbox, Inc.) HKLM-x32\...\Run: [Logitech H800] => C:\Program Files (x86)\Logitech\H800\H800.exe [273432 2011-07-29] (Logitech) HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [518456 2015-09-13] (Citrix Systems, Inc.) HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [231736 2015-09-13] (Citrix Systems, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\Run: [Remote Control Editor] => C:\Program Files (x86)\Common Files\TERRATEC\Remote\TTTvRc.exe [1531904 2009-12-04] (Elgato Systems) HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\Run: [gSyncit] => C:\Program Files (x86)\Fieldston Software\gSyncit\gsyncit.exe [228352 2016-03-23] (Fieldston Software) HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\Run: [GoogleChromeAutoLaunch_46CC980BEC52B96990B7C5C5D183D9AB] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304 2016-04-28] (Google Inc.) HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\Run: [AVMUSBFernanschluss] => C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_60ff6cdc6aeff8f9\AVMAutoStart.exe [139264 2015-08-25] (AVM Berlin) HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1399208 2016-04-08] (Garmin Ltd. or its subsidiaries) HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [51662464 2016-04-08] (Skype Technologies S.A.) HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8590760 2015-12-08] (Piriform Ltd) HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\RunOnce: [Uninstall C:\Users\re_000\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_3\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\re_000\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_3\amd64" HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1399208 2016-04-08] (Garmin Ltd. or its subsidiaries) ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DBRShellOverlayBackupFile] -> {831CEBDD-6BAF-4432-BE76-9E0989C14AEF} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconBackuped.dll [2015-09-11] (SoftThinks SAS) ShellIconOverlayIdentifiers: [DBRShellOverlayModifiedBackupFile] -> {275E4FD7-21EF-45CF-A836-832E5D2CC1B3} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconNotBackuped.dll [2015-09-11] (SoftThinks SAS) ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk [2016-02-02] ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe () Startup: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2016-05-04] ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation) Startup: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Password Safe.lnk [2015-06-30] ShortcutTarget: Password Safe.lnk -> C:\Program Files (x86)\Password Safe\pwsafe.exe (SourceForge.net) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{5f7df4b3-456c-4765-bdf7-f8d6997dfb55}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{a6677946-6dab-4686-9cd5-136f00488629}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP SearchScopes: HKU\S-1-5-21-1839789197-1946932406-2014121803-1001 -> DefaultScope {F9AC36A4-A21B-404D-B46B-F58D947DCF6A} URL = SearchScopes: HKU\S-1-5-21-1839789197-1946932406-2014121803-1001 -> {F9AC36A4-A21B-404D-B46B-F58D947DCF6A} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-03-17] (Microsoft Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-21] (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-21] (Oracle Corporation) Toolbar: HKLM-x32 - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll [2009-09-22] (TerraTec Electronic GmbH) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-06-30] (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-09-13] (Citrix Systems, Inc.) FireFox: ======== FF ProfilePath: C:\Users\re_000\AppData\Roaming\Mozilla\Firefox\Profiles\6zvrdzc8.default-1451912850870 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] () FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2015-09-13] (Citrix Systems, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-21] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-21] (Oracle Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-06-30] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1839789197-1946932406-2014121803-1001: @citrixonline.com/appdetectorplugin -> C:\Users\re_000\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-08-18] (Citrix Online) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll [2008-08-16] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll [2008-08-16] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\msvcm80.dll [2008-05-21] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\msvcp80.dll [2008-05-21] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\msvcr80.dll [2008-05-21] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll [2008-08-16] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll [2008-06-05] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll [2008-08-16] (Citrix Systems, Inc.) FF Extension: FireFTP - C:\Users\re_000\AppData\Roaming\Mozilla\Firefox\Profiles\6zvrdzc8.default-1451912850870\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2016-01-04] FF Extension: Garmin Communicator - C:\Users\re_000\AppData\Roaming\Mozilla\Firefox\Profiles\6zvrdzc8.default-1451912850870\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2016-05-04] FF Extension: Video DownloadHelper - C:\Users\re_000\AppData\Roaming\Mozilla\Firefox\Profiles\6zvrdzc8.default-1451912850870\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-04-12] Chrome: ======= CHR Profile: C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-02] CHR Extension: (Google Docs) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-02] CHR Extension: (Google Drive) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22] CHR Extension: (YouTube) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24] CHR Extension: (Google Cast) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-01-02] CHR Extension: (Google-Suche) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29] CHR Extension: (Google Tabellen) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-02] CHR Extension: (Google Docs Offline) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-03] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29] CHR Extension: (Google Mail) - C:\Users\re_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-02] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2790368 2016-02-18] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKService.exe [970872 2016-02-11] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe [4068592 2016-02-18] (G Data Software AG) S2 avmike; C:\Program Files\FRITZ!Fernzugang\avmike.exe [337824 2012-11-28] (AVM Berlin) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 certsrv; C:\Program Files\FRITZ!Fernzugang\certsrv.exe [143776 2012-11-28] (AVM Berlin) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation) R2 cpextender; C:\Program Files (x86)\CheckPoint\SSL Network Extender\slimsvc.exe [368272 2015-02-23] (Check Point Software Technologies) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-04] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-04] (Dropbox, Inc.) R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2571352 2016-01-05] (Dell Inc.) R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [201816 2016-01-05] (Dell Inc.) S3 DellProdRegManager; C:\Program Files (x86)\Dell Product Registration\regmgrsvc.exe [293440 2014-04-01] (Aviata, Inc.) R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.) R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1385640 2015-05-27] (Intel Corporation) R2 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [414360 2015-11-25] () S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [792592 2016-04-08] (Garmin Ltd. or its subsidiaries) R3 GDFwSvc; C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe [3219872 2016-03-04] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [791160 2016-02-18] (G Data Software AG) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-24] (NVIDIA Corporation) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [26680 2016-02-18] (Hewlett-Packard Company) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18584 2014-10-09] (Intel Corporation) R2 ibtsiva; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [165104 2015-08-07] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Datei ist nicht signiert] R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [350312 2015-09-07] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Datei ist nicht signiert] S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Datei ist nicht signiert] S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation) R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation) R2 LMS; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [411936 2015-06-24] (Intel Corporation) S2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [62382256 2015-03-30] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1868432 2015-06-24] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-24] (NVIDIA Corporation) R2 nwtsrv; C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe [191328 2013-06-10] (AVM Berlin) R2 ParagonMounter; C:\Program Files (x86)\Paragon Software\Paragon ExtFS for Windows\extservice.exe [487936 2015-09-02] () [Datei ist nicht signiert] R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2013-07-30] (CyberLink) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312056 2015-12-28] (Realtek Semiconductor) R2 Samsung Printer Dianostics Service; C:\WINDOWS\SysWOW64\\spdsvc.exe [491328 2015-12-05] () S2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [2084088 2015-10-02] (SoftThinks SAS) R2 SONICWALL_NetExtender; C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEService64.exe [614928 2014-11-10] (Dell Inc.) S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [442536 2015-03-30] (Microsoft Corporation) R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.) S2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [31928 2016-01-12] (Dell Inc.) R2 SWGVCSvc; C:\Program Files\Dell SonicWALL\Global VPN Client\SWGVCSvc.exe [336616 2014-03-06] (Dell SonicWALL, Inc.) S2 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [112792 2015-11-25] () R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH) S3 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [414360 2015-11-25] () R2 vncserver; C:\Program Files\RealVNC\VNC Server\vncservice.exe [639808 2015-01-28] (RealVNC Ltd) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 avmaura; C:\Windows\System32\drivers\avmaura.sys [116480 2015-07-23] (AVM Berlin) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) R3 CVPNDRVA; C:\WINDOWS\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [23760 2015-05-22] (Dell Computer Corporation) R3 DellProf; C:\Windows\system32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation) R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-25] (OSR Open Systems Resources, Inc.) R1 DNE; C:\Windows\system32\DRIVERS\dnelwf64.sys [133456 2013-10-03] (Citrix Systems, Inc.) R2 Dokan; C:\Windows\System32\DRIVERS\dokan.sys [57464 2015-08-27] (Windows (R) Win 7 DDK provider) R3 dptf_acpi; C:\Windows\System32\drivers\dptf_acpi.sys [47096 2015-05-27] (Intel Corporation) R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [43000 2015-05-27] (Intel Corporation) R3 dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [41976 2015-05-27] (Intel Corporation) R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [251384 2015-05-27] (Intel Corporation) R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [160768 2016-03-31] (G Data Software AG) S0 GDElam; C:\Windows\System32\DRIVERS\GDElam.sys [117904 2015-01-08] (G Data Software AG) R1 GDKBB; C:\Windows\system32\drivers\GDKBB64.sys [37400 2016-03-31] (G Data Software AG) R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [29720 2016-03-31] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [246272 2016-03-31] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [92160 2016-03-31] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [77848 2016-03-31] (G DATA Software AG) R1 GRD; C:\WINDOWS\system32\drivers\GRD.sys [106272 2015-12-28] (G Data Software) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [134656 2016-03-31] (G Data Software AG) R3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [46856 2015-06-15] (Intel Corporation) R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [132360 2015-06-15] (Intel Corporation) R3 iaLPSS_UART2; C:\Windows\System32\drivers\iaLPSS_UART2.sys [155400 2015-06-15] (Intel Corporation) R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [270080 2015-12-17] (Intel Corporation) R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [183584 2015-06-12] (Intel Corporation) S3 mod7700; C:\Windows\system32\DRIVERS\dvb7700all.sys [866600 2012-08-09] (DiBcom) R3 Netwtw02; C:\Windows\System32\drivers\Netwtw02.sys [7081200 2015-09-25] (Intel Corporation) R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2015-09-06] (Riverbed Technology, Inc.) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-24] (NVIDIA Corporation) S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46768 2015-05-19] (NVIDIA Corporation) R3 NxDrv; C:\Windows\System32\drivers\NxDrv.sys [26584 2014-11-10] (SonicWALL Inc.) R2 ParagonLDM; C:\Windows\system32\drivers\biont_bs.sys [19208 2014-04-11] () S4 RsFx0153; C:\Windows\System32\DRIVERS\RsFx0153.sys [322736 2015-03-30] (Microsoft Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [552152 2014-09-09] (Realsil Semiconductor Corporation) R3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2015-06-04] () R2 SWIPsec; C:\WINDOWS\system32\Drivers\SWIPsec.sys [110064 2014-03-06] (Dell SonicWALL, Inc.) R3 VNA; C:\Windows\system32\DRIVERS\vna.sys [161256 2009-11-02] (Check Point Software Technologies) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) R3 PCDSRVC{3B54B31B-D06B6431-06020200}_0; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-05-08 14:00 - 2016-05-08 14:00 - 00000000 ____D C:\FRST 2016-05-08 13:59 - 2016-05-08 14:00 - 00000000 ____D C:\Users\re_000\Downloads\Trojaner Board 2016-05-06 17:19 - 2016-05-08 13:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-05-04 14:15 - 2016-05-06 16:43 - 00000000 ____D C:\Users\re_000\Downloads\qdpm 2016-05-04 10:06 - 2016-05-04 10:06 - 00000000 ___HD C:\OneDriveTemp 2016-04-29 09:41 - 2016-04-29 09:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2016-04-19 04:59 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll 2016-04-19 04:59 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll 2016-04-19 04:59 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll 2016-04-19 04:59 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll 2016-04-19 04:59 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll 2016-04-19 04:59 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll 2016-04-19 04:59 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll 2016-04-19 04:59 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2016-04-19 04:59 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-04-19 04:59 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll 2016-04-19 04:59 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe 2016-04-19 04:59 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2016-04-19 04:59 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll 2016-04-19 04:59 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll 2016-04-19 04:59 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll 2016-04-19 04:59 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-04-19 04:59 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll 2016-04-19 04:59 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-04-19 04:59 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2016-04-19 04:59 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll 2016-04-19 04:59 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll 2016-04-19 04:59 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2016-04-19 04:59 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2016-04-19 04:59 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll 2016-04-19 04:59 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys 2016-04-19 04:59 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2016-04-19 04:59 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2016-04-19 04:58 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-04-19 04:58 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll 2016-04-19 04:58 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll 2016-04-19 04:58 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll 2016-04-19 04:58 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2016-04-19 04:58 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2016-04-19 04:58 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2016-04-19 04:58 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll 2016-04-19 04:58 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe 2016-04-19 04:58 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-04-19 04:58 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-04-19 04:58 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys 2016-04-19 04:58 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2016-04-19 04:58 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2016-04-19 04:58 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-04-19 04:58 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll 2016-04-19 04:58 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-04-19 04:58 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-04-19 04:58 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll 2016-04-19 04:58 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe 2016-04-19 04:58 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2016-04-19 04:58 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll 2016-04-19 04:58 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-04-19 04:58 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys 2016-04-19 04:58 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll 2016-04-19 04:58 - 2016-03-29 09:49 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys 2016-04-19 04:58 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-04-19 04:58 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2016-04-19 04:58 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll 2016-04-19 04:58 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys 2016-04-19 04:58 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2016-04-19 04:58 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-04-19 04:58 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2016-04-19 04:58 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-04-19 04:58 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2016-04-19 04:58 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2016-04-19 04:58 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2016-04-19 04:58 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2016-04-19 04:58 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll 2016-04-19 04:58 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-04-19 04:58 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll 2016-04-19 04:58 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2016-04-19 04:58 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-04-19 04:58 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-04-19 04:58 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll 2016-04-19 04:58 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-04-19 04:58 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2016-04-19 04:58 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-04-19 04:58 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll 2016-04-19 04:58 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2016-04-19 04:58 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-04-19 04:58 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe 2016-04-19 04:58 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll 2016-04-19 04:58 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-04-19 04:58 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll 2016-04-19 04:58 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll 2016-04-19 04:58 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll 2016-04-19 04:58 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll 2016-04-19 04:58 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-04-19 04:58 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2016-04-19 04:57 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll 2016-04-19 04:57 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-04-19 04:57 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys 2016-04-19 04:57 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-04-19 04:57 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-04-19 04:57 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2016-04-19 04:57 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-04-19 04:57 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-04-19 04:57 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2016-04-19 04:57 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll 2016-04-19 04:57 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll 2016-04-19 04:57 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2016-04-19 04:57 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-04-19 04:57 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-04-19 04:57 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2016-04-19 04:57 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll 2016-04-19 04:57 - 2016-03-29 09:14 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS 2016-04-19 04:57 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-04-19 04:57 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2016-04-19 04:57 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-04-19 04:57 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-04-19 04:57 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-04-19 04:57 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll 2016-04-19 04:57 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-04-19 04:57 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll 2016-04-19 04:57 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2016-04-19 04:57 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2016-04-19 04:57 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-04-19 04:57 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-04-19 04:57 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-04-19 04:57 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-04-19 04:57 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-04-19 04:57 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-04-19 04:57 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-04-19 04:57 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-04-19 04:57 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-04-19 04:57 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-04-19 04:57 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-04-19 04:57 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2016-04-19 04:57 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2016-04-19 04:57 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-04-19 04:57 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2016-04-19 04:57 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll 2016-04-19 04:57 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll 2016-04-19 04:57 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll 2016-04-19 04:57 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2016-04-19 04:57 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll 2016-04-19 04:56 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2016-04-19 04:56 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2016-04-19 04:56 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll 2016-04-19 04:56 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2016-04-19 04:56 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-04-19 04:56 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-04-19 04:56 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-04-19 04:56 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-19 04:56 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-04-19 04:56 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-04-19 04:56 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2016-04-19 04:56 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-04-19 04:56 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-04-19 04:56 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-04-19 04:56 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-04-19 04:56 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-04-19 04:56 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll 2016-04-19 04:56 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll 2016-04-19 04:56 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-04-19 04:56 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll 2016-04-19 04:56 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll 2016-04-19 04:56 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll 2016-04-19 04:56 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-04-19 04:56 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll 2016-04-19 04:56 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2016-04-19 04:56 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll 2016-04-19 04:56 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2016-04-19 04:56 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2016-04-19 04:56 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-04-19 04:56 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll 2016-04-19 04:56 - 2016-03-29 09:54 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys 2016-04-19 04:56 - 2016-03-29 09:51 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys 2016-04-19 04:56 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll 2016-04-19 04:56 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll 2016-04-19 04:56 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-04-19 04:56 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2016-04-19 04:56 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll 2016-04-19 04:56 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll 2016-04-19 04:56 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll 2016-04-19 04:56 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-04-19 04:56 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2016-04-19 04:56 - 2016-03-29 09:14 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2016-04-19 04:56 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2016-04-19 04:56 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-04-19 04:56 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll 2016-04-19 04:56 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll 2016-04-19 04:56 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2016-04-19 04:56 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2016-04-19 04:56 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2016-04-19 04:56 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2016-04-19 04:56 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll 2016-04-19 04:56 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-04-19 04:56 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll 2016-04-19 04:56 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-04-19 04:56 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2016-04-19 04:56 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2016-04-19 04:56 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-04-19 04:56 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-04-19 04:56 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2016-04-19 04:56 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll 2016-04-19 04:56 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll 2016-04-19 04:56 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-04-19 04:56 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-04-19 04:56 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll 2016-04-19 04:56 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2016-04-19 04:56 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll 2016-04-19 04:56 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2016-04-19 04:56 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll 2016-04-19 04:55 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-04-19 04:55 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2016-04-19 04:55 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2016-04-19 04:55 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2016-04-19 04:55 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2016-04-19 04:55 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2016-04-19 04:55 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2016-04-19 04:55 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-04-19 04:55 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-04-19 04:55 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-04-19 04:55 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-04-19 04:55 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-04-19 04:55 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2016-04-19 04:55 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-04-19 04:55 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-04-19 04:55 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-04-19 04:55 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-04-19 04:55 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll 2016-04-19 04:55 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-04-19 04:55 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll 2016-04-19 04:55 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2016-04-19 04:55 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll 2016-04-19 04:55 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2016-04-19 04:55 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-04-19 04:55 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2016-04-19 04:55 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-04-19 04:55 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2016-04-19 04:55 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-04-19 04:55 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2016-04-19 04:55 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2016-04-19 04:55 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-04-19 04:55 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-04-19 04:55 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll 2016-04-19 04:55 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-04-19 04:55 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2016-04-19 04:55 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2016-04-19 04:55 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2016-04-19 04:55 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2016-04-19 04:55 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2016-04-19 04:55 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2016-04-19 04:55 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-04-19 04:55 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2016-04-19 04:55 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL 2016-04-19 04:55 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2016-04-19 04:54 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2016-04-19 04:54 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-04-19 04:54 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-04-19 04:54 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-04-19 04:54 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-04-19 04:54 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-04-19 04:54 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-04-19 04:54 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-04-19 04:54 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-04-19 04:54 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-04-19 04:54 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-04-19 04:54 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-04-19 04:54 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2016-04-19 04:54 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll 2016-04-19 04:54 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2016-04-19 04:54 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2016-04-19 04:54 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2016-04-19 04:54 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2016-04-19 04:54 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-04-19 04:54 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2016-04-19 04:54 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-04-19 04:54 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2016-04-19 04:54 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-04-19 04:54 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2016-04-19 04:54 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-04-19 04:54 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-04-19 04:54 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-04-19 04:54 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-04-19 04:54 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-04-19 04:54 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-04-19 04:54 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-04-19 04:54 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-04-19 04:54 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-04-19 04:54 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-04-19 04:54 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-04-19 04:54 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-04-19 04:54 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-04-19 04:54 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-04-19 04:54 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-04-19 04:54 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-04-19 04:54 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-04-19 04:54 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-04-19 04:54 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-04-19 04:54 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-04-16 02:06 - 2016-04-16 02:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-04-12 09:20 - 2016-05-07 21:47 - 00003256 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForre_000 2016-04-12 09:20 - 2016-05-07 21:47 - 00000360 _____ C:\WINDOWS\Tasks\HPCeeScheduleForre_000.job 2016-04-08 14:17 - 2016-04-08 14:17 - 05934784 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe 2016-04-08 13:22 - 2016-04-08 13:22 - 00012011 _____ C:\Users\re_000\Documents\Raini Portemonnaie.xlsx ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-05-08 14:01 - 2015-06-30 16:59 - 00004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D752A245-D403-4776-9759-3ECECE084EF8} 2016-05-08 13:55 - 2015-07-02 10:15 - 00000000 ____D C:\Users\re_000\Documents\Outlook-Dateien 2016-05-08 13:54 - 2015-06-30 17:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-05-08 13:53 - 2015-09-22 12:14 - 00000000 ____D C:\Users\re_000\AppData\Roaming\Skype 2016-05-08 13:53 - 2015-07-31 09:54 - 00002346 ____H C:\Users\re_000\Documents\Default.rdp 2016-05-08 13:53 - 2015-07-02 16:56 - 00000000 ____D C:\Users\re_000\AppData\Roaming\gSyncit 2016-05-08 01:17 - 2015-06-30 22:12 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-05-08 01:12 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2016-05-08 01:11 - 2015-06-30 17:06 - 00001238 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job 2016-05-08 00:44 - 2015-08-18 15:22 - 00000592 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1839789197-1946932406-2014121803-1001.job 2016-05-08 00:37 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2016-05-08 00:29 - 2015-07-01 17:28 - 00001142 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-05-08 00:29 - 2015-07-01 17:28 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-05-07 23:52 - 2015-06-19 23:39 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery 2016-05-07 16:15 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-05-07 16:15 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-05-07 16:11 - 2015-06-30 17:06 - 00001234 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job 2016-05-04 21:13 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache 2016-05-04 18:06 - 2015-06-30 16:44 - 00000000 ____D C:\Users\re_000\AppData\Local\Packages 2016-05-04 18:00 - 2016-03-18 12:40 - 00002626 _____ C:\Users\re_000\Desktop\Sietsema Farms (445).lnk 2016-05-04 18:00 - 2015-07-03 13:57 - 00000000 ____D C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz 2016-05-04 12:06 - 2015-09-22 12:14 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-05-04 12:06 - 2015-09-22 12:14 - 00000000 ____D C:\ProgramData\Skype 2016-05-04 10:09 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-05-04 10:08 - 2015-10-30 20:35 - 00844552 _____ C:\WINDOWS\system32\perfh007.dat 2016-05-04 10:08 - 2015-10-30 20:35 - 00180310 _____ C:\WINDOWS\system32\perfc007.dat 2016-05-04 10:08 - 2015-07-31 02:03 - 01984654 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-05-04 10:07 - 2015-06-30 17:08 - 00000000 ___RD C:\Users\re_000\Dropbox 2016-05-04 10:06 - 2015-12-28 22:20 - 00000000 ____D C:\Users\re_000\AppData\Local\Deployment 2016-05-04 10:06 - 2015-07-01 00:23 - 00000000 ____D C:\Users\re_000\AppData\Local\PasswordSafe 2016-05-04 10:06 - 2015-06-30 16:51 - 00000000 ___RD C:\Users\re_000\OneDrive 2016-05-04 10:05 - 2015-12-28 19:19 - 00000000 ____D C:\Users\re_000 2016-05-04 10:04 - 2015-12-28 19:13 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2016-05-04 10:04 - 2015-06-30 16:44 - 00000000 __SHD C:\Users\re_000\IntelGraphicsProfiles 2016-05-04 10:00 - 2015-12-28 19:49 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-05-04 10:00 - 2015-12-28 19:05 - 00370000 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-05-04 09:55 - 2015-10-30 08:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI 2016-05-04 09:51 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-05-04 09:51 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-05-04 09:51 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2016-05-04 09:51 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-05-03 09:30 - 2015-07-02 11:25 - 00002266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-05-03 09:30 - 2015-07-02 11:25 - 00002254 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-05-02 14:50 - 2015-10-30 09:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-05-02 14:48 - 2015-06-30 16:55 - 00000000 ____D C:\Program Files\Microsoft Office 15 2016-05-02 14:31 - 2016-04-06 13:55 - 00002608 _____ C:\Users\re_000\Desktop\TSR Suedwestfalen GmbH (453).lnk 2016-04-29 09:42 - 2015-06-19 23:26 - 00000000 ____D C:\ProgramData\Package Cache 2016-04-29 09:41 - 2016-02-02 13:35 - 00001965 _____ C:\Users\Public\Desktop\Garmin Express.lnk 2016-04-29 09:41 - 2015-10-23 19:09 - 00003624 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask 2016-04-29 09:41 - 2015-10-23 19:09 - 00000000 ____D C:\Program Files (x86)\Garmin 2016-04-29 09:27 - 2015-07-31 07:44 - 00002392 _____ C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-04-21 07:36 - 2016-04-07 11:56 - 00002612 _____ C:\Users\re_000\Desktop\Slatlem Bilplan AS (444).lnk 2016-04-21 07:36 - 2016-04-06 13:46 - 00002608 _____ C:\Users\re_000\Desktop\Metallhandel Südwest GmbH(452).lnk 2016-04-21 07:36 - 2016-03-15 17:06 - 00002610 _____ C:\Users\re_000\Desktop\Ehrens EDV-Beratung (52).lnk 2016-04-21 07:36 - 2015-11-03 14:26 - 00002604 _____ C:\Users\re_000\Desktop\Test Combined Metal Industries Inc. (998).lnk 2016-04-21 07:36 - 2015-06-30 22:14 - 00000000 ____D C:\ProgramData\Oracle 2016-04-21 07:36 - 2015-06-30 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-04-21 07:35 - 2015-08-31 15:36 - 00000000 ____D C:\Users\re_000\.oracle_jre_usage 2016-04-21 07:35 - 2015-06-30 22:15 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-04-21 07:34 - 2015-06-30 22:14 - 00000000 ____D C:\Program Files (x86)\Java 2016-04-19 05:06 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-04-19 04:53 - 2015-06-30 23:16 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-04-19 04:40 - 2015-06-30 23:16 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-04-18 15:39 - 2015-06-30 17:00 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-04-17 07:29 - 2015-08-18 15:22 - 00003852 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-1839789197-1946932406-2014121803-1001 2016-04-17 07:29 - 2015-08-18 15:22 - 00003756 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-1839789197-1946932406-2014121803-1001 2016-04-17 07:29 - 2015-08-18 15:22 - 00000688 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1839789197-1946932406-2014121803-1001.job 2016-04-17 05:18 - 2015-06-19 23:37 - 00000000 ____D C:\Temp 2016-04-17 05:16 - 2016-03-14 23:09 - 00000000 ____D C:\Users\re_000\AppData\Roaming\FLV and Media Player 2016-04-16 02:07 - 2015-06-19 23:45 - 00000000 ____D C:\Program Files (x86)\Dropbox 2016-04-16 01:55 - 2015-06-30 17:06 - 00000000 ____D C:\Users\re_000\AppData\Local\Dropbox 2016-04-08 16:09 - 2015-11-14 23:40 - 00000000 ____D C:\Users\re_000\Documents\Soundaufnahmen 2016-04-08 14:17 - 2015-06-30 22:12 - 00003870 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-07-01 00:03 - 2015-07-01 00:03 - 0000000 _____ () C:\Users\re_000\AppData\Roaming\gdfw.log 2015-07-01 00:02 - 2015-07-01 00:02 - 0000779 _____ () C:\Users\re_000\AppData\Roaming\gdscan.log 2015-10-15 13:19 - 2015-10-28 12:03 - 0009216 _____ () C:\Users\re_000\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-07-03 14:52 - 2015-07-03 14:52 - 0000017 _____ () C:\Users\re_000\AppData\Local\resmon.resmoncfg 2015-07-31 09:47 - 2016-02-25 12:06 - 0001832 _____ () C:\Users\re_000\AppData\Local\SLC_re_000.prx 2015-12-28 19:14 - 2015-12-28 19:14 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2015-06-19 23:25 - 2015-06-19 23:26 - 0000121 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log 2015-06-19 23:22 - 2015-06-19 23:23 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log 2015-06-19 23:23 - 2015-06-19 23:24 - 0000111 _____ () C:\ProgramData\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}.log 2015-06-19 23:24 - 2015-06-19 23:25 - 0000108 _____ () C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log 2015-06-19 23:22 - 2015-06-19 23:22 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\re_000\CTX.DAT Einige Dateien in TEMP: ==================== C:\Users\re_000\AppData\Local\Temp\ACLMInstaller.exe C:\Users\re_000\AppData\Local\Temp\jre-8u71-windows-au.exe C:\Users\re_000\AppData\Local\Temp\jre-8u73-windows-au.exe C:\Users\re_000\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\re_000\AppData\Local\Temp\jre-8u91-windows-au.exe C:\Users\re_000\AppData\Local\Temp\SkypeSetup.exe C:\Users\re_000\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-05-04 19:48 ==================== Ende von FRST.txt ============================ |
08.05.2016, 13:28 | #2 |
| Rechner versendet scheinbar Spammails FRST Additions Logfile:
__________________Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:07-05-2016 durchgeführt von re_000 (2016-05-08 14:03:15) Gestartet von C:\Users\re_000\Downloads\Trojaner Board Windows 10 Home Version 1511 (X64) (2015-12-28 18:01:19) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1839789197-1946932406-2014121803-500 - Administrator - Disabled) => C:\Users\Administrator DefaultAccount (S-1-5-21-1839789197-1946932406-2014121803-503 - Limited - Disabled) Gast (S-1-5-21-1839789197-1946932406-2014121803-501 - Limited - Disabled) re_000 (S-1-5-21-1839789197-1946932406-2014121803-1001 - Administrator - Enabled) => C:\Users\re_000 ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: G DATA INTERNET SECURITY (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: G DATA INTERNET SECURITY (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: G*DATA Personal Firewall (Enabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon) <==== ACHTUNG ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden calibre (HKLM-x32\...\{DCB4A686-C75A-4F07-A5AE-00A4A618CE81}) (Version: 2.52.0 - Kovid Goyal) Cardiris 5.5 (HKLM-x32\...\{420106FE-E83B-47C1-87F9-11D263B52C39}) (Version: 5.05.216 - I.R.I.S.) Cardiris 5.5 (HKLM-x32\...\{C54EBF2F-8AE8-4E9D-8164-057358723631}) (Version: 5.05.216 - I.R.I.S.) CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform) CDex - Open Source Digital Audio CD Extractor (HKLM-x32\...\CDex) (Version: 1.79.0.2015 - Georgy Berdyshev) Check Point SSL Network Extender Service (HKLM-x32\...\{b9e1b295-23d6-4cc3-9558-8f6e36d0cd34}) (Version: 7.01.0000 - CheckPoint) Check Point SSL Network Extender Service (HKLM-x32\...\{bd2dc9de-a525-48b8-8b62-f96efd6d81eb}) (Version: 7.01.0000 - CheckPoint) Cinergy T USB XXS Driver Installation (64 Bit) (HKLM-x32\...\{B4382B8A-CCDA-4DB7-B3D9-EE091F73242D}) (Version: 2.03.03.29 - TERRATEC Electronic GmbH) Cisco Systems VPN Client 5.0.07.0440 (HKLM\...\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}) (Version: 5.0.7 - Cisco Systems, Inc.) Citrix Online Launcher (HKLM-x32\...\{DB014C85-A264-4BCA-A66F-6DD1FCF8EC36}) (Version: 1.0.335 - Citrix) Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.3.100.10 - Citrix Systems, Inc.) Citrix XenApp Web Plugin (HKLM-x32\...\{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}) (Version: 11.0.0.5357 - Citrix Systems, Inc.) Common Desktop Agent (Version: 1.62.0 - OEM) Hidden CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.9.1.3 - Dell Inc.) Dell Customer Connect (HKLM-x32\...\{FEFDCDCF-C49C-45D0-AAF8-5345858ADEC7}) (Version: 1.2.1.0 - Dell Inc.) Dell Data Vault (Version: 4.3.7.0 - Dell Inc.) Hidden Dell Digital Delivery (HKLM-x32\...\{693A23FB-F28B-4F7A-A720-4C1263F97F43}) (Version: 3.1.1002.0 - Dell Products, LP) Dell Product Registration (HKLM-x32\...\{17FFE63C-6734-4950-B488-134B5A2505F7}) (Version: 2.04.0280 - Aviata Inc.) Dell SonicWALL NetExtender (HKLM-x32\...\{EF06A6A8-6B81-4A09-8225-789953972FFF}) (Version: 7.5.225 - Dell) Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.2.6793.01 - Dell) Dell SupportAssistAgent (HKLM-x32\...\{A62A2F03-3006-40CA-A3FA-C1086B2FEF5D}) (Version: 1.2.0.94 - Dell) Dell System Detect (HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\58d94f3ce2c27db0) (Version: 6.12.0.1 - Dell) Dell Update (HKLM-x32\...\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.) Diagram Designer (HKLM-x32\...\{BE725DFC-550D-4C4B-BA2D-B1AE3CC0E33F}) (Version: 1.28 - MeeSoft) Dropbox (HKLM-x32\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.) Dropbox 20 GB (HKLM-x32\...\{597A58EC-42D6-4940-8739-FB94491B013C}) (Version: 0.9.0 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.35.1 - Dropbox, Inc.) Hidden DVBViewer TERRATEC Edition (HKLM-x32\...\DVBViewer TERRATEC Edition_is1) (Version: - CM&V) Elevated Installer (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version: - SEIKO EPSON Corporation) FileZilla Client 3.11.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.11.0.2 - Tim Kosse) FLV and Media Player 4.2.1.1 (HKLM-x32\...\FLV and Media Player) (Version: 4.2.1.1 - Applian Technologies) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Free FLV to MP4 Converter 1.0 (HKLM-x32\...\{EE698DD0-BA36-405C-8F34-B0C64C562344}_is1) (Version: - PolySoft Solutions) Free M4a to MP3 Converter 9.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) FRITZ!Box AB-Tool 1.0 (HKLM-x32\...\{00227387-8915-4A71-B4D9-286EAEC46090}) (Version: - Heiko Frenzel (doo!media)) FRITZ!Box USB-Fernanschluss (HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\2db37667170956ee) (Version: 2.3.3.2 - AVM Berlin) FRITZ!Fernzugang (HKLM\...\{DD57CC22-8864-4CCA-94D4-600D024C1207}) (Version: 1.3.1 - AVM Berlin) G DATA INTERNET SECURITY (HKLM-x32\...\{AC68D2FF-1674-4C16-A536-A69FC11BBD82}) (Version: 25.1.0.12 - G DATA Software AG) Garmin Express (HKLM-x32\...\{2639b4f0-83b4-4f3d-942f-e4ba22a40b9b}) (Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden GDR 4042 für SQL Server 2008 R2 (KB3045313) (64-bit) (HKLM\...\KB3045313) (Version: 10.52.4042.0 - Microsoft Corporation) Global VPN Client (HKLM\...\{E828FDAA-B4E0-46B6-B647-7C03CCF48C83}) (Version: 4.9.4 - Dell SonicWALL) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 50.0.2661.94 - Google Inc.) Google Earth Pro (HKLM-x32\...\{35DAA04C-1720-4BE3-A920-A03731EC6A1D}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden GoToMeeting 7.16.0.4800 (HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\GoToMeeting) (Version: 7.16.0.4800 - CitrixOnline) gSyncit (HKLM-x32\...\{46B6D34A-5A3C-4ABE-B40D-5F28F032C489}) (Version: 4.1.42 - Fieldston Software) gSyncit (HKLM-x32\...\{8E2E5C15-5A1E-48A5-9685-DFCF0C60D2CC}) (Version: 4.2.131 - Fieldston Software) HP Support Assistant (HKLM-x32\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.2.8.25 - Hewlett-Packard Company) HP Support Solutions Framework (HKLM-x32\...\{A38E954F-9043-42BD-9DE9-246ED183791D}) (Version: 12.2.8.17 - HP) Intel Driver Update Utility (HKLM-x32\...\{a699b395-cd93-4135-85ec-828113841355}) (Version: 2.2.0.6 - Intel) Intel(R) Driver Update Utility 2.2.0.6 (x32 Version: 2.2.0.1 - Intel) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.1.10600.147 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4274 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.5.0.1056 - Intel Corporation) Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 1.1.253.0 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation) Intel(R) WiDi (HKLM\...\{5BBC7722-E4D9-4406-A8B9-1E11A23B9EAF}) (Version: 5.0.32.0 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{E3FD53DA-893B-4981-AAB7-1BF1AB0A1784}) (Version: 17.1.1532.1814 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden Intel® PROSet/Wireless Software (HKLM-x32\...\{cc892976-0919-4ba9-ab52-ae15d2127a12}) (Version: 18.21.0 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan) IRISPen driver (x64) (x32 Version: 1.03.0000 - I.R.I.S.) Hidden IRISPen Executive 6 (HKLM-x32\...\InstallShield_{84ABE4F4-65E4-42EC-BD40-68C7AD536F37}) (Version: 6.00.1889 - I.R.I.S.) IRISPen Executive 6 (x32 Version: 6.00.1889 - I.R.I.S.) Hidden Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation) Kodi (HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\...\Kodi) (Version: - XBMC-Foundation) Logitech H800 (HKLM\...\{7DE24FDD-A655-4AB7-A877-7236B91A9675}) (Version: 1.0.034 - Logitech) Maxx Audio Installer (x64) (Version: 2.6.6168.1 - Waves Audio Ltd.) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 Language Pack - deu (HKLM-x32\...\{742D41A9-B3BF-3A65-806E-F8372FB3E492}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Office Professional 2013 - de-de (HKLM\...\ProfessionalRetail - de-de) (Version: 15.0.4815.1001 - Microsoft Corporation) Microsoft Report Viewer Redistributable 2008 SP1 (HKLM-x32\...\Microsoft Report Viewer Redistributable 2008 (KB971119)) (Version: - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2008 R2 (64-bit) (HKLM\...\Microsoft SQL Server 2008 R2) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{49860BCD-24D6-44C1-922E-AC12FE32234E}) (Version: 10.52.4042.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Policies (HKLM-x32\...\{D21BC5B2-CBAC-48FA-A701-B5A63C1CA7B8}) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Setup (English) (HKLM\...\{B2213E4E-F502-4D36-BE95-9293C866EF3F}) (Version: 10.52.4042.0 - Microsoft Corporation) Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation) Microsoft SQL Server Browser (HKLM-x32\...\{BF9BF038-FE03-429D-9B26-2FA0FD756052}) (Version: 10.52.4000.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 Query Tools ENU (HKLM-x32\...\{DDFD8348-058C-4F4B-85E5-6D740D4AB3FE}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.52.4000.0 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{288D79EE-A2D1-42AF-9597-B0ADCC23A8ED}) (Version: 10.52.4000.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 (HKLM\...\{BBBE35B2-9349-3C48-BD3D-F574B17C7924}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{4ECF4BDC-8387-329A-ABE9-CF5798F84BB2}) (Version: 9.0.35191 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 46.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 46.0.1 (x86 de)) (Version: 46.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 46.0.1.5966 - Mozilla) Mp3tag v2.71 (HKLM-x32\...\Mp3tag) (Version: v2.71 - Florian Heidenreich) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.9 - Notepad++ Team) NVIDIA GeForce Experience 2.4.5.57 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.57 - NVIDIA Corporation) NVIDIA Graphics Driver 344.32 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.32 - NVIDIA Corporation) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4815.1001 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden Online Plug-in (x32 Version: 14.3.100.10 - Citrix Systems, Inc.) Hidden Paragon ExtFS for Windows (HKLM-x32\...\ParagonExtFS) (Version: - ) Password Safe (HKLM-x32\...\Password Safe) (Version: - ) PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: 4.5.9.2600 - Jan Fiala) QuickSet64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.1.26 - Dell Inc.) Readiris Pro 11 Corporate Edition (HKLM-x32\...\{2B6E0003-45D0-4751-83AD-2D053A61B88E}) (Version: 11.00.4937 - I.R.I.S.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21261 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7544 - Realtek Semiconductor Corp.) Revo Uninstaller Pro 3.1.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.) Samsung CLP-360 Series (HKLM-x32\...\Samsung CLP-360 Series) (Version: 1.21 (12.06.2015) - Samsung Electronics Co., Ltd.) Samsung CLP-360 Series XPS (Windows 8) (HKLM-x32\...\Samsung CLP-360 Series XPS (Windows 8)) (Version: 3.03.06.00:05 - Samsung Electronics Co., Ltd.) Samsung Drucker-Diagnose (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.1.6.02 - Samsung Electronics Co., Ltd.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.05.81.00(25.05.2015) - Samsung Electronics Co., Ltd.) Samsung Easy Wireless Setup (HKLM-x32\...\Easy Wireless Setup) (Version: 3.70.18.0 - Samsung Electronics Co., Ltd.) Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.) Self-Service Plug-in (x32 Version: 4.3.100.10167 - Citrix Systems, Inc.) Hidden Service Pack 2 für SQL Server 2008 R2 (KB2630458) (64-bit) (HKLM\...\KB2630458) (Version: 10.52.4000.0 - Microsoft Corporation) SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.5.57 - NVIDIA Corporation) Hidden Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation) Skype™ 7.22 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.22.109 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.0.15082.16 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.0.15082.16 - Samsung Electronics Co., Ltd.) Hidden SQL Server 2008 R2 SP2 Client Tools (Version: 10.52.4000.0 - Microsoft Corporation) Hidden SQL Server 2008 R2 SP2 Common Files (Version: 10.52.4000.0 - Microsoft Corporation) Hidden SQL Server 2008 R2 SP2 Database Engine Services (Version: 10.52.4000.0 - Microsoft Corporation) Hidden SQL Server 2008 R2 SP2 Database Engine Shared (Version: 10.52.4000.0 - Microsoft Corporation) Hidden SQL Server 2008 R2 SP2 Management Studio (Version: 10.52.4000.0 - Microsoft Corporation) Hidden Sql Server Customer Experience Improvement Program (Version: 10.50.1600.1 - Microsoft Corporation) Hidden Streaming Audio Recorder V4.0.3 (HKLM-x32\...\{B6D9D06B-4B4D-4B41-B963-C056B627F704}_is1) (Version: 4.0.3 - APOWERSOFT LIMITED) Team Helpdesk Agent (x86) (HKLM-x32\...\{669E38A4-EBD7-4905-8FE5-D5A91890611C}) (Version: 8.5.189 - AssistMyTeam) TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.56083 - TeamViewer) TerraTec Home Cinema (HKLM-x32\...\{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}) (Version: 6.12.0 - ) VNC Server 5.2.3 (HKLM\...\{0D2201F0-2E7B-4C89-8C5D-03D3F5BB5042}) (Version: 5.2.3 - RealVNC Ltd) VNC Viewer 5.2.3 (HKLM\...\{8824CB84-60DF-4CBC-AB3A-7C5AB2A41F31}) (Version: 5.2.3 - RealVNC Ltd) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Windows-Treiberpaket - TerraTec (mod7700) Media (04/23/2009 2.03.03.29) (HKLM\...\9CBD3148832E0CEA2404A4A1C6EBACBCDDB90AD0) (Version: 04/23/2009 2.03.03.29 - TerraTec ) Windows-Treiberpaket - TerraTec (mod7700) Media (04/23/2009 2.03.03.29) (HKLM\...\BC42F563D01ACE0E7F869C96EA50AF00CABED596) (Version: 04/23/2009 2.03.03.29 - TerraTec ) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Z-Scan2Send (HKLM-x32\...\{0E062D19-D9B8-4F00-9F1A-3810EA8994F8}) (Version: 3.9.0.11 - IMU Andreas Baumann) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1839789197-1946932406-2014121803-1001_Classes\CLSID\{3573BD2A-B790-466B-909B-8284322838C0}\InprocServer32 -> C:\Users\re_000\AppData\Roaming\AssistMyTeam\Team Helpdesk Agent (x86)\adxloader64.dll () CustomCLSID: HKU\S-1-5-21-1839789197-1946932406-2014121803-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\re_000\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1839789197-1946932406-2014121803-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\re_000\AppData\Local\Citrix\GoToMeeting\3499\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.) CustomCLSID: HKU\S-1-5-21-1839789197-1946932406-2014121803-1001_Classes\CLSID\{ED90173A-3B4C-4E7E-B9CF-79714425D4B5}\InprocServer32 -> C:\Program Files (x86)\PSPad editor\pspshellx64.dll () ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {03DD9877-71AD-4276-A7CF-0E3C949DB9A3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-03-07] (Hewlett-Packard) Task: {06B20057-1681-44C2-984E-0E9B2EB5F81A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated) Task: {07370D38-56BF-4DDD-983F-0C25BFC6A515} - System32\Tasks\{E7764957-C076-4F6F-8CB0-C5748BA6C8CA} => launchwinapp.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?LastError=1603 Task: {0BC888B2-734C-4E42-A5C3-DE22B799ECEA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {0EC7161A-947F-4539-86C8-81AE3F79E5D9} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-12-28] (Realtek Semiconductor) Task: {15A3209B-3EEB-47CE-8DAE-392FC392C57B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-01] (Google Inc.) Task: {185905A0-3CB0-4CEE-B43E-D9EC89C4D131} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd) Task: {22FA1DD7-D8C7-4CC4-9218-24F714795F70} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\WINDOWS\TEMP\DeleteFolderTask.exe Task: {259032DF-51F4-4734-A155-37419EAEFEA7} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-03-02] (Hewlett-Packard) Task: {2B2A85C0-B1C7-4888-9ECE-216BCD864C10} - System32\Tasks\{9C752BAC-9B54-4336-9F3B-B31DF7EAF4EB} => Firefox.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?LastError=1603 Task: {2D41B417-F4B4-45BA-BC69-80E94121144C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-04-06] (Hewlett-Packard) Task: {31B06A1D-AD86-47B1-9C50-1EE1A9D9354A} - System32\Tasks\{0F8D5628-146F-4D77-AE71-17085914D0BA} => Firefox.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?source=lightinstaller&LastError=1603 Task: {353CD1EA-F8B5-4088-A116-908DC4DC5065} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2016-03-24] (PC-Doctor, Inc.) Task: {3663CE13-1C74-4D89-AB22-0434913EBCB2} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2016-04-08] () Task: {3664010A-2A5D-47A2-9B5B-ABC2238FC8DE} - System32\Tasks\HPCeeScheduleForre_000 => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard) Task: {381CA5FD-0692-485F-9FD2-CF9D468D98F4} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-05] (CyberLink) Task: {461E5891-8F69-42C5-9951-1ED3DAEFB8B9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {47F9C188-968C-4D7D-99F5-32B6425B0D28} - System32\Tasks\Dell\Dell Product Registration Update => C:\Program Files (x86)\Dell Product Registration\prodreg.exe [2014-04-01] (Aviata Inc) Task: {56B8F0DD-64D1-4C90-A155-393C8746F05A} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation) Task: {57FE48E2-A5B5-4F28-A65B-BD5D1C15BB9D} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {5E914DA9-A446-4B2A-98C9-8E8F3AB3752C} - System32\Tasks\{CEB37942-E76A-43C4-B224-D0C83A4101B5} => Firefox.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?LastError=1603 Task: {612D9FEE-DF75-4FB7-84E9-A4FD417B9C2E} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {6C801031-5743-4660-AABE-ECF797F7FF79} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-04-04] (Dropbox, Inc.) Task: {6C9E52E1-44F3-49CB-8CE3-6917B821BC64} - System32\Tasks\USER_ESRV_SVC_WILLAMETTE => Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\task.vbs" Task: {71CC486F-0AB6-4DD6-BD1F-0B0CE077F525} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-02-18] (Hewlett-Packard Company) Task: {76AF5444-50C0-400C-8C18-CE9867F3C4AD} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {7737E9A0-1FFE-4C86-B9D2-04A3DAA0AC7A} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2016-01-12] (Dell Inc.) Task: {7F7CE2A3-7C06-48D1-8F3C-D674F4F0171D} - System32\Tasks\{6E047C56-5717-4087-B0D1-9EC50AE65FF8} => Firefox.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?LastError=1603 Task: {81DFB082-E230-4DAC-8AFE-DE953381F446} - System32\Tasks\G2MUpdateTask-S-1-5-21-1839789197-1946932406-2014121803-1001 => C:\Users\re_000\AppData\Local\Citrix\GoToMeeting\4800\g2mupdate.exe [2016-04-17] (Citrix Online, a division of Citrix Systems, Inc.) Task: {87365F78-FECE-447C-A39C-9B0513FB55B5} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2016-03-24] (PC-Doctor, Inc.) Task: {87F43542-7457-4ED3-B8D9-0A01FF02A305} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {944ACC3A-A2F0-4AC0-8C9C-BBDD98FA2E10} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {9829A229-861B-4676-8B40-FEE1E677C3C5} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-04-04] (Dropbox, Inc.) Task: {9B7B11BC-F97A-4CF1-8CDB-B826A7B51025} - System32\Tasks\Paragon Updater => C:\Program Files (x86)\Paragon Software\Updater\Updater.exe [2015-02-04] (Paragon Software Group) Task: {9B9C4C8D-1D49-4D3D-9E9B-C8F3BA9A3BAC} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-19] (Microsoft Corporation) Task: {A3883024-8E5A-44B8-85CE-EF1E2CDCA000} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-01] (Google Inc.) Task: {A80E967F-747A-4245-82E3-26A2EB3AD53D} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-22] (CyberLink Corp.) Task: {ABF5262A-14E8-4253-A09F-E894D89BD6FA} - System32\Tasks\Dell\Dell Product Registration => C:\Program Files (x86)\Dell Product Registration\prodreg.exe [2014-04-01] (Aviata Inc) Task: {ADE902F7-3199-451A-A57B-3C2543154D67} - System32\Tasks\G2MUploadTask-S-1-5-21-1839789197-1946932406-2014121803-1001 => C:\Users\re_000\AppData\Local\Citrix\GoToMeeting\4800\g2mupload.exe [2016-04-17] (Citrix Online, a division of Citrix Systems, Inc.) Task: {B78E3E2C-2724-443B-9D8B-47858F300F1F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {B82A423C-8B9B-4669-B6BD-BC3B2AAE823B} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {B8A44234-23FB-4486-B021-F15CCAA1F11F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation) Task: {C1F52BBE-F005-4EE8-8240-6CD55888AE56} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated) Task: {C34A0706-787C-4458-A02E-E6E4F50417E1} - System32\Tasks\{A4A34639-CC4C-43D3-859B-3639765D21BE} => Firefox.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?LastError=1603 Task: {C5AE8489-048D-4528-8BF7-EB15D89E36D2} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation) Task: {C9B2703B-A86B-4DB7-A73B-AB91C9191B17} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG Task: {D7F278DC-E98B-4B98-B012-0D582E4D33CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-02-18] (Hewlett-Packard Company) Task: {E4D05807-5761-4063-AB82-E1F0E336FE67} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe Task: {F2B4D9EA-471D-46B6-8847-77FCC200B737} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {F320EF2C-EDB4-49A0-988B-6DF581B511D3} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG Task: {F6ACAFF1-6810-48E1-AEBB-B91120CFA643} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {F70ECE6B-9779-4C1F-A21A-0E38BFB7DC24} - System32\Tasks\{9A82EC01-530A-4F9E-A526-50D6F905B018} => Firefox.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?LastError=1603 Task: {F8D3EF3D-6C6F-412A-840E-D8B85250E01B} - System32\Tasks\{97ADFF4E-47D2-4FBD-9A8B-693D2CA4B352} => Firefox.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?LastError=1603 Task: {F9F64173-047D-42BF-A0A1-4F5F9C6F1D23} - System32\Tasks\{F9B57BF2-13D8-4174-8B97-196D5DD4F9E8} => Firefox.exe hxxp://ui.skype.com/ui/0/7.8.0.102/de/go/help.faq.installer?LastError=1603 Task: {FF90811F-DF2F-4CDE-B2B0-38762773B131} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Active Health Launcher => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-03-02] (Hewlett-Packard) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1839789197-1946932406-2014121803-1001.job => C:\Users\re_000\AppData\Local\Citrix\GoToMeeting\4800\g2mupdate.exe Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1839789197-1946932406-2014121803-1001.job => C:\Users\re_000\AppData\Local\Citrix\GoToMeeting\4800\g2mupload.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForre_000.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\WINDOWS\Tasks\RunDFS.job => cmd /c sc start Dell Foundation Services WORKGROUP RAINER_DELL ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\Users\re_000\Desktop\Ehrens EDV-Beratung (52).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/52_EEnchdgeNGdbee3fm2mBFFsdzds/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\59192e1c-10692188" ShortcutWithArgument: C:\Users\re_000\Desktop\Metallhandel Südwest GmbH(452).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/452_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\2b762a7d-2b3b8a4d" ShortcutWithArgument: C:\Users\re_000\Desktop\Sietsema Farms (445).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/445_SietJllfjgoos39dsjf4s499sllj3239dk/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\24047961-244a83df" ShortcutWithArgument: C:\Users\re_000\Desktop\Slatlem Bilplan AS (444).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/444_SLmnchd5gC23aXapl4dcd4CSAFpe/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\30cac282-287d30d8" ShortcutWithArgument: C:\Users\re_000\Desktop\Test Combined Metal Industries Inc. (998).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/998_cmi3f480nvCDD3smchdFSWsx/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\b0f14ec-5bf36ea1" ShortcutWithArgument: C:\Users\re_000\Desktop\TSR Suedwestfalen GmbH (453).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/453_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\3cad8a8c-41abe459" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\AH Holz (127).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/127_ah6kgdL943jnfhIehf4fewf/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\5da5ecf9-65eba5f4" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Autohaus Dreher GmbH (279).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/279_admnHdbch4fhfnrhd94jd4d4BCF/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\69f48502-79eafc28" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Autohaus Dreher GmbH (953).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/953_admnHdbch4fhfnrhd94jd4d4BCF/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\a9213b2-2edff31a" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Autohaus Hofmann KG (900).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/900_hoefjgdgGFRdw34245kMNseqJf/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\f6ef952-52fdba61" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Autohaus Markus Hofmann GmbH (901).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/901_hoefjgdgGFRdw34245kMNseqJf/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\1c256d77-7cfadf82" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Autozentrum AS (358).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/358_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\6c6bcfcd-799bc784" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Autozentrum Gardermoen AS (359).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/359_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\74f6fc35-5c78ce4e" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Arendal AS (365).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/365_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\5dddd06d-5d11d6bb" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Bryne AS (361).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/361_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\3b502604-6987bc8f" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Haugesund AS (362).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/362_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\440b4d27-71344f89" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Kristiansand AS (366).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/366_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\6692087d-351c8393" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Lillestrøm AS (360).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/360_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\32b28df3-1bd548e1" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Molde AS (367).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/367_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\6f6c30af-79e67dad" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Norge as (374).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/374_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\612fbbc5-1bc0997b" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Sport AS (363).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/363_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\4cbe1d4a-5a8f50b3" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bavaria Stavanger AS (364).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/364_BEdc4kdcbd())dbVG32vbd3dsa3/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\5565a6d8-68ac53df" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Bilsalongen AS (315).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/315_bsnfh4dsKHG3s3a2sx0NDF32/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\2d034ed1-19fe6192" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\BMW Autohaus VOGL (382).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/382_extern_vovmfjfhrbFDD453f4HGFvde/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\54d7c763-57d7eff1" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Combined Metal Industries Inc. (304).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/304_cmi3f480nvCDD3smchdFSWsx/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\6ae76cc8-501e694f" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Dyrenes Beskyttelse (189).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/189_dbfvf8fjnBF43ddcmnvf74BBFwa/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\220acb7d-229228fb" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Ehrens EDV-Beratung (52).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/52_EEnchdgeNGdbee3fm2mBFFsdzds/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\59192e1c-10692188" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Auto Weber GmbH (911).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/911_extern_vmjg95dfscmvk4acclfvvvveeees/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\6e6477c0-5bc5f8c6" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Auto-Neulinger GmbH & Co. KG (902).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/902_extern_nvfj487fhvnfgVFDEd83kdmcdNV/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\6d824e4e-5eb54176" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Autohaus J. Stanglmair & Co. GmbH (909).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/909_extern_v85jgbvgss4HHHHHdwcxswerxdd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\ef19ac3-5e8a2344" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Autohaus Josef Stanglmair GmbH (910).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/910_extern_vvfd85dssfbcrrkbd999aqzdmm/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\4f89d09d-2a930e68" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Autohaus Stanglmair GmbH & Co. Betriebs KG (905).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/905_extern_jdndgei8BDSE3kdn4dfdNC943f/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\540ed863-6c4cc8de" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Autohaus Straub GmbH (908).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/908_extern_cdf569dvmvqzadr5bg85dvMFFFd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\6f21fe3a-6719b534" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Autohaus Vodermayer GmbH (906).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/906_extern_mcdjhf4mvd49mzpNFFFd3445s/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\483a47e2-18f026ef" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern J. Scharf Automobile GmbH & Co. KG (903).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/903_extern_mcndhenmv(3jcnVCDDDDs298/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\c153366-4e17106f" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Schielein Autohaus GmbH & Co. KG (904).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/904_extern_mcvd3fvnVdjelforMMMdwcsw3dz/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\2691e5fc-69619a70" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Extern Sebastian Vogl e. K. (907).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/907_extern_nfdhf5VDDTGhj49vffndfhFDq44400/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\28b155aa-2a4a7a63" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Formula Automobile A-S (335).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/335_Formdh47bfsdBNHDRd49df3dDdd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\4a662f16-10bb3427" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\GMR GmbH (329).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/329_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\7361ccbb-1c22d9dc" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\KOVOSROT GROUP a.s. (438).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/438_JTVM7aJDwNmuw6VMKi54lTxDD/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\ca500e-7a4697cd" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Metallhandel Südwest GmbH(452).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/452_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\2b762a7d-2b3b8a4d" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Motor Forum AS Kristiansand (352).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/352_mfnvcjdh4876BVF3dm4seJHFd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\67d592e8-47874604" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\REMINE GmbH (397).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/397_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\2a0365bc-2a631068" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Rohstoffhandel Rackwitz GmbH (328).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/328_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\627f7532-60e886d9" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Sietsema Farms (445).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/445_SietJllfjgoos39dsjf4s499sllj3239dk/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\24047961-244a83df" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Slatlem Bilplan AS (444).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/444_SLmnchd5gC23aXapl4dcd4CSAFpe/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\30cac282-287d30d8" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Slatlem Kristiansund AS (423).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/423_SLmnchd5gC23aXapl4dcd4CSAFpe/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\4fb2a43a-6bbb5cac" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\Test Combined Metal Industries Inc. (998).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/998_cmi3f480nvCDD3smchdFSWsx/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\b0f14ec-5bf36ea1" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\TSR Recycling GmbH & Co. KG (326).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/326_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\406a7f90-617a2ddc" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\TSR RheinRuhr GmbH (327).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/327_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\5180db2c-60317ca8" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\TSR Suedwestfalen GmbH (453).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/453_Tcds645cdgaz234NVD32saxcd/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\3cad8a8c-41abe459" ShortcutWithArgument: C:\Users\re_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DocuBizz\ZIGGY mediahouse GmbH (289).lnk -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://jws.docubizz.com/DocuBizzClient/289_zmdvb47HVBFD3sexsNB/DocuBizz.jnlp "C:\Users\re_000\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\6862750a-12feb34a" ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-28 19:14 - 2015-07-23 03:10 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-07-23 18:27 - 2012-09-18 15:27 - 00192512 _____ () C:\WINDOWS\System32\zlhp1020.dll 2016-01-14 13:29 - 2015-05-26 19:53 - 00022528 _____ () C:\WINDOWS\System32\sst6clm.dll 2015-12-28 17:27 - 2015-12-28 17:27 - 00022016 _____ () C:\WINDOWS\System32\suge1l6.dll 2015-07-01 09:45 - 2015-07-01 09:45 - 00022528 _____ () C:\WINDOWS\System32\us005lm.dll 2015-07-23 18:27 - 2012-09-18 16:27 - 00065024 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\pphp1020.dll 2016-01-14 13:29 - 2015-12-05 13:02 - 00491328 ____N () C:\WINDOWS\SysWOW64\spdsvc.exe 2015-09-02 14:38 - 2015-09-02 14:38 - 00487936 _____ () C:\Program Files (x86)\Paragon Software\Paragon ExtFS for Windows\extservice.exe 2015-06-30 16:55 - 2015-10-13 05:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2016-02-11 05:43 - 2016-02-11 05:43 - 00387704 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll 2015-06-11 06:44 - 2015-12-28 17:27 - 01199104 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\sst6cdu.dll 2016-04-19 04:56 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-19 04:56 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-04-29 09:27 - 2016-04-29 09:27 - 00959176 _____ () C:\Users\re_000\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\ClientTelemetry.dll 2015-06-02 17:18 - 2015-06-02 17:18 - 00043480 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll 2015-09-07 14:43 - 2015-09-07 14:43 - 00395880 _____ () C:\WINDOWS\system32\igfxTray.exe 2015-12-23 01:47 - 2015-11-25 22:40 - 00414360 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe 2015-12-23 01:47 - 2015-11-25 22:46 - 00709272 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_modeler.dll 2015-12-23 01:47 - 2015-11-25 22:43 - 00130712 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_process_input.dll 2015-12-23 01:47 - 2015-11-25 22:44 - 00025752 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_system_power_state_input.dll 2015-12-23 01:47 - 2015-11-25 22:44 - 00059544 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_quality_and_reliability_input.dll 2015-12-23 01:47 - 2015-11-25 22:44 - 00194712 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\acpi_battery_input.dll 2015-12-23 01:47 - 2015-11-25 22:45 - 00159896 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\sema_thermal_input.dll 2015-12-23 01:47 - 2015-11-25 22:45 - 00158360 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\wifi_input.dll 2015-12-23 01:47 - 2015-11-25 22:44 - 00050840 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\devices_use_input.dll 2015-12-23 01:47 - 2015-11-25 22:43 - 00032920 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_disktrace_input.dll 2015-12-28 18:59 - 2015-12-28 18:59 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-04-19 04:58 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2014-09-08 14:39 - 2014-09-08 14:39 - 00464608 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2014-09-08 14:38 - 2014-09-08 14:38 - 00051200 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2016-04-20 06:00 - 2016-04-20 06:01 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-23 01:47 - 2015-11-25 22:36 - 00458904 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv.exe 2015-12-23 01:47 - 2015-11-25 22:45 - 00185496 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\foreground_window_input.dll 2016-04-19 04:56 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-04-19 04:54 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-04-19 04:54 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-04-19 04:54 - 2016-04-02 05:00 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-04-19 04:54 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-05-07 16:12 - 2016-05-07 16:14 - 00016896 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_15.17.3003.0_x64__8wekyb3d8bbwe\XboxApp.exe 2016-05-07 16:12 - 2016-05-07 16:14 - 28891136 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_15.17.3003.0_x64__8wekyb3d8bbwe\XboxApp.dll 2015-10-24 15:33 - 2016-04-08 10:10 - 00025512 _____ () C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe 2011-03-04 13:49 - 2011-03-04 13:49 - 00202752 _____ () C:\Program Files (x86)\Cisco Systems\VPN Client\vpnapi.dll 2015-03-16 12:28 - 2015-03-16 12:28 - 00155528 _____ () C:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll 2015-07-03 16:50 - 2015-06-24 13:37 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-06-19 23:23 - 2013-03-05 05:40 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2013-03-05 18:41 - 2013-03-05 18:41 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll 2015-07-23 11:13 - 2015-07-23 11:13 - 00122024 _____ () C:\Program Files\Microsoft Office 15\root\Office15\JitV.dll 2015-06-30 21:51 - 2016-02-23 10:12 - 00325824 _____ () C:\Program Files\Microsoft Office 15\root\Office15\AppVIsvStream32.dll 2016-04-29 09:27 - 2016-04-29 09:27 - 00679624 _____ () C:\Users\re_000\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\ClientTelemetry.dll 2015-06-30 21:51 - 2016-02-23 10:12 - 00325824 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll 2016-04-16 02:02 - 2016-03-21 23:50 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2016-04-16 02:06 - 2016-03-21 23:51 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2016-04-16 02:06 - 2016-03-21 23:50 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2016-04-16 02:02 - 2016-03-21 23:50 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2015-12-15 15:14 - 2016-03-21 23:50 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2015-12-15 15:14 - 2016-04-08 20:20 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2016-04-16 02:06 - 2016-03-21 23:50 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2015-12-15 15:14 - 2016-04-08 20:20 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2015-12-15 15:14 - 2016-03-21 23:50 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2015-12-15 15:14 - 2016-03-21 23:51 - 00112592 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2015-12-15 15:14 - 2016-04-08 20:20 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2016-04-16 02:06 - 2016-03-21 23:52 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2016-02-19 13:03 - 2016-04-08 20:20 - 00021832 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 00117056 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd 2015-12-15 15:14 - 2016-04-08 20:20 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2016-04-16 02:02 - 2016-03-21 23:50 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd 2016-04-16 02:06 - 2016-03-21 23:50 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2016-04-16 02:06 - 2016-03-21 23:51 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2016-04-16 02:06 - 2016-03-21 23:52 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2016-04-16 02:06 - 2016-04-08 20:19 - 00031568 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd 2016-04-16 02:06 - 2016-03-12 02:46 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll 2016-04-16 02:06 - 2016-04-08 20:19 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2016-02-19 13:03 - 2016-04-08 20:20 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-02-19 13:03 - 2016-04-08 20:20 - 00021824 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd 2016-02-19 13:03 - 2016-04-08 20:20 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd 2016-02-19 13:03 - 2016-04-08 20:20 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2015-12-15 15:14 - 2016-03-21 23:52 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2016-02-19 13:03 - 2016-04-08 20:20 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2016-04-16 02:06 - 2016-04-08 20:19 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2016-04-16 02:06 - 2016-04-08 20:20 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2015-12-15 15:14 - 2016-03-21 23:51 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 01971504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 00223544 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 00158008 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd 2016-04-16 02:06 - 2016-03-21 23:54 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll 2016-04-16 02:06 - 2016-03-21 23:54 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2016-04-16 02:02 - 2016-04-08 20:20 - 00025928 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd 2015-12-15 15:14 - 2016-04-08 20:20 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2016-04-16 02:06 - 2016-04-08 20:20 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2015-12-15 15:14 - 2016-03-21 23:56 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-06-30 21:58 - 2016-02-23 10:14 - 00325824 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll 2015-06-16 17:47 - 2015-06-16 17:47 - 00100688 _____ () C:\Program Files (x86)\Citrix\AuthManager\AppReceiverSDKWrapper.dll 2015-06-24 02:07 - 2015-06-24 02:07 - 01243936 _____ () C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-04-20 06:00 - 2016-04-20 06:01 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-20 06:00 - 2016-04-20 06:02 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2015-10-09 20:13 - 2015-10-09 20:13 - 00607744 _____ () C:\Users\re_000\AppData\Roaming\AssistMyTeam\Team Helpdesk Agent (x86)\adxloader.dll 2016-04-19 04:54 - 2016-04-19 04:59 - 01041600 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\ADDINS\UmOutlookAddin.dll 2015-10-06 23:59 - 2015-10-08 12:35 - 01601536 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\STRestoreAPI.dll 2015-06-19 23:40 - 2012-11-26 05:19 - 01153384 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\libxml2.dll 2015-06-19 23:39 - 2014-02-18 21:12 - 00117568 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\zlib1.dll 2015-05-20 22:53 - 2015-05-20 22:53 - 01777664 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\QtCore4.dll 2015-05-20 23:00 - 2015-05-20 23:00 - 01224704 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\IGCore.dll 2015-05-20 23:00 - 2015-05-20 23:00 - 00290816 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\IGUtils.DLL 2015-05-20 23:00 - 2015-05-20 23:00 - 00631808 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\IGMath.dll 2015-05-20 23:01 - 2015-05-20 23:01 - 01393664 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\alchemy\ogles20\IGSg.dll 2015-05-20 23:01 - 2015-05-20 23:01 - 00751104 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\alchemy\ogles20\IGAttrs.dll 2015-05-20 23:01 - 2015-05-20 23:01 - 03105280 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\alchemy\ogles20\IGGfx.dll 2015-05-20 23:01 - 2015-05-20 23:01 - 00519168 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\alchemy\ogles20\libGLESv2.dll 2015-05-20 23:01 - 2015-05-20 23:01 - 00059392 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\alchemy\ogles20\libEGL.dll 2015-05-20 23:28 - 2015-05-20 23:28 - 17856000 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\googleearth_pro.dll 2015-05-20 23:00 - 2015-05-20 23:00 - 00726016 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\IGExportCommon.dll 2015-05-20 23:07 - 2015-05-20 23:07 - 00015872 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\alchemyext.dll 2015-05-20 22:53 - 2015-05-20 22:53 - 07877632 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\QtWebKit4.dll 2015-05-20 22:53 - 2015-05-20 22:53 - 06174208 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\QtGui4.dll 2015-05-20 22:53 - 2015-05-20 22:53 - 00518656 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\QtNetwork4.dll 2015-05-21 00:11 - 2015-05-21 00:11 - 00093000 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\ge_expat.dll 2015-05-20 23:00 - 2015-05-20 23:00 - 01050624 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\IGOpt.dll 2015-05-20 22:53 - 2015-05-20 22:53 - 00018944 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\imageformats\qgif4.dll 2015-05-20 22:53 - 2015-05-20 22:53 - 00158208 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\imageformats\qjpeg4.dll 2015-05-20 23:00 - 2015-05-20 23:00 - 00145408 _____ () C:\Program Files (x86)\Google\Google Earth Pro\client\alchemy\optimizations\IGOptExtension.dll 2015-06-30 21:51 - 2016-02-23 10:12 - 00325824 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll 2016-02-26 22:43 - 2016-02-26 22:43 - 21848248 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll 2015-03-17 01:34 - 2015-03-17 01:34 - 00322208 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\sqlite.dll 2015-12-18 17:42 - 2015-12-18 17:42 - 50708664 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\libcef.dll 2016-05-06 16:23 - 2016-05-06 16:23 - 00014336 _____ () C:\Users\re_000\AppData\Local\Temp\WDEB58E.tmp\ml_online.lng 2016-05-06 16:23 - 2016-05-06 16:23 - 00036352 _____ () C:\Users\re_000\AppData\Local\Temp\WDEB58E.tmp\ombrowser.lng 2007-09-16 15:49 - 2007-09-16 15:49 - 00764928 _____ () C:\Program Files (x86)\Winamp\Plugins\in_tv.dll 2013-12-13 04:47 - 2013-12-13 04:47 - 00333824 _____ () C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac 2015-06-02 17:18 - 2015-06-02 17:18 - 00039384 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2013-08-22 15:25 - 2015-12-22 20:03 - 00000832 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1839789197-1946932406-2014121803-1001\Control Panel\Desktop\\Wallpaper -> c:\users\re_000\pictures\__rainer toronto ostküste usa\dsc00221.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{A58C3C03-445C-44A5-A039-A0A94DE15B00}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Audio Recorder\ApowersoftVideoHelper.dll FirewallRules: [{B0292FA4-CD41-41C9-90CA-D15E1EC43C2E}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Audio Recorder\ApowersoftVideoHelper.dll FirewallRules: [{440AAD4A-240E-47A9-8A31-AF1B68DBEB48}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Audio Recorder\Streaming Audio Recorder.exe FirewallRules: [{666B74F8-A0CE-4111-A3FE-B556BBBE3CCC}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Audio Recorder\Streaming Audio Recorder.exe FirewallRules: [{D41DBE60-CDC0-4B90-8D2B-315F55DDC234}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{80610887-B426-468C-91E0-40F455AE14D7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{4866CCFA-F2FC-4767-AF8F-C2590A36D254}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\tvtvSetup\tvtv_Wizard.exe FirewallRules: [{1C659417-5F22-40F6-95E7-53E956DE1E2D}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\tvtvSetup\tvtv_Wizard.exe FirewallRules: [{DC73E6E3-1E76-4C8D-92C1-3CDC6D197F9E}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\CinergyDvr.exe FirewallRules: [{D62FB53A-191D-45A7-AB14-0BA5B7D8DB35}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\CinergyDvr.exe FirewallRules: [{F5C21A01-B9B8-464A-BA82-A27E0B0F792B}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\InstTool.exe FirewallRules: [{2837D421-B527-4FDD-96C1-FD2C1ABA0434}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\InstTool.exe FirewallRules: [{84319BE0-9D40-4F2D-B7B6-A443DAD7B37C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{63115CB5-6BCD-4283-A91F-F374684EE7BB}] => (Allow) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_60ff6cdc6aeff8f9\fritzbox-usb-fernanschluss.exe FirewallRules: [{B7E1E1E3-C1A6-4300-B942-F11AAC02F5C8}] => (Allow) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_60ff6cdc6aeff8f9\fritzbox-usb-fernanschluss.exe FirewallRules: [{D3DDD0C6-54B4-46E1-BCD0-517731EB1FE2}] => (Allow) C:\Program Files (x86)\CheckPoint\SSL Network Extender\slimsvc.exe FirewallRules: [{577B1822-321A-4219-9852-34C4AA39BCC1}] => (Allow) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{9EE5628A-420E-400D-B5F9-1B50F6341975}] => (Allow) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{F623027C-B30B-43D5-8AC8-A0938B1851B3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{8B9E6764-C558-48DA-9FF1-8D202A8C5059}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe FirewallRules: [{3965EAB5-D95C-4DCC-B4FA-89BB57891A4E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{5C1844A1-3253-4F82-8811-29ED166FDDE4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{FA891340-C5E6-4821-85B9-6EE42D501E60}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{8D52D754-94E5-4B44-A626-D3A29A4F322D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{65406A64-3279-4998-8C8A-9C6CBE088352}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{8A210A25-4D86-4858-8B67-A21C8E42DBA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{4E022CDF-6681-48BB-B1E5-5AF6E28F2A7F}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [{D4E78CAA-BDDA-45D6-9AB2-011C7E7F25FD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{67DF3899-EE88-47B6-B059-5918D41143E3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{2A602204-93F3-420F-A361-B62CDC0E4ED2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{D6D69AB0-9400-45DE-B2F9-2328F18E9B7E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{AAF03FB4-BB1F-4BD4-8D57-CF550BE4B639}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5DA08119-21EF-49DC-9075-2990CDC3F968}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3D0E7F1B-6ECA-4AC8-94A0-4256D28F5E56}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\InstTool.exe FirewallRules: [{BE3F4112-20AF-436E-A11C-C925976D4C8C}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\InstTool.exe FirewallRules: [{FA694E83-36D9-4AF4-A992-A376421AA561}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\CinergyDvr.exe FirewallRules: [{DD6057BA-858B-4586-8032-15EDD514BDDA}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\CinergyDvr.exe FirewallRules: [{49AF71A4-91DD-4832-A546-8C05A22B9CD5}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\tvtvSetup\tvtv_Wizard.exe FirewallRules: [{124033A5-FAFE-43DC-ACC4-ECFE9E48D5C6}] => (Allow) C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\tvtvSetup\tvtv_Wizard.exe FirewallRules: [{97148271-8ABF-4D5D-B7EB-8AD04D473A33}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{97EFB0CE-A36C-408C-840C-539B47DD3F34}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{F6764982-DC8C-4828-A0F1-F53293690B8C}] => (Allow) C:\Program Files\RealVNC\VNC Server\vncserver.exe FirewallRules: [{570C50FA-438D-4D5B-B802-BF4226BCE0AC}] => (Allow) C:\Program Files\RealVNC\VNC Server\vncserver.exe FirewallRules: [{0E516658-2F44-48E9-90C1-C641C4BCA9EE}] => (Allow) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{C63C07D7-C876-4447-9207-5B82C64FBE05}] => (Allow) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{3493AE58-A8AC-4A35-AC6D-7DDAC75F155B}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{8CBFC247-D265-4B8A-9D9A-D4C868EAFE33}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{31E51339-0FC0-4D0F-A10E-E9CD18C04F5E}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{7AD57825-5290-44ED-BDF5-7CC0D8BBD81C}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\uninstall.exe FirewallRules: [{2F76C0D0-03F9-4E24-8E3C-9458827840AD}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{9F85069B-409C-4802-94FF-66EEBF76AF7C}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\ScanProcess.exe FirewallRules: [{6B5B3344-1320-446D-A341-DE1DB3017DC2}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\Scan2PCNotify.exe FirewallRules: [{CB7912C7-4FB0-48D7-9D55-D5B12E4E0FC9}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{65F5026B-4018-4B84-9C27-D3A888068955}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{9C121F00-2021-448E-B77F-1C1294981ED7}] => (Allow) C:\Program Files (x86)\CheckPoint\SSL Network Extender\slimsvc.exe FirewallRules: [{CD81754E-3D73-4684-A63E-C3BEDEAB4BF6}] => (Allow) C:\Users\re_000\AppData\Local\Temp\7zS3F06\HPDiagnosticCoreUI.exe FirewallRules: [{DD025666-37EE-4784-B870-01C1FB7E5498}] => (Allow) C:\Users\re_000\AppData\Local\Temp\7zS3F06\HPDiagnosticCoreUI.exe FirewallRules: [{67026E2F-CC36-40CB-8531-CDDD59C2CC84}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{039D40CA-1C5C-48F1-911E-092831F69F71}] => (Allow) LPort=2869 FirewallRules: [{DC24A046-C98B-439B-A813-36C256122545}] => (Allow) LPort=1900 FirewallRules: [{0E4A97C5-4A47-45BA-AEFB-9755ED9396E3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{67FB4C5F-97CB-4A3D-8123-A13103431817}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{B3B00670-C0FE-4573-A6CA-F8A466C3E296}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{9478D4A2-1B22-494F-99B6-80C3F51E3600}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{EEE77F4B-8B75-4E60-81EE-290DCC2CB466}] => (Allow) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_60ff6cdc6aeff8f9\fritzbox-usb-fernanschluss.exe FirewallRules: [{650B7408-DAAC-42FF-80A1-A55AECD2EE3C}] => (Allow) C:\Users\re_000\AppData\Local\Apps\2.0\A6YBL99D.LBJ\VW0PB4GA.04G\frit..tion_1acae14e4778b8d2_0002.0003_60ff6cdc6aeff8f9\fritzbox-usb-fernanschluss.exe FirewallRules: [{088DC394-3575-43CE-B036-680FA1606FFE}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{CD8D0BEE-95EE-4BBA-BE5D-BD870D0FD47D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Wiederherstellungspunkte ========================= 19-04-2016 04:35:33 Windows Modules Installer 29-04-2016 09:40:00 Garmin Express 06-05-2016 17:24:59 Geplanter Prüfpunkt ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Cisco Systems VPN Adapter for 64-bit Windows Description: Cisco Systems VPN Adapter for 64-bit Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: CVirtA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: SonicWALL Virtual NIC Description: SonicWALL Virtual NIC Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: SonicWALL Service: SWVNIC Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (05/08/2016 01:52:42 PM) (Source: DPTF) (EventID: 256) (User: ) Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10600.147) TYPE: ERROR DPTF Build Version: 8.1.10600.147 DPTF Build Date: May 26 2015 13:35:22 Source File: ..\..\..\Sources\Manager\EsifApplicationInterface.cpp @ line 737 Executing Function: DptfEvent Message: Received unexpected event Framework Event: DptfResume [3] Error: (05/07/2016 04:03:22 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RAINER_DELL) Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (05/07/2016 04:02:58 PM) (Source: DPTF) (EventID: 256) (User: ) Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10600.147) TYPE: ERROR DPTF Build Version: 8.1.10600.147 DPTF Build Date: May 26 2015 13:35:22 Source File: ..\..\..\Sources\Manager\EsifApplicationInterface.cpp @ line 737 Executing Function: DptfEvent Message: Received unexpected event Framework Event: DptfResume [3] Error: (05/06/2016 05:25:12 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (05/06/2016 03:13:32 PM) (Source: DPTF) (EventID: 256) (User: ) Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10600.147) TYPE: ERROR DPTF Build Version: 8.1.10600.147 DPTF Build Date: May 26 2015 13:35:22 Source File: ..\..\..\Sources\Manager\EsifApplicationInterface.cpp @ line 737 Executing Function: DptfEvent Message: Received unexpected event Framework Event: DptfResume [3] Error: (05/04/2016 05:58:46 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RAINER_DELL) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (05/04/2016 05:58:45 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RAINER_DELL) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (05/04/2016 05:58:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RAINER_DELL) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (05/04/2016 05:58:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RAINER_DELL) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (05/04/2016 05:58:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RAINER_DELL) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Systemfehler: ============= Error: (05/08/2016 01:19:35 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (05/06/2016 06:13:58 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (05/05/2016 01:08:35 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (05/04/2016 05:58:46 PM) (Source: DCOM) (EventID: 10001) (User: RAINER_DELL) Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca31CortanaUI.AppXn73w0hsq3g4wx1h9fhf7q02vw2wta6qc.mcaNicht verfügbarNicht verfügbar Error: (05/04/2016 05:58:45 PM) (Source: DCOM) (EventID: 10001) (User: RAINER_DELL) Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca31CortanaUI.AppX66vvx0wsdb34y1dm8b872ypnaj4fqty0.mcaNicht verfügbarNicht verfügbar Error: (05/04/2016 05:58:44 PM) (Source: DCOM) (EventID: 10001) (User: RAINER_DELL) Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca31CortanaUI.AppX66vvx0wsdb34y1dm8b872ypnaj4fqty0.mcaNicht verfügbarNicht verfügbar Error: (05/04/2016 04:00:14 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (05/04/2016 12:34:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "SoftThinks Agent Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (05/04/2016 10:10:06 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Dell SupportAssist Agent" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error: (05/04/2016 10:09:32 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Dell SupportAssist Agent" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 32767 Millisekunden durchgeführt: Aufführung des konfigurierten Wiederherstellungsp. CodeIntegrity: =================================== Date: 2016-05-07 23:37:21.833 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Common Files\G Data\AVKProxy\ExploitProtection64.dll that did not meet the Store signing level requirements. Date: 2016-05-07 23:37:21.818 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Common Files\G Data\AVKProxy\ExploitProtection64.dll that did not meet the Store signing level requirements. Date: 2016-05-07 23:37:21.806 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Common Files\G Data\AVKProxy\ExploitProtection64.dll that did not meet the Store signing level requirements. Date: 2016-05-06 15:24:29.436 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-04 10:03:15.581 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-19 04:47:24.080 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-04 14:06:08.915 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Common Files\G Data\AVKProxy\ExploitProtection64.dll that did not meet the Store signing level requirements. Date: 2016-04-04 14:06:08.903 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Common Files\G Data\AVKProxy\ExploitProtection64.dll that did not meet the Store signing level requirements. Date: 2016-04-04 14:06:08.888 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Common Files\G Data\AVKProxy\ExploitProtection64.dll that did not meet the Store signing level requirements. Date: 2016-03-23 18:31:43.584 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-5500U CPU @ 2.40GHz Prozentuale Nutzung des RAM: 37% Installierter physikalischer RAM: 16295.43 MB Verfügbarer physikalischer RAM: 10112.96 MB Summe virtueller Speicher: 18727.43 MB Verfügbarer virtueller Speicher: 10886.85 MB ==================== Laufwerke ================================ Drive c: (OS) (Fixed) (Total:918.69 GB) (Free:612.54 GB) NTFS Drive e: (ESP) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT32 Drive w: (PBR Image) (Fixed) (Total:9.73 GB) (Free:0.69 GB) NTFS Drive x: () (Fixed) (Total:0.44 GB) (Free:0.09 GB) NTFS ==================== MBR & Partitionstabelle ================== ==================== Ende von Addition.txt ============================ |
10.05.2016, 14:08 | #3 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner versendet scheinbar SpammailsZitat:
__________________ |
10.05.2016, 14:16 | #4 |
| Rechner versendet scheinbar Spammails Hallo Cosinus, das hatte ich auch schon vermutet, aber die Mails gehen zum Teil an Adressen aus meinem Adressbuch. Wären das nur irgendwelche wilde Unbekannte, würde ich mich zwar ärgern, aber zumindest würde ich mir dann keine Sorgen wegen Fremdzugriffs auf meine Daten machen. Was meinst Du dazu? Liebe Grüße Rainer |
10.05.2016, 14:21 | #5 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner versendet scheinbar Spammails Das wurde tw. bis zum Erbrechen hier diskutiert => http://www.trojaner-board.de/172428-...nden-spam.html Wenn du ein starkes Indiz für Befall hast schau ich mir deinen Rechner genauer an.
__________________ Logfiles bitte immer in CODE-Tags posten |
10.05.2016, 14:31 | #6 |
| Rechner versendet scheinbar Spammails Ich sach ma so, bis vorhin kannte ich den Begriff Spoofing nicht und da ihr ja immer sagt, dass jede Infektion anders ist und daher immer ein neuer Thread angelegt werden soll, hab ich auch nicht weiter gesucht. Jetzt weiß ich aber zumindest, was Spoofing ist und was da passiert und verstehe natürlich auch, dass das Thema für euch völlig ätzend ist. Was mich derzeit noch ein wenig irritiert, ist die Tatsache, dass nicht nur Adressen aus meinem Adressbuch verwendet werden, sondern auch Emailempfänger, von denen ich kurz vorher eine Mail bekommen habe. Auf der einen Seite könnte es natürlich daran liegen, dass ggfs. mein Emailprovider ein Problem mit seinem Server hat - ich schreib die gleich mal an, aber so ganz lässt mich dadurch der Verfolgungswahn noch nicht los. |
10.05.2016, 15:04 | #7 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Rechner versendet scheinbar Spammails Nein ist ja auch schon ok weil du janicht weißt was die Ursache ist. Aber in dem verlinkten Thread konnten wir ja auch alle nur spekulieren. Ein Fakt ist jedenfalls, dass bei solchen Dingern einfach nur die Absendeadresse "gefälscht" wird. Vllt aber vllt auch nicht konnte da mal bei einem Sicherheitsproblem durch was auch immer das Adressbuch abgegriffen werden. Passwort beim Mailacc ändern und gut. Anders sähe es aus, wenn du dicke Trojaner drauf hättest. Aber du hast nix davon gepostet, dass dein AV mal was gemeldet hätte...
__________________ Logfiles bitte immer in CODE-Tags posten |
10.05.2016, 15:19 | #8 |
| Rechner versendet scheinbar Spammails Nö, sonst läuft der stabil und sauber. Hab auch mal Malwareantibytes laufen lassen - keine Bedrohung gefunden und mein GData ist auch auf dem aktuellen Stand:-) Ansonsten hab ich gerade mit meinem Provider gesprochen. Dieser bietet die Möglichkeit, auf dem Server einen SPF-Eintrag anzulegen. Das hab ich auch gerade gemacht, ich hoffe, dass damit das Problem zumindest zum Großteil erledigt ist. Hier mal noch kurz zur Info, was mein Provider (one.com) zum SPF-Eintrag sagt: Wie funktioniert ein SPF? Per SPF können Sie die ausgehenden Mailserver bestimmen, die E-Mails von Ihrem Domainnamen senden können. Wenn ein eingehender Mailserver eine E-Mail von Ihrem Domainnamen empfängt, vergleicht dieser den SPF Record mit den Informationen des ausgehenden Mailservers. Sollten die Informationen nicht übereinstimmen, wird die E-Mail als unauthorisiert erkannt und nicht zugestellt. Leider kontrollieren nicht alle eingehenden Mailserver auf einen SPF Record, sodass das Hinzufügen eines SPF Records zwar helfen wird, dies jedoch nicht sämtliches Spoofing verhindern kann. |
Themen zu Rechner versendet scheinbar Spammails |
computer, cpu, defender, desktop, firefox, flash player, google, helper, home, mozilla, prozesse, realtek, registry, rundll, scan, security, server, services.exe, software, spam, svchost.exe, system, trojaner, usb, windows, windowsapps |