Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Laptop Windows 10 - ziemlich vollgemüllt!

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 04.09.2016, 07:05   #1
Calinjar
 
Laptop Windows 10 - ziemlich vollgemüllt! - Standard

Laptop Windows 10 - ziemlich vollgemüllt!



Hallo Trojaner,

ein Bekannter von mir, bat mich, mal nach seinem Laptop zu sehen, der u.a. beim Hochfahren, Spielen, Öffnen von Programmen sehr bzw. ziemlich langsam ist.
Das Betriebssystem wurde von Win 7 auf Win 10 "upgegraded" (was bei dem Laptop vielleicht ein Fehler war).
Beim durchstöbern der installierten Programme und Googlen der Funde war einiges dabei, was sehr gut Malware sein könnte, darum bitte ich euch mir zu helfen.
Außerdem sehr merkwürdig ist, dass seit einem Windows Update vom 03.09.16 im Revo Uninstaller der 03.09.16 bei vielen Programmen als Installationsdatum angegeben ist, obwohl diese deutlich später installiert wurden.
Also ließ ich erstmal ESET durchlaufen - ~15 infizierte Dateien, Toolbars und evt. Trojaner! - in die Quarantäne o.ä. verschoben habe ich nichts, das überlass' ich Euch.
Die Logs der Scans von ESET und FRST sind beigefügt:

FRST.txt
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
durchgeführt von MM (Administrator) auf SECURITY-SERVIC (04-09-2016 07:47:56)
Gestartet von C:\Users\MM\Desktop
Geladene Profile: MM (Verfügbare Profile: MM)
Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_3.6.23981.0_x64__8wekyb3d8bbwe\Music.UI.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-16] (NVIDIA Corporation)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-07-16] (Microsoft Corporation)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\MM\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29494400 2016-07-13] (Skype Technologies S.A.)
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2857248 2016-08-23] (Valve Corporation)
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Policies\Explorer: [NoLogOff] 0
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\MountPoints2: {60a0c8d8-c050-11e4-8957-1c7508363078} - "E:\SETUP.EXE" 
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [175368 2015-12-16] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWoW64\nvinit.dll => C:\WINDOWS\SysWoW64\nvinit.dll [153208 2015-12-16] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll [2010-05-27] (Egis Technology Inc.)
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll [2010-05-27] (Egis Technology Inc.)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Hosts: 127.0.0.1 secure.tune-up.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ed735836-3afc-4360-8600-80e0ea9c88ea}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = 
SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {D7D76D1E-238F-460F-B08C-8DD2E10C0ECB} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {F41EB89B-2688-4F5A-897C-7E40717AB1E9} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {FDA48F1C-BDD5-4B3B-ADB0-534AA741BAD1} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001 -> {FF1D2452-E87F-4192-A05E-3F5811BC9DA9} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-06-30] (Sun Microsystems, Inc.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default
FF DefaultSearchEngine: Google Default
FF SearchEngineOrder.1: 
FF SelectedSearchEngine: Bing
FF Homepage: about:home
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2011-05-04] (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin-x32: @thrixxx.com/WebLaunch -> C:\Program Files (x86)\thriXXX\WebLaunch\Binaries\npWebLaunch.dll [2006-08-09] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1669543924-1338975548-1525228061-1001: @thrixxx.com/WebLaunch -> C:\Program Files (x86)\thriXXX\WebLaunch\Binaries\npWebLaunch.dll [2006-08-09] ( )
FF Plugin HKU\S-1-5-21-1669543924-1338975548-1525228061-1001: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll [2013-05-05] (The Happy Cloud)
FF Plugin HKU\S-1-5-21-1669543924-1338975548-1525228061-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Keine Datei]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2011-05-04] (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npWebLaunch.dll [2006-08-09] ( )
FF SearchPlugin: C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default\searchplugins\google-default.xml [2015-06-04]
FF SearchPlugin: C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default\searchplugins\youtube.xml [2015-12-21]
FF Extension: (Adblock Plus) - C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28]
FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25]
FF Extension: (DVDVideoSoft YouTube MP3 and Video Download) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2014-12-15] [ist nicht signiert]
FF HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\MM\AppData\Roaming\Mozilla\Firefox\Profiles\cn5wj6oj.default\extensions\cliqz@cliqz.com => nicht gefunden

Chrome: 
=======
CHR Profile: C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-14]
CHR Extension: (Google Docs) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-14]
CHR Extension: (Google Drive) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-14]
CHR Extension: (YouTube) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-14]
CHR Extension: (Google-Suche) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-14]
CHR Extension: (Google Tabellen) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-14]
CHR Extension: (Avira Browserschutz) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-06-14]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-14]
CHR Extension: (Google Wallet) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-14]
CHR Extension: (Google Mail) - C:\Users\MM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-14]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]

Opera: 
=======
StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1392648 2016-07-26] ()
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-16] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [Datei ist nicht signiert]
S4 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-16] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-16] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-02-01] (Electronic Arts)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1310448 2016-08-14] (Overwolf LTD)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-17] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7585280 2016-07-16] (Broadcom Corporation)
S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30352 2015-03-01] (Disc Soft Ltd)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2013-11-16] (Huawei Technologies Co., Ltd.) [Datei ist nicht signiert]
S3 ew_hwusbdev; C:\Windows\System32\DRIVERS\ew_hwusbdev.sys [117248 2013-11-16] (Huawei Technologies Co., Ltd.) [Datei ist nicht signiert]
S3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [121600 2013-11-16] (Huawei Technologies Co., Ltd.) [Datei ist nicht signiert]
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-12-16] (NVIDIA Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-09-04 07:47 - 2016-09-04 07:51 - 00021458 _____ C:\Users\MM\Desktop\FRST.txt
2016-09-04 07:47 - 2016-09-04 07:47 - 00000000 ____D C:\FRST
2016-09-04 00:52 - 2016-09-04 00:52 - 03955544 _____ (Crystal Dew World ) C:\Users\MM\Downloads\CrystalDiskInfo7_0_3-en.exe
2016-09-04 00:26 - 2016-09-04 07:46 - 02397696 _____ (Farbar) C:\Users\MM\Desktop\FRST64.exe
2016-09-04 00:08 - 2016-09-04 00:08 - 01875208 _____ (Malwarebytes ) C:\Users\MM\Downloads\mbae-setup-1.08.1.2572.exe
2016-09-04 00:08 - 2016-09-04 00:08 - 00563880 _____ C:\Users\MM\Downloads\noscript-2.9.0.14.zip
2016-09-04 00:01 - 2016-09-04 00:02 - 05660313 _____ (Swearware) C:\Users\MM\Downloads\ComboFix.exe
2016-09-04 00:00 - 2016-09-04 00:01 - 16563352 _____ (Malwarebytes Corp.) C:\Users\MM\Downloads\mbar-1.09.3.1001.exe
2016-09-03 23:01 - 2016-09-03 23:02 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-09-03 23:01 - 2016-09-03 23:01 - 00001179 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2016-09-03 23:01 - 2016-09-03 23:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2016-09-03 23:01 - 2016-09-03 23:01 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-09-03 23:01 - 2016-09-03 23:01 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2016-09-03 23:01 - 2016-09-03 23:01 - 00000000 ____D C:\Program Files (x86)\ESET
2016-09-03 23:01 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-09-03 23:01 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-09-03 23:01 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-09-03 22:59 - 2016-09-03 23:01 - 02870984 _____ (ESET) C:\Users\MM\Downloads\esetsmartinstaller_deu.exe
2016-09-03 22:59 - 2016-09-03 23:00 - 22851472 _____ (Malwarebytes ) C:\Users\MM\Downloads\mbam-setup-2.2.1.1043.exe
2016-09-03 22:37 - 2016-09-04 00:30 - 00000000 ____D C:\Users\MM\Desktop\RevoUninstaller_Portable
2016-09-03 22:36 - 2016-09-03 22:36 - 09256439 _____ C:\Users\MM\Downloads\RevoUninstaller_Portable_2.0.zip
2016-09-03 22:18 - 2016-09-03 22:18 - 00000000 ____D C:\ProgramData\AirportMania
2016-09-03 22:09 - 2016-09-03 22:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-03 21:05 - 2016-09-03 21:10 - 00000000 ____D C:\AdwCleaner
2016-09-03 21:05 - 2016-09-03 21:05 - 03826240 _____ C:\Users\MM\Desktop\AdwCleaner_6.010.exe
2016-09-03 21:05 - 2016-09-03 21:05 - 01610560 _____ (Malwarebytes) C:\Users\MM\Desktop\JRT.exe
2016-09-03 20:55 - 2016-09-03 20:55 - 00206966 _____ C:\Users\MM\Documents\cc_20160903_205536-03.09.2016.reg
2016-09-03 10:59 - 2016-09-03 20:43 - 00000000 ____D C:\Users\MM\AppData\Local\ConnectedDevicesPlatform
2016-09-03 10:57 - 2016-09-03 10:57 - 00000020 ___SH C:\Users\MM\ntuser.ini
2016-09-03 05:01 - 2016-09-03 20:57 - 00000000 ___DC C:\WINDOWS\Panther
2016-09-03 04:58 - 2016-09-03 04:58 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-09-03 04:57 - 2016-09-03 04:58 - 00000000 ____D C:\Windows.old
2016-09-03 04:56 - 2016-09-03 04:56 - 23682560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 22571008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 22218808 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 20965240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 19423232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 19418624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 13433856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 13080576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 12345344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 12174336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-09-03 04:56 - 2016-09-03 04:56 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-09-03 04:56 - 2016-09-03 04:56 - 09128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 08124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 07814488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 07624192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 05622600 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 04612096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 04130944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 03893376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 03299328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-09-03 04:56 - 2016-09-03 04:56 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-09-03 04:56 - 2016-09-03 04:56 - 02745224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 02537824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-09-03 04:56 - 2016-09-03 04:56 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 02264064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 02257248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-09-03 04:56 - 2016-09-03 04:56 - 02251432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-09-03 04:56 - 2016-09-03 04:56 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-09-03 04:56 - 2016-09-03 04:56 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01906176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01780736 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01595904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01469120 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01453992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01377008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01349120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-09-03 04:56 - 2016-09-03 04:56 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01316352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01163696 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 01106944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01071728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01066328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01066096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01046976 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-09-03 04:56 - 2016-09-03 04:56 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00955008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00885832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00665768 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00590952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00450400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-09-03 04:56 - 2016-09-03 04:56 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00435040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2016-09-03 04:56 - 2016-09-03 04:56 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00381760 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00321280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2016-09-03 04:56 - 2016-09-03 04:56 - 00224096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-09-03 04:56 - 2016-09-03 04:56 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00204288 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-09-03 04:56 - 2016-09-03 04:56 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00151224 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00141824 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-09-03 04:56 - 2016-09-03 04:56 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2016-09-03 04:56 - 2016-09-03 04:56 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-09-03 04:56 - 2016-09-03 04:56 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2016-09-03 04:56 - 2016-09-03 04:56 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL
2016-09-03 04:56 - 2016-09-03 04:56 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2016-09-03 04:56 - 2016-09-03 04:56 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2016-09-03 04:56 - 2016-09-03 04:56 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2016-09-03 04:56 - 2016-09-03 04:56 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 17187328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 13867520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 05722312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 03617792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 03245056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 03116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 02913104 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 02846208 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 02711040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 02680832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 02422784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 02315264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 02289664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 02143232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01875456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01694200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01430200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01279328 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01264912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01099608 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 01062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01052672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01014784 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 01006080 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00987992 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00942424 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2016-09-03 04:55 - 2016-09-03 04:55 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00852824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00846552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00807776 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00681312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00658776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00595488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00587968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00509952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00509784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00361096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
2016-09-03 04:55 - 2016-09-03 04:55 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00077664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00050880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2016-09-03 04:55 - 2016-09-03 04:55 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-09-03 04:55 - 2016-09-03 04:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2016-09-03 04:55 - 2016-09-03 04:55 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
2016-09-03 04:55 - 2016-09-03 04:55 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\c_GSM7.DLL
2016-09-03 04:55 - 2016-09-03 04:55 - 00000000 ____D C:\ProgramData\USOShared
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Vorlagen
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Startmenü
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2016-09-03 04:53 - 2016-09-03 04:53 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2016-09-03 04:51 - 2016-09-03 04:51 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-09-03 04:48 - 2016-09-03 04:52 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2016-09-03 04:48 - 2016-09-03 04:52 - 00007623 _____ C:\WINDOWS\diagerr.xml
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\WINDOWS\system32\msmq
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\Program Files\MSBuild
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-09-03 04:45 - 2016-09-03 04:45 - 00000000 ____D C:\inetpub
2016-09-03 04:44 - 2016-05-25 15:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-09-03 04:44 - 2016-05-25 15:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-09-03 04:44 - 2016-05-25 15:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-09-03 04:44 - 2016-05-25 12:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-09-03 04:44 - 2016-05-25 12:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-09-03 04:44 - 2016-05-25 12:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-09-03 04:43 - 2016-09-03 04:43 - 00199008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2016-09-03 04:39 - 2016-09-03 22:26 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-03 04:39 - 2016-09-03 09:29 - 00003626 _____ C:\WINDOWS\System32\Tasks\FileAdvisorCheck
2016-09-03 04:39 - 2016-09-03 04:39 - 00003662 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-09-03 04:39 - 2016-09-03 04:39 - 00003438 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-09-03 04:39 - 2016-09-03 04:39 - 00003142 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-09-03 04:39 - 2016-09-03 04:39 - 00003110 _____ C:\WINDOWS\System32\Tasks\Java Update Scheduler
2016-09-03 04:39 - 2016-09-03 04:39 - 00003100 _____ C:\WINDOWS\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2016-09-03 04:39 - 2016-09-03 04:39 - 00002978 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-09-03 04:39 - 2016-09-03 04:39 - 00002818 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task
2016-09-03 04:39 - 2016-09-03 04:39 - 00002702 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP Deskjet 2540 series
2016-09-03 04:39 - 2016-09-03 04:39 - 00002672 _____ C:\WINDOWS\System32\Tasks\FileAdvisorUpdate
2016-09-03 04:39 - 2016-09-03 04:39 - 00002668 _____ C:\WINDOWS\System32\Tasks\Overwolf Updater Task
2016-09-03 04:39 - 2016-09-03 04:39 - 00002484 _____ C:\WINDOWS\System32\Tasks\{32D6F56B-7833-457F-9718-457689953BF1}
2016-09-03 04:39 - 2016-09-03 04:39 - 00002472 _____ C:\WINDOWS\System32\Tasks\{F3EA1D55-FD45-431E-B847-554D475A3F6C}
2016-09-03 04:39 - 2016-09-03 04:39 - 00002306 _____ C:\WINDOWS\System32\Tasks\{067A521F-C03C-4F1A-A33C-E4B44A20E46A}
2016-09-03 04:39 - 2016-09-03 04:39 - 00002212 _____ C:\WINDOWS\System32\Tasks\{46FDBF1B-2F00-4BEB-910C-C50DB49D1A4E}
2016-09-03 04:39 - 2016-09-03 04:39 - 00002198 _____ C:\WINDOWS\System32\Tasks\{71547766-FA89-4004-9203-F3F410888270}
2016-09-03 04:39 - 2016-09-03 04:39 - 00002164 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-09-03 04:39 - 2016-09-03 04:39 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2016-09-03 04:39 - 2016-09-03 04:39 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2016-09-03 04:27 - 2016-09-03 04:27 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-09-03 04:27 - 2016-09-03 04:27 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2016-09-03 04:27 - 2016-09-03 04:27 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-09-03 04:27 - 2016-09-03 04:27 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2016-09-03 04:27 - 2016-09-03 04:27 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-09-03 04:17 - 2016-09-03 04:17 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2016-09-03 04:16 - 2016-09-03 04:28 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-09-03 04:14 - 2016-09-03 21:11 - 00000000 ____D C:\Users\MM
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Vorlagen
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Startmenü
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Netzwerkumgebung
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Lokale Einstellungen
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Eigene Dateien
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Druckumgebung
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Documents\Eigene Videos
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Documents\Eigene Musik
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Documents\Eigene Bilder
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\AppData\Local\Verlauf
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\AppData\Local\Anwendungsdaten
2016-09-03 04:14 - 2016-09-03 04:14 - 00000000 _SHDL C:\Users\MM\Anwendungsdaten
2016-09-03 04:11 - 2016-09-03 20:46 - 01792596 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-09-03 04:11 - 2016-09-03 04:11 - 01604148 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-09-03 04:07 - 2016-09-03 04:28 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2016-09-03 04:07 - 2016-09-03 04:28 - 00000000 ____D C:\WINDOWS\system32\NV
2016-09-03 04:07 - 2016-09-03 04:18 - 00000000 ____D C:\ProgramData\NVIDIA
2016-09-03 04:07 - 2016-09-03 04:07 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2016-09-03 04:07 - 2016-09-03 04:07 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-09-03 04:07 - 2016-09-03 04:07 - 00000000 ____D C:\Program Files\Synaptics
2016-09-03 04:07 - 2016-09-03 04:07 - 00000000 ____D C:\Program Files\Realtek
2016-09-03 04:07 - 2015-12-16 16:54 - 06359672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-09-03 04:07 - 2015-12-16 16:54 - 02985264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-09-03 04:07 - 2015-12-16 16:54 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-09-03 04:07 - 2015-12-16 16:54 - 01256240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-09-03 04:07 - 2015-12-16 16:54 - 00523384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-09-03 04:07 - 2015-12-16 16:54 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-09-03 04:07 - 2015-12-16 16:54 - 00075056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-09-03 04:07 - 2015-12-16 16:54 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-09-03 04:07 - 2015-12-16 16:49 - 06090019 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-09-03 04:06 - 2016-09-03 04:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-09-03 04:06 - 2016-07-16 13:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-09-03 04:05 - 2016-09-03 04:17 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-09-03 04:05 - 2016-09-03 04:17 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-09-03 04:03 - 2016-09-04 07:45 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-09-03 04:03 - 2016-09-03 10:55 - 00298928 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-09-03 04:03 - 2016-09-03 04:03 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-08-31 12:14 - 2016-08-31 12:16 - 00000000 ___HD C:\$SysReset
2016-08-24 09:54 - 2016-08-14 09:41 - 00000000 ____D C:\Users\MM\Desktop\VA-TOP100_Single_Charts_vom_12-08-2016-CannaPower
2016-08-24 09:49 - 2016-08-24 09:52 - 201710165 _____ C:\Users\MM\Downloads\VA-TOP100_Single_Charts_vom_12-08-2016_02-CannaPower.zip
2016-08-24 09:46 - 2016-08-24 09:48 - 199614156 _____ C:\Users\MM\Downloads\VA-TOP100_Single_Charts_vom_12-08-2016_01-CannaPower.zip
2016-08-24 09:46 - 2016-08-24 09:46 - 08834489 _____ C:\Users\MM\Downloads\VA-TOP100_Single_Charts_vom_12-08-2016_05-CannaPower.zip
2016-08-09 21:34 - 2016-08-09 21:34 - 00084648 _____ C:\Users\MM\Documents\businessplan(2).pdf
2016-08-05 19:24 - 2016-08-05 19:24 - 00000000 ____D C:\Users\MM\Documents\League of Legends
2016-08-05 19:23 - 2016-08-05 19:23 - 00000000 ____D C:\Users\MM\AppData\Roaming\LolClient
2016-08-05 18:13 - 2016-08-05 18:13 - 00000000 ____D C:\ProgramData\Riot Games
2016-08-05 13:05 - 2016-09-03 04:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2016-08-05 13:05 - 2016-08-05 18:05 - 00000000 ____D C:\rads
2016-08-05 13:05 - 2016-08-05 13:05 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-08-05 13:05 - 2016-08-05 13:05 - 00000000 ____D C:\Riot Games
2016-08-05 13:05 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2016-08-05 13:05 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2016-08-05 13:05 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2016-08-05 13:02 - 2016-08-05 13:05 - 00000000 ____D C:\Users\MM\AppData\Roaming\Riot Games
2016-08-05 13:01 - 2016-08-05 13:02 - 31001328 _____ (Riot Games) C:\Users\MM\Documents\LeagueofLegends_EUW_Installer_2016_05_13.exe

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-09-04 07:39 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2016-09-04 07:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-09-04 03:35 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\appcompat
2016-09-03 22:57 - 2010-08-30 11:03 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-09-03 22:55 - 2010-08-30 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer GameZone
2016-09-03 22:55 - 2010-08-30 11:12 - 00000000 ____D C:\Program Files (x86)\Acer GameZone
2016-09-03 22:55 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-09-03 22:54 - 2014-09-02 10:16 - 00000000 ____D C:\Program Files (x86)\Softland
2016-09-03 22:54 - 2014-08-15 08:45 - 00000000 ____D C:\ProgramData\Package Cache
2016-09-03 22:52 - 2014-09-02 10:16 - 00000000 ____D C:\Program Files\Softland
2016-09-03 22:51 - 2012-11-12 11:30 - 00000000 ____D C:\Users\MM\AppData\Local\Cyberlink
2016-09-03 22:51 - 2012-11-12 11:29 - 00000000 ____D C:\Users\MM\AppData\Roaming\CyberLink
2016-09-03 22:50 - 2012-11-12 11:29 - 00000000 ____D C:\ProgramData\CyberLink
2016-09-03 22:48 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2016-09-03 22:45 - 2016-01-19 10:18 - 00000000 ____D C:\Program Files (x86)\Steam
2016-09-03 22:42 - 2016-07-16 13:47 - 00000000 __RHD C:\Users\Public\Libraries
2016-09-03 22:33 - 2014-05-01 00:34 - 00000000 ____D C:\ProgramData\Avira
2016-09-03 22:26 - 2016-07-16 08:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-09-03 22:26 - 2012-06-08 19:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-03 22:25 - 2014-05-01 00:41 - 00000000 ____D C:\Users\MM\AppData\Roaming\Avira
2016-09-03 22:23 - 2015-02-09 12:52 - 00000000 ____D C:\ProgramData\Apple
2016-09-03 22:23 - 2015-02-09 12:52 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-09-03 22:18 - 2010-11-16 21:24 - 00000000 ____D C:\ProgramData\Temp
2016-09-03 22:17 - 2014-04-06 14:56 - 00000000 ____D C:\Users\MM\Documents\My Games
2016-09-03 22:10 - 2011-03-08 02:14 - 00504488 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-09-03 21:39 - 2011-03-14 17:28 - 00000000 ____D C:\Users\MM\AppData\Local\ElevatedDiagnostics
2016-09-03 21:09 - 2015-06-02 12:48 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2016-09-03 21:09 - 2015-06-02 12:47 - 00000000 ____D C:\Users\MM\AppData\Roaming\Lavasoft
2016-09-03 21:09 - 2015-06-02 12:47 - 00000000 ____D C:\ProgramData\Lavasoft
2016-09-03 20:46 - 2016-07-17 00:51 - 00630074 _____ C:\WINDOWS\system32\perfh007.dat
2016-09-03 20:46 - 2016-07-17 00:51 - 00136552 _____ C:\WINDOWS\system32\perfc007.dat
2016-09-03 11:39 - 2015-12-20 07:16 - 00000000 ____D C:\Users\MM\AppData\Local\Packages
2016-09-03 11:15 - 2015-12-20 07:28 - 00002427 _____ C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-09-03 11:15 - 2015-12-20 07:28 - 00000000 ___RD C:\Users\MM\OneDrive
2016-09-03 11:02 - 2016-07-16 08:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-09-03 10:59 - 2015-12-20 07:16 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-09-03 09:29 - 2014-02-28 09:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Type Advisor
2016-09-03 09:29 - 2014-02-28 09:31 - 00000000 ____D C:\Program Files (x86)\File Type Advisor
2016-09-03 07:11 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-09-03 05:01 - 2016-07-16 13:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-09-03 04:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Provisioning
2016-09-03 04:55 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\USOPrivate
2016-09-03 04:54 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
2016-09-03 04:53 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows NT
2016-09-03 04:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-09-03 04:47 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Registration
2016-09-03 04:47 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-09-03 04:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-09-03 04:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2016-09-03 04:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-09-03 04:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-09-03 04:45 - 2016-07-16 13:44 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2016-09-03 04:45 - 2016-07-16 13:44 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2016-09-03 04:45 - 2016-07-16 13:44 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2016-09-03 04:45 - 2016-07-16 13:44 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2016-09-03 04:45 - 2016-07-16 13:44 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2016-09-03 04:45 - 2016-07-16 13:44 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2016-09-03 04:45 - 2016-07-16 13:44 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2016-09-03 04:45 - 2016-07-16 13:43 - 01414144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00785408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2016-09-03 04:45 - 2016-07-16 13:43 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2016-09-03 04:45 - 2016-07-16 13:43 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2016-09-03 04:45 - 2016-07-16 13:43 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2016-09-03 04:45 - 2016-07-16 13:43 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2016-09-03 04:45 - 2016-07-16 13:43 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2016-09-03 04:45 - 2016-07-16 13:43 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2016-09-03 04:45 - 2016-07-16 13:43 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2016-09-03 04:45 - 2016-07-16 13:43 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2016-09-03 04:45 - 2016-07-16 13:43 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2016-09-03 04:45 - 2016-07-16 13:43 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2016-09-03 04:45 - 2016-07-16 13:43 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2016-09-03 04:45 - 2016-07-16 13:43 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2016-09-03 04:45 - 2016-07-16 13:43 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2016-09-03 04:39 - 2016-07-16 13:47 - 00000000 __RSD C:\WINDOWS\Media
2016-09-03 04:39 - 2015-12-19 18:42 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-09-03 04:28 - 2016-08-01 16:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emergency 2016
2016-09-03 04:28 - 2016-04-06 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft Classic
2016-09-03 04:28 - 2016-01-25 17:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2016-09-03 04:28 - 2016-01-19 10:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2016-09-03 04:28 - 2016-01-15 14:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-09-03 04:28 - 2015-10-30 20:44 - 00000000 ____D C:\WINDOWS\ShellNew
2016-09-03 04:28 - 2015-06-02 12:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2016-09-03 04:28 - 2015-03-01 22:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-09-03 04:28 - 2015-02-09 12:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-09-03 04:28 - 2014-12-16 13:48 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Happy Cloud
2016-09-03 04:28 - 2014-03-30 20:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ITHau.Faktura
2016-09-03 04:28 - 2014-02-28 09:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free M4a to MP3 Converter
2016-09-03 04:28 - 2013-08-03 00:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-09-03 04:28 - 2013-08-02 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2016-09-03 04:28 - 2012-12-30 14:55 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-09-03 04:28 - 2012-12-30 13:35 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-09-03 04:28 - 2012-12-30 13:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-09-03 04:28 - 2012-12-02 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MixMeister
2016-09-03 04:28 - 2012-11-12 11:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt
2016-09-03 04:28 - 2012-03-17 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player Classic - Home Cinema
2016-09-03 04:28 - 2011-08-15 16:11 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2016-09-03 04:28 - 2011-03-08 20:01 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.2
2016-09-03 04:28 - 2010-11-16 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Media Maker 9
2016-09-03 04:28 - 2010-11-16 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2016-09-03 04:28 - 2010-11-16 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye webcam
2016-09-03 04:28 - 2010-11-16 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem
2016-09-03 04:28 - 2010-08-30 11:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Backup Manager
2016-09-03 04:28 - 2010-08-30 11:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2016-09-03 04:28 - 2010-08-30 11:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-09-03 04:27 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-09-03 04:27 - 2015-10-30 08:28 - 00000000 ____D C:\Users\Default.migrated
2016-09-03 04:21 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2016-09-03 04:21 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-09-03 04:21 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\spool
2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-09-03 04:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\IME
2016-09-03 04:20 - 2012-04-08 21:22 - 00000000 ____D C:\WINDOWS\system32\SPReview
2016-09-03 04:20 - 2012-01-30 21:19 - 00000000 ____D C:\WINDOWS\system32\EventProviders
2016-09-03 04:18 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\schemas
2016-09-03 04:18 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-09-03 04:18 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-09-03 04:18 - 2016-03-29 20:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2016-09-03 04:18 - 2015-12-19 14:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-09-03 04:18 - 2015-06-02 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2016-09-03 04:18 - 2013-11-14 22:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2016-09-03 04:18 - 2012-12-30 14:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2016-09-03 04:18 - 2010-08-30 11:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EgisTec
2016-09-03 04:18 - 2009-07-14 09:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2016-09-03 04:17 - 2016-07-16 13:47 - 00000000 __SHD C:\Program Files\Windows Sidebar
2016-09-03 04:17 - 2016-07-16 13:47 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2016-09-03 04:17 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-09-03 04:17 - 2010-08-30 11:01 - 00000000 ____D C:\Program Files (x86)\Intel
2016-09-03 04:17 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games
2016-09-03 04:15 - 2016-01-25 17:24 - 00000000 ____D C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2016-09-03 04:10 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-09-03 04:08 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-09-03 04:08 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-09-03 04:08 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-09-03 04:07 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Help
2016-09-03 03:18 - 2016-07-17 01:55 - 00000000 ___HD C:\$WINDOWS.~BT
2016-09-03 03:00 - 2015-06-14 23:43 - 00001150 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-03 02:59 - 2013-11-17 18:21 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-09-03 02:00 - 2015-06-14 23:43 - 00001146 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-02 11:15 - 2016-08-01 17:14 - 00004096 _____ C:\Users\Public\Documents\0000D07B.LCS
2016-09-02 08:32 - 2014-03-02 09:31 - 00000000 ____D C:\Users\MM\AppData\Roaming\FileAdvisor
2016-08-30 16:29 - 2011-02-26 23:09 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-08-29 21:50 - 2015-07-05 13:51 - 00000000 ____D C:\Users\MM\AppData\Roaming\Skype
2016-08-29 14:19 - 2016-04-07 10:07 - 00000000 ____D C:\Users\MM\Desktop\SSA
2016-08-26 07:43 - 2016-07-16 13:49 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-08-26 07:43 - 2016-07-16 13:49 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-08-17 17:24 - 2016-01-25 17:23 - 00000000 ____D C:\Program Files (x86)\Overwolf
2016-08-15 19:23 - 2016-08-01 17:14 - 00000000 ____D C:\Users\MM\AppData\Roaming\Promotion Software GmbH
2016-08-15 13:49 - 2014-03-12 21:49 - 00000000 ____D C:\ProgramData\Electronic Arts
2016-08-15 13:42 - 2016-02-23 11:12 - 00000000 ____D C:\Users\MM\AppData\Local\CrashDumps
2016-08-15 13:40 - 2014-06-29 08:02 - 00000000 ____D C:\Users\MM\Desktop\Neuer Ordner (3)
2016-08-10 07:26 - 2013-11-17 11:16 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-08-10 07:15 - 2011-06-06 10:19 - 147640136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-08-09 16:34 - 2015-12-19 14:22 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-08-09 16:34 - 2015-07-05 13:50 - 00000000 ____D C:\ProgramData\Skype
2016-08-08 23:03 - 2015-06-14 23:44 - 00002268 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-03-14 17:06 - 2011-03-14 17:06 - 32742184 _____ () C:\Program Files\Virtualdj_home_v7.0.3.msi
2015-12-23 17:17 - 2015-12-23 17:17 - 0000218 _____ () C:\Users\MM\AppData\Local\recently-used.xbel
2016-03-29 20:04 - 2016-03-29 20:04 - 0000057 _____ () C:\ProgramData\Ament.ini
2010-08-30 11:12 - 2010-03-03 00:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe

Einige Dateien in TEMP:
====================
C:\Users\MM\AppData\Local\Temp\avgnt.exe
C:\Users\MM\AppData\Local\Temp\libeay32.dll
C:\Users\MM\AppData\Local\Temp\msvcr120.dll
C:\Users\MM\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-09-03 04:02

==================== Ende von FRST.txt ============================
         

Alt 04.09.2016, 07:05   #2
Calinjar
 
Laptop Windows 10 - ziemlich vollgemüllt! - Standard

Laptop Windows 10 - ziemlich vollgemüllt!



Addition.txt
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 31-08-2016
durchgeführt von MM (04-09-2016 07:53:53)
Gestartet von C:\Users\MM\Desktop
Windows 10 Home Version 1607 (X64) (2016-09-03 02:53:46)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-1669543924-1338975548-1525228061-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1669543924-1338975548-1525228061-503 - Limited - Disabled)
Gast (S-1-5-21-1669543924-1338975548-1525228061-501 - Limited - Disabled)
MM (S-1-5-21-1669543924-1338975548-1525228061-1001 - Administrator - Enabled) => C:\Users\MM

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

µTorrent (HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\uTorrent) (Version: 3.4.6.42094 - BitTorrent Inc.)
Acer Backup Manager (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.68 - NewTech Infosystems)
Acer Crystal Eye webcam (HKLM-x32\...\{51F026FA-5146-4232-A8BA-1364740BD053}) (Version: 1.0.4.5 - Liteon)
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.00.3005 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0707.2010 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Ad-Aware Web Companion (x32 Version: 2.0.1013.2086 - Lavasoft) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Adobe Reader X (10.1.1) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.1 - Adobe Systems Incorporated)
Age of Wonders III (HKLM\...\Steam App 226840) (Version:  - Triumph Studios)
Backup Manager Basic (x32 Version: 2.0.0.68 - NewTech Infosystems) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
EMERGENCY 2016 (HKLM\...\EMERGENCY 2016) (Version:  - Sixteen Tons Entertainment)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
File Type Advisor 1.4 (HKLM-x32\...\File Type Advisor_is1) (Version:  - filetypeadvisor.com)
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version:  - Oberon Media)
GEAR driver installer for AMD64 and Intel EM64T (HKLM\...\{50CBBEC7-1010-41C5-8718-A1A6FEDD9C3A}) (Version: 2.003.1 - GEAR Software, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Happy Cloud Client (HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\HappyCloud) (Version: 4.28 - Happy Cloud, Inc.)
Heroes of Hellas (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}) (Version:  - Oberon Media)
HP Deskjet 2540 series - Grundlegende Software für das Gerät (HKLM\...\{333E22D7-9F56-4482-A13C-1B9D35B9D641}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
Inkscape 0.91 (HKLM-x32\...\Inkscape) (Version: 0.91 - )
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2182 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
ITHau.Faktura 2013.11.20 (HKLM-x32\...\Freeware Faktura) (Version: 2013.11.20 - IT-Service Christian Hau)
iTunes (HKLM\...\{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}) (Version: 12.1.0.71 - Apple Inc.)
Java(TM) 6 Update 26 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216018FF}) (Version: 6.0.260 - Sun Microsystems, Inc.)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\...\LManager) (Version: 4.0.14 - Acer Inc.)
LavasoftTcpService (x32 Version: 2.3.4.2 - Lavasoft) Hidden
League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Merriam Websters Spell Jam (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}) (Version:  - Oberon Media)
Microsoft Office Excel Viewer (HKLM-x32\...\{95120000-003F-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 48.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 48.0.2 (x86 de)) (Version: 48.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 48.0.2.6079 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\...\InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}) (Version: 3.1.212.0 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden
NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8939 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.8939 - NTI Corporation) Hidden
NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5997 - NVIDIA Corporation)
NVIDIA Grafiktreiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
OpenOffice.org 3.2 (HKLM-x32\...\{192A107E-C6B9-41B9-BDBF-38E3AA226054}) (Version: 3.2.9483 - OpenOffice.org)
Opera Stable 20.0.1387.91 (HKLM-x32\...\Opera 20.0.1387.91) (Version: 20.0.1387.91 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.97.31.0 - Overwolf Ltd.)
Poker Pop (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111355427}) (Version:  - Oberon Media)
ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: 11.0.0.14 - ProtectDisc Software GmbH)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6141 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30122 - Realtek Semiconductor Corp.)
Screensaver for POS (x32 Version: 1.0.0 - Storecast GmbH, Germany) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden
Shredder (Version: 2.0.8.3 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.3 - Egis Technology Inc.) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Songr (HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\Songr) (Version: 2.0.2378 - Xamasoft)
Spin & Win (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}) (Version:  - Oberon Media)
Stardew Valley (HKLM-x32\...\Steam App 413150) (Version:  - ConcernedApe)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 2540 series (HKLM\...\{98802D44-4885-41EA-9BA8-96A117ECF223}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.39052 - TeamViewer)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
thriXXX 3DSexVilla2-153.001 (HKLM-x32\...\3DSexVilla2-153.001) (Version:  - thriXXX Software GmbH)
thriXXX WebLaunch (HKLM-x32\...\thriXXX WebLaunch) (Version: 1.0 - thriXXX)
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3010.1 - TuneUp Software) Hidden
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
VirtualDJ Home FREE (HKLM-x32\...\{19192A84-6172-4312-A661-D8F9A34585AB}) (Version: 7.0.4.1 - Atomix Productions)
VirtualDJ PRO Full (HKLM-x32\...\{4769E972-2E92-49C5-B6F9-465EFD0C4D94}) (Version: 7.0.5 - Atomix Productions)
Web Companion (HKLM-x32\...\{d6e3fcc2-3043-4fa9-ac4a-5bd9145d1a9e}) (Version: 2.1.1265.2535 - Lavasoft)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3004 - Acer Incorporated)
Windows Live Anmelde-Assistent (HKLM-x32\...\{52B97218-98CB-4B8B-9283-D213C85E1AA4}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileCoAuth.exe (Microsoft Corporation)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {08798CFB-DDF9-4444-B732-299ECDA8A973} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08] (Sun Microsystems, Inc.)
Task: {0A9D94A7-228F-4E54-ACFC-640C6FFD6008} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {19639003-C77D-4B18-A332-8DD151EC2CEE} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {1EF41258-2361-4435-B500-B774E7C9A65B} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {21AE865E-E468-4C66-867A-FF05FB272454} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {25E443D9-FDDD-4FF6-A6AD-851434DBDE77} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-08-14] (Overwolf LTD)
Task: {271C0386-D54D-4A89-B34C-25C482A17FF9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-14] (Google Inc.)
Task: {27EC5ADC-D1B8-4257-81FF-FB7B2866CD41} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {2A962F0F-2974-404E-A78F-4467E9EEB137} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {2C256425-F33F-4FFC-BBC1-55568D4C0405} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
Task: {2C6CE008-C8D9-43A4-BE6E-1577ECF7BDEE} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {30E277BB-AD19-4955-AF85-60BD9730D343} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd)
Task: {3510A4A3-A209-42AA-9D63-ED2A2BB7397A} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {3619DDEB-01D8-4AEF-BA75-2F893C3AB41D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {3B438481-7716-48C7-8F26-CDDCB32B72DB} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {4100373C-75FD-4D2B-BB49-7BF3EB34E54E} - System32\Tasks\{32D6F56B-7833-457F-9718-457689953BF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.1.0.179.367/de/abandoninstall?source=lightinstaller&amp;page=tsOptions&amp;installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;notincluded
Task: {57331538-E388-41D4-AEB2-0B9A6B2B9B01} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {5F20C597-0BD8-48E1-95E0-0871A15CA3E8} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {66411273-9DF4-47B4-9B75-944299189921} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {69B6444B-BFF6-4CA3-9D1A-400E43C66C05} - System32\Tasks\{F3EA1D55-FD45-431E-B847-554D475A3F6C} => Firefox.exe hxxp://ui.skype.com/ui/0/4.1.0.179.367/de/abandoninstall?source=lightinstaller&amp;page=tsMain&amp;installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;notincluded
Task: {6B03AB12-F40F-4417-A139-84B6A70EB610} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {73F9B103-3EE7-4B05-8D4E-40F0CCC962A9} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-08-17] (Microsoft Corporation)
Task: {757B2DC7-58A5-4F77-A711-5C3493D90F88} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {7B07EB25-D90B-42A0-8AEC-82F95314ADA2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {82B45B36-6237-4F43-975D-C6ECC37A25CE} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-09-05] (filetypeadvisor.com                                         )
Task: {868BFDBC-C5C8-4363-B770-658518AA278E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {8AD66453-92BC-475A-A5FB-2AE8237E961C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-08-10] (Microsoft Corporation)
Task: {8F158D86-9AFB-455C-B00B-7E929DD83D81} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {9192218C-A91F-4FE3-874B-0F3A6EB8F85C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {921F0D5F-50B5-4D5F-81C5-FF2278365DC2} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {97696FC3-36DC-4F2D-B4EC-72E2A847B77D} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {9C26BBD8-C3A0-42F9-BB27-9BA1C4665722} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {9EBAFC53-E906-47E6-BDAC-F007A73F0184} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-14] (Google Inc.)
Task: {A8CB5879-61D0-4488-936D-BE917FB72D36} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {B22B4BB8-C7B5-4905-96DE-FECC25B22D28} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Keine Datei <==== ACHTUNG
Task: {B3143ED4-CA6B-42CB-BA0E-5808C049D0B3} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-09-04] (File Type Advisor)
Task: {B3FC0613-3EB0-44A7-B33F-D2CF847E1726} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {B7BB9DB2-5AB7-4FC7-869F-07EA042B77FB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {BBC27A08-F6A9-4DEC-8CAB-19D9FEA5533D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {C5A4AAF9-FCA8-444B-B0D4-716823EA71DD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {CB45435D-F51C-461E-8BCC-59BADDF06F66} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {D3E12E90-512B-4A37-A984-24A94839BC0B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-12] (Adobe Systems Incorporated)
Task: {DA0A6D3E-E0BB-46D6-B33A-A2BAE3B5823B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {DD7DE760-6056-4A7D-8D5A-1BB224CB9308} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {DEB4E9AC-5C50-4B77-AA52-4EA4F3B5EA0B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {E59AE448-17AF-4A00-A1CF-965288D9856C} - System32\Tasks\{71547766-FA89-4004-9203-F3F410888270} => launchwinapp.exe hxxp://ui.skype.com/ui/0/7.18.85.112/de/abandoninstall?page=tsMain
Task: {E5C357C7-9935-49C6-B5D1-5EAB992C1C2C} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {EAE8F0A1-96E1-41C2-9C75-DFD74D91AE69} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {EB87C302-8830-44E2-93D8-A80193AE26A6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {EC9FE113-BB82-47AC-84D1-8A6BB184763C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {ED3227B2-FB7B-44AF-8BCC-8D020B07C8A6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {F26141CE-E1E5-4FCB-AC75-5709BF949E68} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {F40D7047-305C-44D2-8853-4B75B1B5BBF9} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {FAD93FFC-0011-4077-BC6B-199970C92E59} - System32\Tasks\{46FDBF1B-2F00-4BEB-910C-C50DB49D1A4E} => pcalua.exe -a F:\install_flash_player.exe -d F:\
Task: {FAEA0EDC-C25E-4820-866B-01CBC081F2C1} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {FFA0B3AE-525E-48CE-BAAB-D4B166BB9631} - System32\Tasks\{067A521F-C03C-4F1A-A33C-E4B44A20E46A} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=4.1.0.179.367&amp;LastError=12007

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

Shortcut: C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\Online Help.lnk -> hxxp://www.virtualdj.com/wiki/
Shortcut: C:\Users\MM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\www.virtualdj.com.lnk -> hxxp://www.virtualdj.com/

ShortcutWithArgument: C:\Users\MM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX
ShortcutWithArgument: C:\Users\MM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.mystartsearch.com/?type=sc&ts=1425240946&from=smt&uid=HitachiXHTS545050B9A300_101017PBN404B7FBYJALX

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-09-03 04:07 - 2015-12-16 16:54 - 00126256 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-01-19 20:43 - 2015-12-16 18:59 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-09-03 11:11 - 2016-09-03 11:11 - 01864384 _____ () C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\amd64\ClientTelemetry.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00130048 _____ () C:\WINDOWS\SYSTEM32\CHARTV.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-07-16 13:43 - 2016-07-16 13:43 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2012-11-27 00:54 - 2012-11-27 00:54 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-11-16 18:55 - 2015-11-16 18:55 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2016-07-16 13:43 - 2016-07-17 00:56 - 09761280 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-07-16 13:43 - 2016-07-17 00:56 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-07-16 13:43 - 2016-07-17 00:56 - 01033728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 02438144 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-09-03 04:56 - 2016-09-03 04:56 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-09-03 11:09 - 2016-09-03 11:11 - 01383616 _____ () C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\ClientTelemetry.dll
2016-09-03 11:14 - 2016-09-03 11:14 - 00118976 _____ () C:\Users\MM\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncViews.dll
2010-08-30 11:45 - 2009-05-20 08:02 - 00072200 _____ () C:\Program Files (x86)\Launch Manager\CdDirIo.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\ProgramData\Temp:798A3728 [250]
AlternateDataStreams: C:\ProgramData\Temp:93EB7685 [300]
AlternateDataStreams: C:\ProgramData\Temp:CDFF58FE [288]
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D [129]

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\localhost -> localhost

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2012-03-17 20:34 - 00000860 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 secure.tune-up.com

==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

MSCONFIG\startupreg: mwlDaemon => C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
MSCONFIG\startupreg: SuiteTray => "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1669543924-1338975548-1525228061-1001\...\StartupApproved\Run: => "Skype"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{6596FFDC-7FE7-4A88-99D7-CEDE81883B23}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{CF9A20C3-7AEE-4DD0-A679-8DB0365286BD}] => (Allow) C:\Program Files (x86)\Emergency 2016\bin\x64r\emergency5.exe
FirewallRules: [{714C21CD-17FE-4CD8-9F59-FA025C9A809B}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{0A40B483-B8E3-4C58-A04B-5BD93A6EDDB9}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{1014C0D5-FA60-4922-B908-15D2DB542D74}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{CF8DAE82-421F-46D4-B713-864CACCA616F}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{667A5E1D-6809-4005-A7B9-254AA2922B95}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{807D104E-5101-4BC4-8AAB-23F2FFD958D1}] => (Allow) C:\Users\MM\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{7E0F7427-E995-4066-B266-6794AFBF1A57}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{721EAAC1-6054-45BC-BF64-03F36E43E75A}] => (Allow) LPort=5357
FirewallRules: [{62463BA9-2908-4B90-82F6-B9FA037E6713}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\DeviceSetup.exe
FirewallRules: [{016D1AAD-3A92-48D8-A128-563CC3690F1F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stardew Valley\Stardew Valley.exe
FirewallRules: [{CC2D7DF0-87FF-42E9-A6A7-ED4D5DF90B31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stardew Valley\Stardew Valley.exe
FirewallRules: [{2BC12A8C-3FC2-4977-9078-0CD61E1CCCAD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{E572ABC1-5480-4244-AB96-229DA15AB318}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{942517F2-A473-45CE-A158-87548B98D89A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{7AF68B21-F7F0-4379-B953-6C9E0366243B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{78BC8548-9507-4383-8321-90EB37A206D2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{AEF1267F-DA14-4368-AB68-934EB232BB89}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{A1F13B90-8332-41A4-8476-D2BBB33AE57A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{884A71EA-1E95-4D62-8CA6-1570CB0DF30C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{2A7DBD6F-9195-4BA6-80C9-A6B57F5D92F7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ED1FAC01-D73E-428E-AA2A-321DDC5385C7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{FA9D4E50-78A6-47E7-AC89-686D33D0B7EA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{07334558-0CE9-4375-8824-0E926CCEB3BB}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe
FirewallRules: [{1C081AE0-33AF-4820-A52B-52E202294289}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [TCP Query User{E9B1FF08-3465-4876-954B-AED6B5619F4B}C:\windows\syswow64\dpnsvr.exe] => (Block) C:\windows\syswow64\dpnsvr.exe
FirewallRules: [UDP Query User{24A8CEFF-1F6A-46B7-A191-2D18AE69EA24}C:\windows\syswow64\dpnsvr.exe] => (Block) C:\windows\syswow64\dpnsvr.exe
FirewallRules: [{721C6183-1324-4A22-9B14-24E9B67EC4DE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8F5C15AF-01C6-48F5-97FA-516117AFC5B4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FD539E59-0CD6-4D10-8F96-76C71E22B8D7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FF349834-7C8E-4C58-BFB4-A6223374B91A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{CD42AD52-6DA8-4B24-A34C-B42ACA41E6A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3.exe
FirewallRules: [{86FE8263-C1BB-44A1-887D-8689D2C7AC9F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3.exe
FirewallRules: [{46F9961A-9F91-4CC3-A653-E7DD525F2894}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3_Debug.exe
FirewallRules: [{A1343DB2-FEC5-4987-8F7E-6002969D6F99}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3_Debug.exe
FirewallRules: [TCP Query User{B5422021-7111-4D66-A230-53CD8289C8E8}C:\program files (x86)\steam\steamapps\common\aow3\aow3.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\aow3\aow3.exe
FirewallRules: [UDP Query User{5F4935CE-1088-4854-8DC1-3264984699D3}C:\program files (x86)\steam\steamapps\common\aow3\aow3.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\aow3\aow3.exe
FirewallRules: [{583A2132-6DF1-4C37-9DD2-9A020780ACEA}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{A5829E81-A004-4615-912C-B8A414B8D4C8}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{C42C582A-1D60-4292-9596-43AA9BD33C17}C:\users\mm\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mm\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{98A86413-AA27-4E95-BE4F-EBFA14B73550}C:\users\mm\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mm\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{3D2328B1-B57E-41BC-BD92-90AEA5560A0D}C:\users\mm\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\mm\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{21A0030D-3525-4B99-ADB0-76614F31F258}C:\users\mm\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\mm\appdata\local\akamai\netsession_win.exe
FirewallRules: [{BEBC9B44-5B9D-4E6A-83A9-F05173DB8BF8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{778EE8DB-9C04-48DD-86CB-B556CC39DC63}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CDC6CDFB-9778-429B-8C24-C5DD0842BED6}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{E40CEEAB-906B-4F3D-BD4F-66F1952071E4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{0F5C6FFE-E656-4C7E-9848-8F20F1906F32}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{243B8960-0A22-41AB-9824-7A965547A55B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{923D60F3-37AA-496E-9837-1BAADA79D34F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{0DFB7521-7449-4C58-A473-DAE8A9A216FF}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{AFCED6E2-75A3-4919-896E-725D07656E46}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{4298EABA-E23C-49E0-927A-14ACA0A9C35D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3Launcher.exe
FirewallRules: [{43372A2D-1579-4702-98F8-ADA4732B70F3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AoW3\AoW3Launcher.exe
FirewallRules: [{C6F3AAA2-C8BE-4A42-8E57-3F9A984A38B4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{43063579-5942-44A3-BD66-10203A6DB15F}] => (Allow) LPort=49187
FirewallRules: [{5A8031EF-62B5-413E-952C-BB32193AB3E5}] => (Allow) LPort=5000
FirewallRules: [{2191F477-D6BE-4DC0-8EA1-4DA0D3E8EF2F}] => (Block) C:\WINDOWS\systemapps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe

==================== Wiederherstellungspunkte =========================

03-09-2016 07:10:17 Windows Update

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (09/04/2016 07:53:49 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (09/04/2016 07:53:49 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_2d0f50fcbdb171b8.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_74bc87d3d22d9abe.manifest.

Error: (09/04/2016 07:50:53 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\windows live\messenger\wlcsdk.exe".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (09/04/2016 07:49:03 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile  8.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (09/04/2016 07:46:10 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "c:\program files (x86)\eset\eset online scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_2d0f50fcbdb171b8.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_74bc87d3d22d9abe.manifest.

Error: (09/04/2016 04:09:13 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (09/04/2016 04:09:12 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_2d0f50fcbdb171b8.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.0_none_74bc87d3d22d9abe.manifest.

Error: (09/04/2016 04:08:23 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\windows live\messenger\wlcsdk.exe".
Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (09/04/2016 04:08:02 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" in Zeile  8.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (09/04/2016 04:05:52 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" in Zeile 3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.


Systemfehler:
=============
Error: (09/04/2016 02:03:50 AM) (Source: DCOM) (EventID: 10005) (User: NT-AUTORITÄT)
Description: Fehler "1053" in DCOM, als der Dienst "gupdate" mit den Argumenten "/comsvc" gestartet wurde, um den folgenden Server zu verwenden:
{4EB61BAC-A3B6-4760-9581-655041EF4D69}

Error: (09/04/2016 02:03:50 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (09/04/2016 02:03:50 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Google Update-Dienst (gupdate) erreicht.

Error: (09/03/2016 11:03:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Treiber konnte nicht geladen werden.

Error: (09/03/2016 11:03:58 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\MM\AppData\Local\Temp\ehdrv.sys

Error: (09/03/2016 11:03:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Treiber konnte nicht geladen werden.

Error: (09/03/2016 11:03:57 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\MM\AppData\Local\Temp\ehdrv.sys

Error: (09/03/2016 11:03:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Treiber konnte nicht geladen werden.

Error: (09/03/2016 11:03:57 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\MM\AppData\Local\Temp\ehdrv.sys

Error: (09/03/2016 11:02:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Treiber konnte nicht geladen werden.


CodeIntegrity:
===================================
  Date: 2016-09-04 06:37:59.020
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:59.018
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:59.015
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:59.005
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:59.003
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:59.000
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:58.990
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:58.988
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:58.986
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-09-04 06:37:58.976
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i3 CPU M 380 @ 2.53GHz
Prozentuale Nutzung des RAM: 50%
Installierter physikalischer RAM: 3766.7 MB
Verfügbarer physikalischer RAM: 1867.48 MB
Summe virtueller Speicher: 7606.7 MB
Verfügbarer virtueller Speicher: 5356.28 MB

==================== Laufwerke ================================

Drive c: (Acer) (Fixed) (Total:452.22 GB) (Free:100.06 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 40731DA7)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=452.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=450 MB) - (Type=27)

==================== Ende von Addition.txt ============================
         
__________________


Alt 06.10.2016, 10:08   #3
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Laptop Windows 10 - ziemlich vollgemüllt! - Standard

Laptop Windows 10 - ziemlich vollgemüllt!





Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...
  • Bitte arbeite alle Schritte der Reihe nach ab.
  • Lies die Anleitungen sorgfältig durch bevor Du beginnst. Wenn es Probleme gibt oder Du etwas nicht verstehst, dann stoppe mit Deiner Ausführung und beschreibe mir das Problem.
  • Führe bitte nur Scans durch, zu denen Du von mir aufgefordert wurdest.
  • Bitte kein Crossposting (posten in mehreren Foren).
  • Installiere oder deinstalliere während der Bereinigung keine Software, außer Du wurdest dazu aufgefordert.
  • Speichere alle unsere Tools auf dem Desktop ab. Link: So ladet Ihr unsere Tools richtig
  • Poste die Logfiles direkt in Deinen Thread in Code-Tags.
  • Bedenke, dass wir hier alle während unserer Freizeit tätig sind, wenn du innerhalb von 24 Stunden nichts von mir liest, dann schreibe mir bitte eine PM.

Hinweis:
Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden.
Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert.
Adware & Co. können wir sehr gut entfernen.
Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean bekommst.


Los geht's:

Schritt 1
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.
__________________
__________________

Antwort

Themen zu Laptop Windows 10 - ziemlich vollgemüllt!
adobe, akamai, avg, defender, explorer, fehler, firefox, flash player, google, home, homepage, infizierte, langsam, launch, malware, mozilla, mp3, prozesse, realtek, registry, revo uninstaller, rundll, services.exe, svchost.exe, teamspeak, trojaner, windows, windowsapps




Ähnliche Themen: Laptop Windows 10 - ziemlich vollgemüllt!


  1. Windows XP Asus Eee PC wieder einmal ziemlich langsam geworden
    Plagegeister aller Art und deren Bekämpfung - 06.01.2016 (1)
  2. Windows 7 - Webseiten durch Spam ersetzt / vollgemüllt
    Log-Analyse und Auswertung - 18.12.2015 (7)
  3. Laptop wird langsamer, CPU Auslastung oftmals ziemlich hoch und treibt den Lüfter in den Wahnsinn
    Plagegeister aller Art und deren Bekämpfung - 25.10.2015 (13)
  4. Notebook langsam und vollgemüllt
    Plagegeister aller Art und deren Bekämpfung - 11.11.2014 (15)
  5. Windows 8, fährt ziemlich langsam hoch, AVIRA Scan zeigt funde
    Log-Analyse und Auswertung - 05.08.2014 (7)
  6. BKA Trojaner..so ziemlich nichts funktioniert
    Plagegeister aller Art und deren Bekämpfung - 10.07.2012 (7)
  7. Neuer laptop dauert ziemlich lange bis er hochgefahren ist
    Plagegeister aller Art und deren Bekämpfung - 26.06.2012 (2)
  8. Computer vollgemüllt, langsam, seltsame dateien
    Log-Analyse und Auswertung - 02.03.2010 (2)
  9. Laptop allgemein ziemlich langsam geworden
    Log-Analyse und Auswertung - 06.06.2009 (9)
  10. PC auf einmal ziemlich langsam!
    Log-Analyse und Auswertung - 29.08.2006 (6)
  11. Computer läuft ziemlich langsam!!
    Log-Analyse und Auswertung - 10.07.2006 (1)
  12. Hilfe! PC ziemlich lahm!
    Log-Analyse und Auswertung - 31.03.2006 (1)
  13. Computer läuft ziemlich langsam! -> Log
    Log-Analyse und Auswertung - 16.10.2005 (1)
  14. Ziemlich viele plagegeister^^
    Log-Analyse und Auswertung - 20.02.2005 (11)
  15. Verzweifelt... Ziemlich...!
    Log-Analyse und Auswertung - 12.02.2005 (8)
  16. ziemlich verzweifelt
    Plagegeister aller Art und deren Bekämpfung - 06.09.2004 (9)
  17. winsvs32.exe - ziemlich hartnäckig
    Plagegeister aller Art und deren Bekämpfung - 13.08.2004 (3)

Zum Thema Laptop Windows 10 - ziemlich vollgemüllt! - Hallo Trojaner, ein Bekannter von mir, bat mich, mal nach seinem Laptop zu sehen, der u.a. beim Hochfahren, Spielen, Öffnen von Programmen sehr bzw. ziemlich langsam ist. Das Betriebssystem wurde - Laptop Windows 10 - ziemlich vollgemüllt!...
Archiv
Du betrachtest: Laptop Windows 10 - ziemlich vollgemüllt! auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.