|
Log-Analyse und Auswertung: Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.12.2016, 20:47 | #16 |
| Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-12-2016 durchgeführt von totti (10-12-2016 20:40:48) Run:1 Gestartet von C:\Users\totti\Downloads Geladene Profile: Thorsten & ttjh1 & totti (Verfügbare Profile: Thorsten & ttjh1 & totti) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** CloseProcesses: C:\ProgramData\Logishrd\LogiOptions\Software\Current\dma_x64.dll C:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat C:\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe C:\Users\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe C:\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm C:\Users\Thorsten\Downloads\Options_6.30.80 (1).exe C:\Users\Thorsten\Downloads\Options_6.30.80.exe C:\Users\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe C:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll C:\Windows.old\Users\Thorsten\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00659b C:\Windows.old\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\VZR6RD7Z\logioptions_logitech[1].exe C:\Windows.old\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe C:\Windows.old\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe D:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll D:\Users\Thorsten\Downloads\HP USB Disk Storage Format Tool - CHIP-Installer.exe D:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll F:\Documents and Settings\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat F:\Documents and Settings\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe F:\Documents and Settings\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm F:\Documents and Settings\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe F:\Documents and Settings\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe F:\Documents and Settings\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe F:\Documents and Settings\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm F:\Documents and Settings\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm F:\Documents and Settings\Thorsten\Downloads\Options_6.30.80 (1).exe F:\Documents and Settings\Thorsten\Downloads\Options_6.30.80.exe F:\Documents and Settings\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe F:\HOME-PC\Backup Set 2015-10-11 200835\Backup Files 2015-10-11 200835\Backup files 8.zip F:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll F:\Users\Thorsten\AppData\Local\Temp\is1070216317\MyBabylonTB.exe F:\Users\Thorsten\AppData\Roaming\OpenCandy\OpenCandy_0181FAC22AA54A5D97FBE1D8AA98F393\LinkuryInstaller.msi F:\Users\Thorsten\AppData\Roaming\OpenCandy\OpenCandy_0181FAC22AA54A5D97FBE1D8AA98F393\LinkuryInstaller_p1v5.exe G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R09HRF2.exe G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R1K4JDO.exe G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R27UN9B.exe G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RCK5YYL.exe G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RLW6BJZ.exe G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RVOUJKL.exe G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RXWAU53.exe G:\Program Files\ConduitEngine\ConduitEngine.dll G:\Program Files\ConduitEngine\ConduitEngineUninstall.exe G:\Program Files\DAEMON Tools Pro\DTCommonRes.dll G:\Program Files\Driver Pro\DPSchedule.exe G:\Program Files\Driver Pro\DPSmartScan.exe G:\Program Files\Driver Pro\DPUninstaller.exe G:\Program Files\Driver Pro\DriverPro.exe G:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll G:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\ads_only_5_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\arcadi2_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\corticas_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\cortica_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\coupish_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\dealply_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\intext_fa_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\monetizationLoader[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\monetizationLoader[2].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\resources_background[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\similar_web_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\widdit_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8NFWNK03\pack[2].7z G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\ads_only_5_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\appApiMessage[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\coupish_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\getdeal_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\intext_5_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\intext_adv_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\jollywallet_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\revizer_p_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\similar_web_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\SingAlong_1060-1052_v114[1] G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\superfish_no_coupons_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\superfish_no_coupons_m[2].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\corticas_ru_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\cortica_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\coupons_intext_ads_5_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\icm_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\jollywallet_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\luck_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\superfish_no_search_no_coupons_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\superfish_pricora_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\arcadi3_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\coupons_intext_ads_5_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\CrossriderUtils[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\dealply_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\ibario_pops_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\icm_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\intext_5_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\luck_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\pack[1].7z G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\revizer_ws_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\superfish_m[1].js G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\superfish_m[2].js G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\1\92\A5268d01 G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\3\16\CFB4Cd01 G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\4\39\9D74Bd01 G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\6\58\18A64d01 G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\8\AA\ED51Bd01 G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\A\B9\50C7Ed01 G:\Users\Jaqueline\AppData\Local\Smartbar\Application\BrowserHelper.exe G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Interop.SHDocVw.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\MACTrackBarLib.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\NDde.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Newtonsoft.Json.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\QuickShare.exe G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.Base.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.DefaultBrowser.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ShareManagerLocalPlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessEntities.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.PersonalizationSettingsManager.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.PublisherSettingsManager.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.UserSettingsManager.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.BrowserHelperUtils.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.GeneralUtilities.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProductsRemovalLibary.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProductUninstaller.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SetBrowsersSettings.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SetBrowsersSettingsAutoUpdater.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ShortcutsLibrary.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.XmlSerializers.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.Translations.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.UninstallScreen.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.UrlHistorySupplier.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe G:\Users\Jaqueline\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\ar\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\es\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\fr\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\he\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_20.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_21.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_22.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_23.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\it\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\pt\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\ru\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Application\tr\Smartbar.Resources.LanguageSettings.resources.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.DMP.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.NotepadPlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.ScreenCapturePlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.UninstallProductsPlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WordPlugin.dll G:\Users\Jaqueline\AppData\Local\Temp\2877.tmp G:\Users\Jaqueline\AppData\Local\Temp\BackupSetup.exe G:\Users\Jaqueline\AppData\Local\Temp\che50FF.tmp G:\Users\Jaqueline\AppData\Local\Temp\MixiDJToolbar.exe G:\Users\Jaqueline\AppData\Local\Temp\SingAlong.exe G:\Users\Jaqueline\AppData\Local\Temp\SmartbarExeInstaller.exe G:\Users\Jaqueline\AppData\Local\Temp\sngalng.exe G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\BabMaint.exe G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\BUSolution.dll G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\CrxInstaller.dll G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\delta1.crx G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\IEHelper.dll G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\MyBabylonTB.exe G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\Setup.exe G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BabMaint.exe G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BExternal.dll G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BUSolution.dll G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\CrxInstaller.dll G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\IEHelper.dll G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\mixiDj.crx G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\MyBabylonTB.exe G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\Setup.exe G:\Users\Jaqueline\AppData\Local\Temp\bus2A1\CrxUpdater_d.exe G:\Users\Jaqueline\AppData\Local\Temp\bus2BE0\BUSolution.dll G:\Users\Jaqueline\AppData\Local\Temp\bus425D\fntupdtr.exe G:\Users\Jaqueline\AppData\Local\Temp\bus58EA\BUSolution.dll G:\Users\Jaqueline\AppData\Local\Temp\busA6B\CrxUpdater_d.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\DomaIQ.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\DomaIQ10.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\exes.zip G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\installer.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Addlyrics.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Delta Babylon.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Format-Factory.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\OptimizerPro.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\DomaIQ.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\DomaIQ10.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\exes.zip G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\installer.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\DomaIQ.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\DomaIQ10.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\exes.zip G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\installer.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Driverpro.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Format-Factory G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Mixi Dj Yahoo.exe G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\QuickShare1.exe G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\BExternal.dll G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\IEHelper.dll G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Setup.exe G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\BExternal.dll G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\IEHelper.dll G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\MyBabylonTB.exe G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\Setup.exe G:\Users\Jaqueline\AppData\Local\Temp\ibtmpc810632\component_612.decrpt G:\Users\Jaqueline\AppData\Local\Temp\ibtmpc810632\component_625 G:\Users\Jaqueline\AppData\Local\Temp\nseC301.tmp\mt.dll G:\Users\Jaqueline\AppData\Local\Temp\nsz2378.tmp\mt.dll G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\LinkuryInstaller.msi G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\26bd7386-e546-41bb-ba63-886152ebd2d3\LinkuryInstaller.msi G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\934faaad-8ac9-423b-8166-8e363f9345cd\LinkuryInstaller.msi G:\Users\Jaqueline\AppData\Local\Temp\upd2348\BabMaint.x G:\Users\Jaqueline\AppData\Local\Temp\upd2348\BUSolution.x G:\Users\Jaqueline\AppData\Roaming\BabSolution\CR\delta1.crx G:\Users\Jaqueline\AppData\Roaming\BabSolution\Shared\BabMaint.exe G:\Users\Jaqueline\AppData\Roaming\BabSolution\Shared\BUSolution.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_20.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_21.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_22.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_23.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_24.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_20.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_21.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_22.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_23.dll G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_24.dll G:\Users\Jaqueline\Downloads\video_downloader.exe G:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll G:\Windows\Installer\5916a.msi G:\Windows\Temp\Optimizer_Pro.exe H:\Downloads\Dark_Theme - CHIP-Installer (1).exe H:\Downloads\Dark_Theme - CHIP-Installer (2).exe H:\Downloads\Dark_Theme - CHIP-Installer.exe H:\Downloads\MediaPortal - CHIP-Installer.exe H:\Downloads\micro SIM Schablone PDF Vorlage - CHIP-Installer.exe H:\Downloads\Nano SIM Schablone PDF Vorlage - CHIP-Installer.exe H:\Downloads\VLC media player 64 Bit - CHIP-Installer.exe H:\Downloads\Adobe Creative Cloud Collection 2015\Adobe Creative Cloud Collection 2015\Adobe Creative Cloud Collection 2015\Aktivierung für alle Versionen\XFORCE Cloud 2015\Adobe Block.cmd H:\Downloads\DAEMON Tools Pro Advanced v6.1.0.0483\DAEMON Tools Pro Advanced v6.1.0.0483.rar H:\Downloads\DAEMON Tools Pro Advanced v6.1.0.0483\DAEMON Tools Pro Advanced v6.1.0.0483\Activator_DTP\activator.exe H:\FileHistory\totti\HOME-PC\Data\$OF\979\981 (2015_10_14 22_35_17 UTC).cmd H:\Neuer Ordner (2)\Program Files (x86)\FunWebProducts\ H:\Neuer Ordner (2)\Program Files (x86)\Conduit H:\Neuer Ordner (2)\Neuer Ordner\Transcend\Alcohol 120% 2.0.2 Build 5830 Retail\Alcohol120_retail_2.0.2.5830.exe C:\Users\totti\Downloads\K-Lite_Codec_Pack_1265_Mega_CB-DL-Manager.exe CreateRestorePoint: EmptyTemp: ***************** Prozess erfolgreich geschlossen. C:\ProgramData\Logishrd\LogiOptions\Software\Current\dma_x64.dll => erfolgreich verschoben "C:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden. C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe => erfolgreich verschoben C:\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe => erfolgreich verschoben C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm => erfolgreich verschoben C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm => erfolgreich verschoben C:\Users\Thorsten\Downloads\Options_6.30.80 (1).exe => erfolgreich verschoben C:\Users\Thorsten\Downloads\Options_6.30.80.exe => erfolgreich verschoben C:\Users\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe => erfolgreich verschoben "C:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden. C:\Windows.old\Users\Thorsten\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00659b => erfolgreich verschoben C:\Windows.old\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\VZR6RD7Z\logioptions_logitech[1].exe => erfolgreich verschoben C:\Windows.old\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe => erfolgreich verschoben C:\Windows.old\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe => erfolgreich verschoben "D:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden. D:\Users\Thorsten\Downloads\HP USB Disk Storage Format Tool - CHIP-Installer.exe => erfolgreich verschoben "D:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden. "F:\Documents and Settings\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe" => nicht gefunden. "F:\Documents and Settings\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe" => nicht gefunden. "F:\Documents and Settings\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm" => nicht gefunden. "F:\Documents and Settings\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm" => nicht gefunden. "F:\Documents and Settings\Thorsten\Downloads\Options_6.30.80 (1).exe" => nicht gefunden. "F:\Documents and Settings\Thorsten\Downloads\Options_6.30.80.exe" => nicht gefunden. "F:\Documents and Settings\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe" => nicht gefunden. F:\HOME-PC\Backup Set 2015-10-11 200835\Backup Files 2015-10-11 200835\Backup files 8.zip => erfolgreich verschoben "F:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden. F:\Users\Thorsten\AppData\Local\Temp\is1070216317\MyBabylonTB.exe => erfolgreich verschoben F:\Users\Thorsten\AppData\Roaming\OpenCandy\OpenCandy_0181FAC22AA54A5D97FBE1D8AA98F393\LinkuryInstaller.msi => erfolgreich verschoben F:\Users\Thorsten\AppData\Roaming\OpenCandy\OpenCandy_0181FAC22AA54A5D97FBE1D8AA98F393\LinkuryInstaller_p1v5.exe => erfolgreich verschoben G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R09HRF2.exe => erfolgreich verschoben G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R1K4JDO.exe => erfolgreich verschoben G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R27UN9B.exe => erfolgreich verschoben G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RCK5YYL.exe => erfolgreich verschoben G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RLW6BJZ.exe => erfolgreich verschoben G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RVOUJKL.exe => erfolgreich verschoben G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RXWAU53.exe => erfolgreich verschoben G:\Program Files\ConduitEngine\ConduitEngine.dll => erfolgreich verschoben G:\Program Files\ConduitEngine\ConduitEngineUninstall.exe => erfolgreich verschoben G:\Program Files\DAEMON Tools Pro\DTCommonRes.dll => erfolgreich verschoben G:\Program Files\Driver Pro\DPSchedule.exe => erfolgreich verschoben G:\Program Files\Driver Pro\DPSmartScan.exe => erfolgreich verschoben G:\Program Files\Driver Pro\DPUninstaller.exe => erfolgreich verschoben G:\Program Files\Driver Pro\DriverPro.exe => erfolgreich verschoben "G:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden. G:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\ads_only_5_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\arcadi2_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\corticas_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\cortica_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\coupish_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\dealply_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\intext_fa_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\monetizationLoader[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\monetizationLoader[2].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\resources_background[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\similar_web_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\widdit_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8NFWNK03\pack[2].7z => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\ads_only_5_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\appApiMessage[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\coupish_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\getdeal_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\intext_5_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\intext_adv_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\jollywallet_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\revizer_p_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\similar_web_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\SingAlong_1060-1052_v114[1] => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\superfish_no_coupons_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\superfish_no_coupons_m[2].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\corticas_ru_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\cortica_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\coupons_intext_ads_5_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\icm_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\jollywallet_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\luck_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\superfish_no_search_no_coupons_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\superfish_pricora_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\arcadi3_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\coupons_intext_ads_5_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\CrossriderUtils[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\dealply_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\ibario_pops_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\icm_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\intext_5_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\luck_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\pack[1].7z => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\revizer_ws_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\superfish_m[1].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\superfish_m[2].js => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\1\92\A5268d01 => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\3\16\CFB4Cd01 => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\4\39\9D74Bd01 => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\6\58\18A64d01 => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\8\AA\ED51Bd01 => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\A\B9\50C7Ed01 => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\BrowserHelper.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Interop.SHDocVw.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\MACTrackBarLib.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\NDde.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Newtonsoft.Json.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\QuickShare.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.Base.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.DefaultBrowser.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ShareManagerLocalPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessEntities.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.PersonalizationSettingsManager.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.PublisherSettingsManager.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.UserSettingsManager.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.BrowserHelperUtils.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.GeneralUtilities.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProductsRemovalLibary.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProductUninstaller.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SetBrowsersSettings.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SetBrowsersSettingsAutoUpdater.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ShortcutsLibrary.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.XmlSerializers.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.Translations.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.UninstallScreen.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.UrlHistorySupplier.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\ar\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\es\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\fr\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\he\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_20.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_21.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_22.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_23.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\it\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\pt\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\ru\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Application\tr\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.DMP.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.NotepadPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.ScreenCapturePlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.UninstallProductsPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WordPlugin.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\2877.tmp => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\BackupSetup.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\che50FF.tmp => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\MixiDJToolbar.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\SingAlong.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\SmartbarExeInstaller.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\sngalng.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\BabMaint.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\BUSolution.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\CrxInstaller.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\delta1.crx => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\IEHelper.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\MyBabylonTB.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\Setup.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BabMaint.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BExternal.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BUSolution.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\CrxInstaller.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\IEHelper.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\mixiDj.crx => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\MyBabylonTB.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\Setup.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\bus2A1\CrxUpdater_d.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\bus2BE0\BUSolution.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\bus425D\fntupdtr.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\bus58EA\BUSolution.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\busA6B\CrxUpdater_d.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\DomaIQ.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\DomaIQ10.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\exes.zip => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\installer.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Addlyrics.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Delta Babylon.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Format-Factory.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\OptimizerPro.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\DomaIQ.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\DomaIQ10.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\exes.zip => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\installer.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\DomaIQ.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\DomaIQ10.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\exes.zip => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\installer.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Driverpro.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Format-Factory => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Mixi Dj Yahoo.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\QuickShare1.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\BExternal.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\IEHelper.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Setup.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\BExternal.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\IEHelper.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\MyBabylonTB.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\Setup.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\ibtmpc810632\component_612.decrpt => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\ibtmpc810632\component_625 => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\nseC301.tmp\mt.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\nsz2378.tmp\mt.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\LinkuryInstaller.msi => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\26bd7386-e546-41bb-ba63-886152ebd2d3\LinkuryInstaller.msi => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\934faaad-8ac9-423b-8166-8e363f9345cd\LinkuryInstaller.msi => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\upd2348\BabMaint.x => erfolgreich verschoben G:\Users\Jaqueline\AppData\Local\Temp\upd2348\BUSolution.x => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\BabSolution\CR\delta1.crx => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\BabSolution\Shared\BabMaint.exe => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\BabSolution\Shared\BUSolution.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_20.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_21.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_22.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_23.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_24.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_20.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_21.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_22.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_23.dll => erfolgreich verschoben G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_24.dll => erfolgreich verschoben G:\Users\Jaqueline\Downloads\video_downloader.exe => erfolgreich verschoben G:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll => erfolgreich verschoben G:\Windows\Installer\5916a.msi => erfolgreich verschoben G:\Windows\Temp\Optimizer_Pro.exe => erfolgreich verschoben H:\Downloads\Dark_Theme - CHIP-Installer (1).exe => erfolgreich verschoben H:\Downloads\Dark_Theme - CHIP-Installer (2).exe => erfolgreich verschoben H:\Downloads\Dark_Theme - CHIP-Installer.exe => erfolgreich verschoben H:\Downloads\MediaPortal - CHIP-Installer.exe => erfolgreich verschoben H:\Downloads\micro SIM Schablone PDF Vorlage - CHIP-Installer.exe => erfolgreich verschoben H:\Downloads\Nano SIM Schablone PDF Vorlage - CHIP-Installer.exe => erfolgreich verschoben H:\Downloads\VLC media player 64 Bit - CHIP-Installer.exe => erfolgreich verschoben H:\Downloads\Adobe Creative Cloud Collection 2015\Adobe Creative Cloud Collection 2015\Adobe Creative Cloud Collection 2015\Aktivierung für alle Versionen\XFORCE Cloud 2015\Adobe Block.cmd => erfolgreich verschoben H:\Downloads\DAEMON Tools Pro Advanced v6.1.0.0483\DAEMON Tools Pro Advanced v6.1.0.0483.rar => erfolgreich verschoben H:\Downloads\DAEMON Tools Pro Advanced v6.1.0.0483\DAEMON Tools Pro Advanced v6.1.0.0483\Activator_DTP\activator.exe => erfolgreich verschoben H:\FileHistory\totti\HOME-PC\Data\$OF\979\981 (2015_10_14 22_35_17 UTC).cmd => erfolgreich verschoben H:\Neuer Ordner (2)\Program Files (x86)\FunWebProducts => erfolgreich verschoben H:\Neuer Ordner (2)\Program Files (x86)\Conduit => erfolgreich verschoben H:\Neuer Ordner (2)\Neuer Ordner\Transcend\Alcohol 120% 2.0.2 Build 5830 Retail\Alcohol120_retail_2.0.2.5830.exe => erfolgreich verschoben "C:\Users\totti\Downloads\K-Lite_Codec_Pack_1265_Mega_CB-DL-Manager.exe" => nicht gefunden. Fehler: (0) Erstellen eines Wiederherstellungspunktes gescheitert. =========== EmptyTemp: ========== BITS transfer queue => 32768 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9784726 B Java, Flash, Steam htmlcache => 1268 B Windows/system/drivers => 15913094 B Edge => 136736752 B Chrome => 488054458 B Firefox => 25967206 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B NetworkService => -650 B Thorsten => 453483435 B ttjh1 => 29144378 B totti => 228443422 B RecycleBin => 0 B EmptyTemp: => 1.3 GB temporäre Dateien entfernt. ================================ Das System musste neu gestartet werden. ==== Ende von Fixlog 20:41:54 ==== |
11.12.2016, 17:32 | #17 |
/// TB-Ausbilder /// Anleitungs-Guru | Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? Gibt es jetzt noch Probleme mit dem PC? Wenn ja, welche?
__________________Schritt 1 Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Untersuchen. Bitte poste mir den Inhalt der beiden Logs die erstellt werden.
__________________ |
11.12.2016, 18:02 | #18 |
| Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-12-2016 durchgeführt von totti (11-12-2016 17:54:15) Gestartet von C:\Users\totti\Downloads Windows 10 Pro Version 1607 (X64) (2016-11-26 22:54:06) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-2586767532-3616519997-416612805-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2586767532-3616519997-416612805-503 - Limited - Disabled) Gast (S-1-5-21-2586767532-3616519997-416612805-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2586767532-3616519997-416612805-1005 - Limited - Enabled) jenny (S-1-5-21-2586767532-3616519997-416612805-1002 - Limited - Disabled) Thorsten (S-1-5-21-2586767532-3616519997-416612805-1001 - Limited - Enabled) => C:\Users\Thorsten totti (S-1-5-21-2586767532-3616519997-416612805-1006 - Administrator - Enabled) => C:\Users\totti ttjh1 (S-1-5-21-2586767532-3616519997-416612805-1003 - Administrator - Enabled) => C:\Users\ttjh1 ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov) AI Suite 3 (HKLM-x32\...\{CD36E28B-6023-469A-91E7-049A2874EC13}) (Version: 1.01.49 - ASUSTeK Computer Inc.) Apple Application Support (32-Bit) (HKLM-x32\...\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) Asmedia USB Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.26.1 - Asmedia Technology) ASUS Boot Setting (HKLM-x32\...\{7AAE9187-C24F-4073-A951-36C370E7A3A5}) (Version: 1.00.22 - ASUSTeK Computer Inc.) ASUS ROG Connect Plus (HKLM-x32\...\{ECF51D37-52ED-4871-BF8B-FEA34B8B4120}) (Version: 1.00.30 - ASUSTeK Computer Inc.) Asus Sonic Suite Plugins (HKLM-x32\...\{c5017606-8bde-4f85-94f4-ba61dcf59860}) (Version: 2.2.2801 - ASUSTeKcomputer.Inc) ASUS(R) Intel(R) Extreme Tuning Utility (HKLM-x32\...\{969659ef-5e6c-4c40-8aec-6b1bd3819fab}) (Version: 6.1.2.208 - Intel Corporation) ASUS(R) Intel(R) Extreme Tuning Utility (x32 Version: 6.1.2.208 - Intel Corporation) Hidden BioExcess (HKLM-x32\...\InstallShield_{596DEDA5-FE48-4078-96E0-E449DF5D08B2}) (Version: 7.1.5.27 - Egis Technology Inc.) BioExcess (Version: 7.1.5.27 - Egis Technology Inc.) Hidden BioExcess (x32 Version: 7.1.5.27 - Egis Technology Inc.) Hidden Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CheckDevicesConfigurator (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden EaseUS Todo PCTrans 9.0 (HKLM-x32\...\EaseUS Todo PCTrans_is1) (Version: - EaseUS) EgisTec Fingerprint Driver (HKLM-x32\...\InstallShield_{E8C889B8-0A8B-46BA-B433-F7D6968A6543}) (Version: 3.5.1.0 - Egis Technology Inc.) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Fingerprint Driver (x32 Version: 3.5.1.0 - Egis Technology Inc.) Hidden Front Base Driver (HKLM-x32\...\{3A02F836-5D7E-4DDE-ADAE-28DFA9B278DC}) (Version: 1.01.17 - ASUSTeK Computer Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.99 - Google Inc.) Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden HDClone 6 Free Edition (HKLM\...\Miray.HDClone.fe.6.0.7.1031-{9111A38F-76E7-40B5-8E0F-EE2C0E43230D}) (Version: 6 - Miray Software AG) Intel(R) Network Connections 20.2.4001.0 (HKLM\...\PROSetDX) (Version: 20.2.4001.0 - Intel) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation) iTunes (HKLM\...\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.) Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) K-Lite Mega Codec Pack 12.7.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 12.7.0 - KLCP) LauncherSetup (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden Logitech Options (HKLM\...\LogiOptions) (Version: - Logitech) Logitech Solar App 1.10 (HKLM\...\SolarApp) (Version: 1.10.3 - Logitech) Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft OneDrive (HKU\S-1-5-21-2586767532-3616519997-416612805-1006\...\OneDriveSetup.exe) (Version: 17.3.6720.1207 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40649 (HKLM-x32\...\{5d0723d3-cff7-4e07-8d0b-ada737deb5e6}) (Version: 12.0.40649.5 - Microsoft Corporation) Mozilla Firefox 50.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.0.2 (x86 de)) (Version: 50.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.0.2.6177 - Mozilla) NahimicSettingsConfigurator (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden ProductDaemonSetup (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7904 - Realtek Semiconductor Corp.) Revo Uninstaller Pro 3.1.7 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.7 - VS Revo Group, Ltd.) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.9.7 - Samsung Electronics) SonicRadarSetup (Version: 1.0.0.0 - ASUSTeKcomputer.Inc) Hidden SonicStudioSetup (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden SVLoadSense (HKLM-x32\...\{C4226734-F925-448C-8F15-0D5419F003DF}) (Version: 1.0.12 - SAVITECH) SyncFileSetup (x86) (x32 Version: 1.3.5949.26210 - Western Digital Technologies, Inc) Hidden TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.71503 - TeamViewer) TERRATEC Cinergy Hybrid Stick (64 Bit) (HKLM-x32\...\{53DE5511-BBC4-441D-AD55-6B8E23A3AA05}) (Version: 1.00.08.06 - TERRATEC Electronic GmbH) Terratec Cinergy T2 micro x64 Drivers (HKLM-x32\...\{170CB5DA-C9CB-4220-9044-54AD389EA9D5}) (Version: 10.00.0000 - Terratec) Terratec Cinergy TC2 x64 Drivers (HKLM-x32\...\{D507B4B1-4DA4-41D1-9F2F-7B2684C8778E}) (Version: 10.00.0000 - Terratec) WD Access (HKLM-x32\...\{046643f7-6206-46bb-8968-92c37fee39e0}) (Version: 1.4.5949.29996 - Western Digital Technologies, Inc.) WD Access (x32 Version: 1.4.5949.29996 - Western Digital Technologies, Inc) Hidden WD My Cloud (HKLM\...\{4B86F896-11DC-4711-BB60-81104832FA44}) (Version: 1.0.7.17 - Western Digital Technologies, Inc.) WD Quick View (HKLM-x32\...\{BE1B25F9-5A51-4DB8-81FA-CE0CABC14D07}) (Version: 2.4.10.17 - Western Digital Technologies, Inc.) WD Sync (HKLM-x32\...\{0d591303-bbc5-4645-a03b-1c3f75f1a762}) (Version: 1.3.5949.26210 - Western Digital Technologies, Inc.) WiFi Station N (HKLM-x32\...\{155314D4-C46C-434A-9297-643E260232C0}) (Version: 3.7.0.0 - Hercules) Windows-Treiberpaket - TerraTec (TTHID) HIDClass (05/21/2009 1.00.01.05) (HKLM\...\7051B1F240802F891754E1EFC6431B0D98C2DA65) (Version: 05/21/2009 1.00.01.05 - TerraTec ) Windows-Treiberpaket - TerraTec (UDXTTM6010) Media (05/14/2009 1.00.08.06) (HKLM\...\FCC6C304DBC4CB7CFCC0BEF0BCE1BEC491CD289D) (Version: 05/14/2009 1.00.08.06 - TerraTec ) Windows-Treiberpaket - Terratec (IT9300BDA) Media (05/11/2015 15.5.11.1) (HKLM\...\0A8AEA4C8078A11CEC9350331C879FDA0D9C649B) (Version: 05/11/2015 15.5.11.1 - Terratec) Windows-Treiberpaket - Terratec (IT9300BDA) Media (10/27/2016 10.0.195.447) (HKLM\...\77862757AE61D1BE0CE158F285743CE10665C5DB) (Version: 10/27/2016 10.0.195.447 - Terratec) Windows-Treiberpaket - Terratec (WUDFRd) Ports (02/16/2015 6.1.7600.16385) (HKLM\...\5C5EBF24671D248D909BD1C9278836EF94379B62) (Version: 02/16/2015 6.1.7600.16385 - Terratec) Windows-Treiberpaket - Terratec (WUDFRd) Ports (10/27/2016 10.0.195.447) (HKLM\...\6CED9945C18ECE0D93909DDB5FFC6F05C125EE60) (Version: 10/27/2016 10.0.195.447 - Terratec) XTUPackage (HKLM-x32\...\{84D11A20-6E7F-4FBB-A2FB-117FCF871040}) (Version: 1.0.0 - ASUSTeK COMPUTER INC.) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {188B9885-CAC6-4C29-9051-F3FE2C0F4DF4} - System32\Tasks\SS2Svc32Run => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2Svc32.exe [2016-08-12] () Task: {188EF076-1076-41D7-875F-1DD8F69606C6} - System32\Tasks\SS2UILauncherRun => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe [2016-08-12] () Task: {2F5ACAD3-FDC4-49A4-91BF-D582F5424D5B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-27] (Google Inc.) Task: {43B6F1BF-91BF-4BDD-BD97-EA8C0BE9C13F} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr.exe [2013-07-24] (ASUSTeK Computer Inc.) Task: {5F4CF43C-7BEE-49B2-B0A0-8D7E6AC8A788} - System32\Tasks\ASUS\GpuFanHelper => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe [2016-03-07] (TODO: <Company name>) Task: {81E98030-F60F-430C-AF12-C1A02FE6DF61} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2016-08-11] (ASUSTeK Computer Inc.) Task: {8C538313-6404-41FF-867D-214170AAA8A1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-27] (Google Inc.) Task: {8D28B0BE-DF11-4E05-BD63-4D7B59468AB9} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [2015-11-20] (Intel Corporation) Task: {8DA5F8A2-2102-49F6-B97A-FF4B65DE6B9E} - System32\Tasks\SS2Svc64Run => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2Svc64.exe [2016-08-12] () Task: {91F12F09-9090-49DD-BE18-5DC343B5C829} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2016-12-01] () Task: {9B4D2772-9992-4DE1-B9B9-6B5BCA519D46} - System32\Tasks\ASUS\RC TweakIt Server Execute => C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsBCLK.exe [2015-06-25] () Task: {A7857351-7FC8-4119-8720-ED706A5775D6} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2016-05-13] (Samsung Electronics.) Task: {B230353A-C381-4FA6-9DF9-0B1C5FBB69CD} - System32\Tasks\ASUS\Push Notice Server Execute => C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe [2014-05-28] (ASUSTeK Computer Inc.) Task: {B47F2739-667E-4812-8FF0-9BAC6C0FE401} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [2016-07-28] () Task: {F0820D76-C981-4B46-AD51-BFF9253FB633} - System32\Tasks\ASUS\WonderBox => C:\Program Files (x86)\ASUS\Front Base Driver\WBoxTT.exe [2015-08-05] () (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ShortcutWithArgument: C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\Videostream for Google Chromecast™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=cnciopoikihiagdjbjpnocolokfelagl ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2012-06-21 18:12 - 2012-06-21 18:12 - 01407568 _____ () C:\Program Files (x86)\EgisTec BioExcess\x64\LIBEAY32.dll 2016-11-27 04:15 - 2016-11-27 04:15 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe 2016-10-05 18:17 - 2016-10-05 18:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-10-05 18:17 - 2016-10-05 18:17 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-11-27 04:16 - 2016-11-27 04:15 - 01360016 _____ () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 ____N () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-09 19:34 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-08-12 12:17 - 2016-08-12 12:17 - 00287760 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll 2016-08-12 12:17 - 2016-08-12 12:17 - 00209936 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll 2016-11-28 23:40 - 2015-06-25 10:42 - 01986872 _____ () C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsBCLK.exe 2016-11-27 04:16 - 2016-07-28 23:33 - 01269208 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe 2016-12-09 19:34 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-12-09 19:21 - 2016-12-09 19:21 - 01678560 _____ () C:\Users\totti\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\ClientTelemetry.dll 2016-09-21 22:27 - 2016-09-07 05:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2016-12-09 19:34 - 2016-11-11 10:23 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-12-09 19:34 - 2016-11-11 10:23 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-11-27 14:20 - 2016-11-27 14:20 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-11-27 14:20 - 2016-11-27 14:20 - 00178688 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-11-27 14:20 - 2016-11-27 14:20 - 41609728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2016-11-28 23:39 - 2015-08-05 09:25 - 01384400 _____ () C:\Program Files (x86)\ASUS\Front Base Driver\WBoxTT.exe 2016-11-27 04:16 - 2015-05-14 09:18 - 01075712 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe 2016-11-27 04:16 - 2014-08-28 10:37 - 00033424 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe 2016-11-27 04:16 - 2016-04-21 13:35 - 01529816 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe 2016-11-27 04:50 - 2016-11-27 04:42 - 00105312 _____ () C:\WINDOWS\SYSTEM32\audioLibVc.dll 2016-08-12 12:15 - 2016-08-12 12:15 - 00557072 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe 2016-08-12 12:15 - 2016-08-12 12:15 - 02741760 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2svc32.exe 2016-08-12 12:18 - 2016-08-12 12:18 - 00486400 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2svc64.exe 2016-11-10 00:01 - 2016-11-02 11:21 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-10 00:01 - 2016-11-02 11:15 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-10 00:01 - 2016-11-02 11:14 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2016-11-10 00:01 - 2016-11-02 11:15 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-10 00:01 - 2016-11-02 11:17 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-11-27 01:08 - 2016-11-08 22:03 - 02367080 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libglesv2.dll 2016-11-27 01:08 - 2016-11-08 22:03 - 00107112 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libegl.dll 2016-11-27 04:15 - 2016-12-11 07:29 - 00040232 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll 2016-11-27 04:15 - 2016-11-27 04:15 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll 2016-11-27 04:16 - 2015-09-17 10:58 - 00091648 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Log4cxxWrapper.dll 2016-11-27 04:16 - 2015-09-17 10:58 - 00147456 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AssistFunc.dll 2016-11-27 04:16 - 2015-02-09 17:53 - 00872960 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AI Charger+\AIChargerPlus.dll 2016-11-27 04:16 - 2016-08-15 10:36 - 04712752 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\dip4.dll 2016-11-27 04:16 - 2016-03-07 21:42 - 00091648 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\Log4cxxWrapper.dll 2016-11-27 04:16 - 2015-11-05 11:13 - 01464320 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Mobo Connect\MoboConnect.dll 2016-11-27 04:16 - 2015-09-17 10:58 - 00838456 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Version\Version.dll 2016-11-28 23:49 - 2016-08-02 15:05 - 00061440 _____ () C:\Program Files (x86)\ASUS\VGA COM\1.00.26\Exeio.dll 2016-11-28 23:49 - 2016-08-02 14:51 - 01752576 _____ () C:\Program Files (x86)\ASUS\VGA COM\1.00.26\Vender.dll 2016-11-28 23:48 - 2016-08-05 15:25 - 00669656 _____ () C:\Program Files (x86)\ASUS\AAHM\1.00.25\aaHMLib.dll 2016-11-27 04:17 - 2012-01-19 09:39 - 00028672 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\PEInfo.dll 2016-08-12 12:14 - 2016-08-12 12:14 - 00256016 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2OSD.dll 2016-08-12 12:14 - 2016-08-12 12:14 - 00178704 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2DevProps.dll 2016-11-27 04:16 - 2015-09-17 10:58 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite III\ImageHelper.dll 2016-11-27 04:16 - 2015-09-17 10:58 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite III\pngio.dll 2016-11-27 04:17 - 2010-02-25 14:01 - 00139264 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\Aszip.dll 2016-11-27 04:17 - 2015-10-14 14:47 - 02613248 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\EzULIB_UFB.dll 2016-11-28 23:40 - 2015-06-05 09:37 - 00179712 _____ () C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsusService.dll 2016-11-27 04:16 - 2016-04-20 23:52 - 00260056 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4cTDPAction.dll 2016-11-27 04:16 - 2016-05-04 21:46 - 00786416 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll 2016-11-27 04:16 - 2016-04-20 23:52 - 00878040 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll 2016-11-27 04:16 - 2016-04-20 23:52 - 00828376 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4FanAction.dll 2016-11-27 04:16 - 2016-04-20 23:52 - 00838616 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll 2016-11-27 04:16 - 2013-11-20 10:10 - 00662016 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\aaHMLib.dll 2016-11-27 04:16 - 2013-07-02 10:40 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\pngio.dll 2016-08-12 12:15 - 2016-08-12 12:15 - 00098816 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\sradarlauncher.dll 2016-12-09 19:21 - 2016-12-09 19:21 - 01244376 _____ () C:\Users\totti\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\ClientTelemetry.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2016-11-26 23:45 - 2016-11-26 23:44 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-2586767532-3616519997-416612805-1006\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [{54E4918F-A16A-4FA9-9F2F-160EDBB8443A}] => C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE FirewallRules: [{19192873-968D-4E2F-98DB-E134957E191E}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{9C5C5112-6DE2-41AD-A69F-BA05190A96A5}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{8483DF55-D597-4E26-BD9B-C06CCC10B227}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{AD27A2B5-5842-4E00-8C06-FF9F7053163E}C:\users\thorsten\desktop\jperf-2.0.2\jperf-2.0.2\bin\iperf.exe] => C:\users\thorsten\desktop\jperf-2.0.2\jperf-2.0.2\bin\iperf.exe FirewallRules: [UDP Query User{DFB24A96-1288-41E3-B341-14F1E1C3CBE9}C:\users\thorsten\desktop\jperf-2.0.2\jperf-2.0.2\bin\iperf.exe] => C:\users\thorsten\desktop\jperf-2.0.2\jperf-2.0.2\bin\iperf.exe FirewallRules: [SNMP-In-UDP] => %SystemRoot%\system32\snmp.exe FirewallRules: [SNMP-Out-UDP] => %SystemRoot%\system32\snmp.exe FirewallRules: [SNMP-In-UDP-NoScope] => %SystemRoot%\system32\snmp.exe FirewallRules: [SNMP-Out-UDP-NoScope] => %SystemRoot%\system32\snmp.exe FirewallRules: [TCP Query User{7B5C2E71-F3E4-4159-8248-FCB8735D3F12}C:\program files (x86)\western digital\wd app manager\wdappmanager.exe] => C:\program files (x86)\western digital\wd app manager\wdappmanager.exe FirewallRules: [UDP Query User{5930F899-70D2-401D-8760-CDFD22F72C6B}C:\program files (x86)\western digital\wd app manager\wdappmanager.exe] => C:\program files (x86)\western digital\wd app manager\wdappmanager.exe FirewallRules: [{B5AF83E3-86A9-4279-9DAB-34A9F65B5BFB}] => C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{6FE7BDB7-317E-40D9-BA68-E88F174AC1AB}] => C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{20B49414-1915-4941-A2B1-C73B8E532466}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{7EA22D8B-07BB-4F54-8384-E1DC8DCB9A35}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E490789F-B35E-48B2-A406-23F972D5C058}] => C:\Program Files\iTunes\iTunes.exe FirewallRules: [{6D2571BC-0D6E-45F5-992C-9499BD739CC0}] => C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{1E65D46E-9309-4FBF-8FC6-6C6C26FBEDE7}] => C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{27370EAC-C5BD-4802-9745-008EDAADBC30}] => C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{E159694B-A5B6-4723-997D-8131C58D391D}] => C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [TCP Query User{92164D59-5689-4281-BB74-7EAA0DE82283}C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe] => C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe FirewallRules: [UDP Query User{5DBC668B-0188-40A0-9693-12926839932A}C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe] => C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe FirewallRules: [{42C30DF6-3DFE-41D1-BA6C-C58524743106}] => C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe FirewallRules: [{A116FCB6-EB63-4F45-857A-1094133606DC}] => C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe ==================== Wiederherstellungspunkte ========================= 11-12-2016 05:08:27 Revo Uninstaller Pro's restore point - WiFi Station N ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Unbekanntes USB-Gerät (Fehler beim Anfordern einer Gerätebeschreibung.) Description: Unbekanntes USB-Gerät (Fehler beim Anfordern einer Gerätebeschreibung.) Class Guid: {36fc9e60-c465-11cf-8056-444553540000} Manufacturer: (Standard-USB-Hostcontroller) Service: Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. Name: Unbekanntes USB-Gerät (Fehler beim Anfordern einer Gerätebeschreibung.) Description: Unbekanntes USB-Gerät (Fehler beim Anfordern einer Gerätebeschreibung.) Class Guid: {36fc9e60-c465-11cf-8056-444553540000} Manufacturer: (Standard-USB-Hostcontroller) Service: Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (12/11/2016 01:11:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 62437 Error: (12/11/2016 01:11:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 62437 Error: (12/11/2016 01:11:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/11/2016 01:11:22 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 46797 Error: (12/11/2016 01:11:22 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 46797 Error: (12/11/2016 01:11:22 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/11/2016 01:11:07 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 31172 Error: (12/11/2016 01:11:07 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 31172 Error: (12/11/2016 01:11:07 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/11/2016 01:10:51 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15578 Systemfehler: ============= Error: (12/11/2016 04:24:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Logitech Solar Keyboard Service" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/11/2016 04:24:21 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Logitech Solar Keyboard Service" wurde mit dem folgenden dienstspezifischen Fehler beendet: Der Vorgang wurde erfolgreich beendet. Error: (12/11/2016 03:38:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Logitech Solar Keyboard Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Error: (12/11/2016 03:38:36 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Logitech Solar Keyboard Service" wurde mit dem folgenden dienstspezifischen Fehler beendet: Der Vorgang wurde erfolgreich beendet. Error: (12/11/2016 03:38:19 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} und der APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/11/2016 03:38:19 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} und der APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/11/2016 03:38:19 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} und der APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (12/11/2016 01:09:46 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht. Error: (12/11/2016 01:09:16 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht. Error: (12/11/2016 01:08:46 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht. CodeIntegrity: =================================== Date: 2016-12-11 15:42:07.555 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements. Date: 2016-12-11 15:42:07.550 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll that did not meet the Store signing level requirements. Date: 2016-12-11 15:41:30.185 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements. Date: 2016-12-11 15:41:30.181 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll that did not meet the Store signing level requirements. Date: 2016-12-11 15:41:06.690 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements. Date: 2016-12-11 15:41:06.683 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll that did not meet the Store signing level requirements. Date: 2016-12-11 15:41:06.571 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements. Date: 2016-12-11 15:41:06.563 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll that did not meet the Store signing level requirements. Date: 2016-12-11 07:29:52.923 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-12-11 00:25:36.272 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz Prozentuale Nutzung des RAM: 13% Installierter physikalischer RAM: 32690.58 MB Verfügbarer physikalischer RAM: 28140.23 MB Summe virtueller Speicher: 37554.58 MB Verfügbarer virtueller Speicher: 32568.91 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:464.67 GB) (Free:311.41 GB) NTFS Drive d: (Samsung850) (Fixed) (Total:232.35 GB) (Free:64.13 GB) NTFS Drive e: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive f: (WD Black ) (Fixed) (Total:931.41 GB) (Free:652.7 GB) NTFS Drive g: () (Fixed) (Total:465.66 GB) (Free:294.32 GB) NTFS Drive h: (WD Elements black) (Fixed) (Total:1862.98 GB) (Free:1318.57 GB) NTFS Drive i: () (CDROM) (Total:0.06 GB) (Free:0 GB) CDFS Drive j: () (Fixed) (Total:55.8 GB) (Free:7.84 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 5DAD4F98) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: FD91664C) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=232.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 55.9 GB) (Disk ID: E1CFC143) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=55.8 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (Size: 931.5 GB) (Disk ID: C032F668) Partition 1: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ======================================================== Disk: 4 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: 044B42CF) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ======================================================== Disk: 5 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: FB639362) Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
11.12.2016, 18:07 | #19 |
| Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016 durchgeführt von totti (Administrator) auf HOME-PC (11-12-2016 17:53:45) Gestartet von C:\Users\totti\Downloads Geladene Profile: totti (Verfügbare Profile: Thorsten & ttjh1 & totti) Platform: Windows 10 Pro Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Edge) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Egis Technology Inc. ) C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.25\aaHMSvc.exe () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Microsoft Corporation) C:\Windows\System32\snmp.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe () C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsBclk.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe () C:\Program Files (x86)\ASUS\Front Base Driver\WBoxTT.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr64.exe () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe () C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe (Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe (Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (SAVITECH) C:\Program Files (x86)\SAVITECH\SVLoadSense\SVLoadSense.exe () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2Svc32.exe () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2Svc64.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe (Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisTSR.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Sync\App\WDSyncService.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\syswow64\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7705.42037.0_x64__8wekyb3d8bbwe\HxMail.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7705.42037.0_x64__8wekyb3d8bbwe\HxTsr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [1735288 2016-09-30] (Logitech, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843784 2016-11-27] (Realtek Semiconductor) HKLM\...\Run: [SVLoadSense] => c:\Program Files (x86)\SAVITECH\SVLoadSense\SVLoadSense.exe [1762000 2015-09-21] (SAVITECH) HKLM\...\Run: [SS2UILauncher] => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe [557072 2016-08-12] () HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.) HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-02-12] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] => C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2013-01-28] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [AO Link Server] => C:\Program Files (x86)\ASUS\AI Suite III\Mobo Connect\ALRun.exe -start HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21384 2016-04-15] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [424528 2012-08-16] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [198736 2012-08-16] (Egis Technology Inc.) HKLM-x32\...\Run: [VitaKeyTSR] => C:\Program Files (x86)\EgisTec BioExcess\EgisTSR.exe [384080 2012-12-07] (Egis Technology Inc. ) HKU\S-1-5-21-2586767532-3616519997-416612805-1006\...\Run: [GoogleChromeAutoLaunch_53F0CD5A7C131BABB0ECFA6A491868AF] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1082472 2016-11-08] (Google Inc.) Lsa: [Notification Packages] scecli C:\Program Files (x86)\EgisTec BioExcess\x64\EgisPwdFilter.dll C:\Program Files (x86)\EgisTec BioExcess\x64\EgisDSPwdFilter.dll ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{278623a9-5409-4fd0-84f9-306d087989c8}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{33feedbb-de7b-4bc4-8b69-96b9e6bac0b6}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{6abf8ccf-8799-4d9f-85cf-650277434338}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== BHO: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files (x86)\EgisTec BioExcess\x64\EgisPBIE.dll [2012-12-07] (Egis Technology Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-27] (Oracle Corporation) BHO-x32: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dll [2012-12-07] (Egis Technology Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-27] (Oracle Corporation) FireFox: ======== FF DefaultProfile: t1674hax.default FF ProfilePath: C:\Users\totti\AppData\Roaming\Mozilla\Firefox\Profiles\t1674hax.default [2016-12-10] FF HKLM-x32\...\Firefox\Extensions: [{41ecbc0b-34d5-4cd4-935f-253a30e2cb7e}] - C:\Program Files (x86)\EgisTec BioExcess\FFExt FF Extension: ( Online Accounts Extension ) - C:\Program Files (x86)\EgisTec BioExcess\FFExt [2016-12-06] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files (x86)\EgisTec BioExcess\FFExt20 FF Extension: ( Online Accounts Extension ) - C:\Program Files (x86)\EgisTec BioExcess\FFExt20 [2016-12-06] [ist nicht signiert] FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-27] (Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-27] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-27] (Google Inc.) Chrome: ======= CHR HomePage: Default -> hxxps://www.google.de/ CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxps://www.google.de/" CHR Profile: C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default [2016-12-11] CHR Extension: (Google Präsentationen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-04] CHR Extension: (Karte des Himmels) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\acnecepeneiomaebkkagcfbbakcfljdc [2016-12-11] CHR Extension: (HD for YouTube™) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\akjbfncbadcmnkopckegnmjgihagponf [2016-12-11] CHR Extension: (Google Docs) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-04] CHR Extension: (Google Drive) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-04] CHR Extension: (YouTube) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-04] CHR Extension: () - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-12-11] CHR Extension: (Videostream for Google Chromecast™) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2016-12-11] CHR Extension: (Webcam) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfpjcegkjhdnnempidlgmeoaiilpidep [2016-12-11] CHR Extension: () - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dliochdbjfkdbacpmhlcpmleaejidimm [2016-12-11] CHR Extension: (My JDownloader) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbcohnmimjicjdomonkcbcpbpnhggkip [2016-12-11] CHR Extension: (Google Tabellen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-04] CHR Extension: (DealExtreme Official) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gadgkbofaenpeeeffgokgjpnbjbflopl [2016-12-11] CHR Extension: (Google Docs Offline) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-04] CHR Extension: (Cr!Box) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjodchcocbnbhfkjeapbdoflbiibnapp [2016-12-11] CHR Extension: (Core) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkhcgfdghbiidgeccbldhfceleibkkpe [2016-12-11] CHR Extension: (Google) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihglnnefiimonkjgebeipifpkmblecpd [2016-12-11] CHR Extension: (Custom Google™ Background) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\jepibmfmhopgkplegmkjgifmhabbjadg [2016-12-11] CHR Extension: (PlayTo für Chromecast™) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\jngkenaoceimiimeokpdbmejeonaaami [2016-12-11] CHR Extension: (Online Accounts Extension ) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ladimmjldcgbeamniagencjbodhnmgen [2016-12-07] CHR Extension: (EXIF Viewer) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2016-12-11] CHR Extension: (Downloads) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngbcgifdaopbfflfhbcfeomijfbbcadi [2016-12-11] CHR Extension: (LocalChromecast Player) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmladpigjlinmngadjgfogblnmddndcp [2016-12-11] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-04] CHR Extension: (MonsterBall) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\oampnkjpomgmmphfoedhihefpbjhjamo [2016-12-11] CHR Extension: (Mein Chrome-Design) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2016-12-11] CHR Extension: (Earth map) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\opmibphegngmljhikklndacjdpkmhocp [2016-12-11] CHR Extension: (Amazon Assistant for Chrome) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2016-12-11] CHR Extension: (Google Mail) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-04] CHR Extension: (Chrome Media Router) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-04] CHR HKLM-x32\...\Chrome\Extension: [ladimmjldcgbeamniagencjbodhnmgen] - C:\Program Files (x86)\EgisTec BioExcess\ChromeEx\EgisPBChromeExt.crx [2012-12-07] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.) R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2016-11-27] () R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.25\aaHMSvc.exe [963544 2016-08-05] (ASUSTeK Computer Inc.) R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2016-11-27] () [Datei ist nicht signiert] R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe [419288 2016-05-27] (ASUSTeK Computer Inc.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation) R2 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation) R2 SNMP; C:\WINDOWS\System32\snmp.exe [53248 2016-11-28] (Microsoft Corporation) R2 SNMP; C:\WINDOWS\SysWOW64\snmp.exe [47104 2016-11-28] (Microsoft Corporation) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10216688 2016-11-28] (TeamViewer GmbH) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [302968 2015-02-12] (Western Digital Technologies, Inc.) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [18232 2016-08-02] (Intel(R) Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.) R3 AndroidAFD; C:\Windows\SysWow64\drivers\AndroidAFDx64.sys [22192 2015-10-19] (ASUSTek Computer Inc.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2016-11-27] () S0 asstahci64; C:\WINDOWS\System32\drivers\asstahci64.sys [88936 2015-06-17] (Asmedia Technology) R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2016-11-27] () R3 ASUSfilter; C:\WINDOWS\System32\drivers\ASUSfilter.sys [48384 2013-03-28] (MCCI Corporation) R3 ASUSfilter; C:\Windows\SysWOW64\drivers\ASUSfilter.sys [46152 2016-11-27] (MCCI Corporation) S3 ASUSstpt; C:\WINDOWS\System32\drivers\ASUSstpt.sys [27392 2013-03-28] (MCCI Corporation) S3 ASUSumsc; C:\WINDOWS\System32\drivers\ASUSumsc.sys [151808 2013-03-28] (MCCI Corporation) S3 ASUSxpsp; C:\WINDOWS\System32\drivers\ASUSxpsp.sys [28416 2013-03-28] (MCCI Corporation) S3 DSI_SiUSBXp_3_1; C:\WINDOWS\system32\drivers\DSI_SiUSBXp_3_1.sys [16384 2007-09-06] (Silicon Laboratories) S3 dtultrascsibus; C:\WINDOWS\System32\drivers\dtultrascsibus.sys [30264 2016-04-17] (Disc Soft Ltd) S3 dtultrausbbus; C:\WINDOWS\System32\drivers\dtultrausbbus.sys [47672 2016-04-17] (Disc Soft Ltd) R3 e1dexpress; C:\WINDOWS\system32\DRIVERS\e1d65x64.sys [530416 2015-06-18] (Intel Corporation) R0 FPWinIo; C:\WINDOWS\System32\drivers\FPWinIo.sys [23536 2014-10-07] (Egis Technology Inc.) S2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [29264 2016-06-09] (Intel Corporation) R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [24824 2016-07-12] (ASUSTeK Computer Inc.) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-12-11] (Malwarebytes) R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R1 SvThLSNS; c:\Program Files (x86)\SAVITECH\SVLoadSense\x64\SvThLSNS.sys [15184 2015-09-21] (Windows (R) Win 7 DDK provider) S3 TTHID; C:\WINDOWS\System32\drivers\Cinergy_Hybrid-Stick_HID.sys [27944 2012-09-27] (DTV-DVB) S3 UDXTTM6010; C:\WINDOWS\system32\DRIVERS\UDXTTM6010.sys [841384 2012-09-27] () S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) S3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation) S3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-09-21] (Intel Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-11 15:57 - 2016-12-11 15:57 - 00000000 ____D C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps 2016-12-11 15:42 - 2016-12-11 15:42 - 00000000 ___HD C:\OneDriveTemp 2016-12-11 07:34 - 2016-12-11 07:34 - 00000000 ____D C:\Users\ttjh1\AppData\Local\EgisTec IPS 2016-12-10 21:50 - 2016-12-10 21:52 - 00000000 ____D C:\Users\totti\AppData\Local\ElevatedDiagnostics 2016-12-10 21:41 - 2016-12-10 21:41 - 00001122 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2016-12-10 21:41 - 2016-12-10 21:41 - 00000000 ____D C:\Users\totti\AppData\Local\VS Revo Group 2016-12-10 21:41 - 2016-12-10 21:41 - 00000000 ____D C:\ProgramData\VS Revo Group 2016-12-10 21:41 - 2016-12-10 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro 2016-12-10 21:41 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\WINDOWS\system32\Drivers\revoflt.sys 2016-12-10 21:40 - 2016-12-10 21:42 - 00000000 ____D C:\Users\totti\Downloads\Revo Uninstaller Pro 3.1.7 2016-12-10 21:37 - 2016-12-10 21:37 - 11481182 _____ C:\Users\totti\Downloads\Revo Uninstaller Pro 3.1.7.rar 2016-12-10 21:24 - 2016-12-10 21:41 - 00000000 ____D C:\Program Files\VS Revo Group 2016-12-10 21:24 - 2016-12-10 21:24 - 07100088 _____ (VS Revo Group ) C:\Users\totti\Downloads\revosetup201.exe 2016-12-10 20:40 - 2016-12-10 20:41 - 00067674 _____ C:\Users\totti\Downloads\Fixlog.txt 2016-12-10 20:40 - 2016-12-10 20:40 - 00000000 ____D C:\Users\totti\Downloads\FRST-OlderVersion 2016-12-10 04:32 - 2016-12-10 04:32 - 00000000 ____D C:\Users\totti\AppData\Roaming\MPC-HC 2016-12-10 04:25 - 2016-12-10 04:25 - 16885631 _____ ( ) C:\Users\totti\Downloads\klcp_update_1270_20161209.exe 2016-12-10 04:25 - 2016-12-10 04:25 - 00001747 _____ C:\Users\totti\Desktop\klcp_codec_log.txt 2016-12-10 04:24 - 2016-12-10 04:24 - 00001544 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-12-10 04:22 - 2016-12-10 04:22 - 00002776 _____ C:\WINDOWS\System32\Tasks\klcp_update 2016-12-10 04:22 - 2016-12-10 04:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack 2016-12-10 04:22 - 2016-05-08 11:27 - 03613696 _____ (x264vfw project) C:\WINDOWS\SysWOW64\x264vfw.dll 2016-12-10 04:22 - 2016-05-08 11:19 - 03642880 _____ (x264vfw project) C:\WINDOWS\system32\x264vfw64.dll 2016-12-10 04:22 - 2015-12-18 11:00 - 00755200 _____ C:\WINDOWS\system32\xvidcore.dll 2016-12-10 04:22 - 2015-12-18 11:00 - 00674816 _____ C:\WINDOWS\SysWOW64\xvidcore.dll 2016-12-10 04:22 - 2015-12-18 11:00 - 00309248 _____ C:\WINDOWS\system32\xvidvfw.dll 2016-12-10 04:22 - 2015-12-18 11:00 - 00282112 _____ C:\WINDOWS\SysWOW64\xvidvfw.dll 2016-12-10 04:22 - 2015-10-24 18:00 - 00112128 _____ C:\WINDOWS\SysWOW64\ff_vfw.dll 2016-12-10 04:22 - 2012-07-21 12:55 - 00180736 _____ (fccHandler) C:\WINDOWS\system32\ac3acm.acm 2016-12-10 04:22 - 2012-07-21 12:54 - 00122880 _____ (fccHandler) C:\WINDOWS\SysWOW64\ac3acm.acm 2016-12-10 04:22 - 2011-12-07 19:37 - 00148992 _____ ( ) C:\WINDOWS\system32\lagarith.dll 2016-12-10 04:22 - 2011-12-07 19:32 - 00216064 _____ ( ) C:\WINDOWS\SysWOW64\lagarith.dll 2016-12-10 04:21 - 2016-12-10 04:22 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack 2016-12-10 04:20 - 2016-12-10 04:21 - 43733412 _____ (KLCP ) C:\Users\totti\Downloads\K-Lite_Codec_Pack_1265_Mega.exe 2016-12-10 03:34 - 2016-12-10 03:34 - 02870984 _____ (ESET) C:\Users\totti\Downloads\esetsmartinstaller_deu (1).exe 2016-12-10 03:19 - 2016-12-10 03:25 - 00000000 ____D C:\ProgramData\HitmanPro 2016-12-10 03:19 - 2016-12-10 03:19 - 11581544 _____ (SurfRight B.V.) C:\Users\totti\Downloads\HitmanPro_x64.exe 2016-12-09 19:34 - 2016-11-11 11:22 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-12-09 19:34 - 2016-11-11 11:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2016-12-09 19:34 - 2016-11-11 11:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll 2016-12-09 19:34 - 2016-11-11 11:14 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2016-12-09 19:34 - 2016-11-11 11:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2016-12-09 19:34 - 2016-11-11 11:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2016-12-09 19:34 - 2016-11-11 11:13 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-12-09 19:34 - 2016-11-11 11:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-12-09 19:34 - 2016-11-11 11:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-12-09 19:34 - 2016-11-11 11:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2016-12-09 19:34 - 2016-11-11 11:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-12-09 19:34 - 2016-11-11 11:10 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-12-09 19:34 - 2016-11-11 11:09 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-12-09 19:34 - 2016-11-11 11:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll 2016-12-09 19:34 - 2016-11-11 11:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2016-12-09 19:34 - 2016-11-11 11:03 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2016-12-09 19:34 - 2016-11-11 11:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-12-09 19:34 - 2016-11-11 11:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2016-12-09 19:34 - 2016-11-11 11:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-12-09 19:34 - 2016-11-11 11:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-12-09 19:34 - 2016-11-11 11:01 - 02189152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-12-09 19:34 - 2016-11-11 11:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-12-09 19:34 - 2016-11-11 11:01 - 01738048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-12-09 19:34 - 2016-11-11 11:01 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-12-09 19:34 - 2016-11-11 11:01 - 00658264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-12-09 19:34 - 2016-11-11 11:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2016-12-09 19:34 - 2016-11-11 11:01 - 00401760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-12-09 19:34 - 2016-11-11 11:00 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2016-12-09 19:34 - 2016-11-11 11:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-12-09 19:34 - 2016-11-11 11:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys 2016-12-09 19:34 - 2016-11-11 10:59 - 02913136 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-12-09 19:34 - 2016-11-11 10:59 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2016-12-09 19:34 - 2016-11-11 10:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-12-09 19:34 - 2016-11-11 10:57 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-12-09 19:34 - 2016-11-11 10:57 - 08170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-12-09 19:34 - 2016-11-11 10:57 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-12-09 19:34 - 2016-11-11 10:57 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-12-09 19:34 - 2016-11-11 10:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2016-12-09 19:34 - 2016-11-11 10:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-12-09 19:34 - 2016-11-11 10:56 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-12-09 19:34 - 2016-11-11 10:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-12-09 19:34 - 2016-11-11 10:56 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2016-12-09 19:34 - 2016-11-11 10:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll 2016-12-09 19:34 - 2016-11-11 10:56 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2016-12-09 19:34 - 2016-11-11 10:56 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2016-12-09 19:34 - 2016-11-11 10:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe 2016-12-09 19:34 - 2016-11-11 10:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll 2016-12-09 19:34 - 2016-11-11 10:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll 2016-12-09 19:34 - 2016-11-11 10:55 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2016-12-09 19:34 - 2016-11-11 10:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2016-12-09 19:34 - 2016-11-11 10:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2016-12-09 19:34 - 2016-11-11 10:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-12-09 19:34 - 2016-11-11 10:51 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2016-12-09 19:34 - 2016-11-11 10:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2016-12-09 19:34 - 2016-11-11 10:31 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-12-09 19:34 - 2016-11-11 10:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-12-09 19:34 - 2016-11-11 10:29 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2016-12-09 19:34 - 2016-11-11 10:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-12-09 19:34 - 2016-11-11 10:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll 2016-12-09 19:34 - 2016-11-11 10:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-12-09 19:34 - 2016-11-11 10:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-12-09 19:34 - 2016-11-11 10:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe 2016-12-09 19:34 - 2016-11-11 10:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys 2016-12-09 19:34 - 2016-11-11 10:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2016-12-09 19:34 - 2016-11-11 10:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll 2016-12-09 19:34 - 2016-11-11 10:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys 2016-12-09 19:34 - 2016-11-11 10:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe 2016-12-09 19:34 - 2016-11-11 10:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll 2016-12-09 19:34 - 2016-11-11 10:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2016-12-09 19:34 - 2016-11-11 10:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-12-09 19:34 - 2016-11-11 10:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe 2016-12-09 19:34 - 2016-11-11 10:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-12-09 19:34 - 2016-11-11 10:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2016-12-09 19:34 - 2016-11-11 10:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2016-12-09 19:34 - 2016-11-11 10:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-12-09 19:34 - 2016-11-11 10:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-12-09 19:34 - 2016-11-11 10:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2016-12-09 19:34 - 2016-11-11 10:23 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2016-12-09 19:34 - 2016-11-11 10:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-12-09 19:34 - 2016-11-11 10:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll 2016-12-09 19:34 - 2016-11-11 10:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-12-09 19:34 - 2016-11-11 10:22 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-12-09 19:34 - 2016-11-11 10:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe 2016-12-09 19:34 - 2016-11-11 10:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-12-09 19:34 - 2016-11-11 10:21 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-12-09 19:34 - 2016-11-11 10:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-12-09 19:34 - 2016-11-11 10:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2016-12-09 19:34 - 2016-11-11 10:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll 2016-12-09 19:34 - 2016-11-11 10:21 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-12-09 19:34 - 2016-11-11 10:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-12-09 19:34 - 2016-11-11 10:20 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll 2016-12-09 19:34 - 2016-11-11 10:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe 2016-12-09 19:34 - 2016-11-11 10:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-12-09 19:34 - 2016-11-11 10:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2016-12-09 19:34 - 2016-11-11 10:19 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-12-09 19:34 - 2016-11-11 10:18 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-12-09 19:34 - 2016-11-11 10:18 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-12-09 19:34 - 2016-11-11 10:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2016-12-09 19:34 - 2016-11-11 10:18 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2016-12-09 19:34 - 2016-11-11 10:18 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2016-12-09 19:34 - 2016-11-11 10:18 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-12-09 19:34 - 2016-11-11 10:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2016-12-09 19:34 - 2016-11-11 10:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2016-12-09 19:34 - 2016-11-11 10:17 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-12-09 19:34 - 2016-11-11 10:17 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-12-09 19:34 - 2016-11-11 10:17 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2016-12-09 19:34 - 2016-11-11 10:17 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2016-12-09 19:34 - 2016-11-11 10:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2016-12-09 19:34 - 2016-11-11 10:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2016-12-09 19:34 - 2016-11-11 10:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2016-12-09 19:34 - 2016-11-11 10:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2016-12-09 19:34 - 2016-11-11 10:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2016-12-09 19:34 - 2016-11-11 10:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll 2016-12-09 19:34 - 2016-11-11 10:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll 2016-12-09 19:34 - 2016-11-11 10:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-12-09 19:34 - 2016-11-11 10:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll 2016-12-09 19:34 - 2016-11-11 10:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe 2016-12-09 19:34 - 2016-11-11 10:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-12-09 19:34 - 2016-11-11 10:14 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-12-09 19:34 - 2016-11-11 10:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-12-09 19:34 - 2016-11-11 10:14 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2016-12-09 19:34 - 2016-11-11 10:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2016-12-09 19:34 - 2016-11-11 10:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2016-12-09 19:34 - 2016-11-11 10:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll 2016-12-09 19:34 - 2016-11-11 10:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-12-09 19:34 - 2016-11-11 10:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-12-09 19:34 - 2016-11-11 10:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll 2016-12-09 19:34 - 2016-11-11 10:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll 2016-12-09 19:34 - 2016-11-11 10:11 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-12-09 19:34 - 2016-11-11 10:11 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-12-09 19:34 - 2016-11-11 10:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2016-12-09 19:34 - 2016-11-11 10:11 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-12-09 19:34 - 2016-11-11 10:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll 2016-12-09 19:34 - 2016-11-11 10:10 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-12-09 19:34 - 2016-11-11 10:10 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-12-09 19:34 - 2016-11-11 10:09 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2016-12-09 19:34 - 2016-11-11 10:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2016-12-09 19:34 - 2016-11-11 10:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll 2016-12-09 19:34 - 2016-11-11 10:08 - 08127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-12-09 19:34 - 2016-11-11 10:08 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2016-12-09 19:34 - 2016-11-11 10:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2016-12-09 19:34 - 2016-11-11 10:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll 2016-12-09 19:34 - 2016-11-11 10:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2016-12-09 19:34 - 2016-11-11 10:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-12-09 19:34 - 2016-11-11 10:06 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-12-09 19:34 - 2016-11-11 10:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-12-09 19:34 - 2016-11-11 10:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-12-09 19:34 - 2016-11-11 10:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2016-12-09 19:34 - 2016-11-11 10:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-12-09 19:34 - 2016-11-11 10:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-12-09 19:34 - 2016-11-11 10:05 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-12-09 19:34 - 2016-11-11 10:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-12-09 19:34 - 2016-11-11 10:05 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2016-12-09 19:34 - 2016-11-11 10:04 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2016-12-09 19:34 - 2016-11-11 10:04 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 02317312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2016-12-09 19:34 - 2016-11-11 10:04 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2016-12-09 19:34 - 2016-11-11 10:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-12-09 19:34 - 2016-11-11 10:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-12-09 19:34 - 2016-11-11 10:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll 2016-12-09 19:34 - 2016-11-11 10:03 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-12-09 19:34 - 2016-11-11 10:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-12-09 19:34 - 2016-11-11 10:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-12-09 19:34 - 2016-11-11 10:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-12-09 19:34 - 2016-11-11 10:02 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-12-09 19:34 - 2016-11-11 10:01 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-12-09 19:34 - 2016-11-11 09:39 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-12-09 19:34 - 2016-11-11 09:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2016-12-09 19:34 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2016-12-09 19:34 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2016-12-09 19:34 - 2016-11-11 09:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-12-09 19:34 - 2016-11-11 08:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-12-09 19:34 - 2016-11-11 08:56 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-12-09 19:34 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll 2016-12-09 19:34 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2016-12-09 19:34 - 2016-11-11 08:49 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2016-12-09 19:34 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-12-09 19:34 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2016-12-09 19:34 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-12-09 19:34 - 2016-11-11 08:47 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-12-09 19:34 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-12-09 19:34 - 2016-11-11 08:47 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-12-09 19:34 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2016-12-09 19:34 - 2016-11-11 08:45 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-12-09 19:34 - 2016-11-11 08:45 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 06668032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll 2016-12-09 19:34 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll 2016-12-09 19:34 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-12-09 19:34 - 2016-11-11 08:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe 2016-12-09 19:34 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-12-09 19:34 - 2016-11-11 08:28 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2016-12-09 19:34 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe 2016-12-09 19:34 - 2016-11-11 08:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-12-09 19:34 - 2016-11-11 08:26 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2016-12-09 19:34 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe 2016-12-09 19:34 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-12-09 19:34 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-12-09 19:34 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2016-12-09 19:34 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-12-09 19:34 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-12-09 19:34 - 2016-11-11 08:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2016-12-09 19:34 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2016-12-09 19:34 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2016-12-09 19:34 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-12-09 19:34 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2016-12-09 19:34 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-12-09 19:34 - 2016-11-11 08:21 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-12-09 19:34 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2016-12-09 19:34 - 2016-11-11 08:20 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-12-09 19:34 - 2016-11-11 08:20 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-12-09 19:34 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-12-09 19:34 - 2016-11-11 08:20 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2016-12-09 19:34 - 2016-11-11 08:20 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-12-09 19:34 - 2016-11-11 08:19 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-12-09 19:34 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2016-12-09 19:34 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-12-09 19:34 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-12-09 19:34 - 2016-11-11 08:19 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2016-12-09 19:34 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2016-12-09 19:34 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll 2016-12-09 19:34 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll 2016-12-09 19:34 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe 2016-12-09 19:34 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2016-12-09 19:34 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2016-12-09 19:34 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2016-12-09 19:34 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2016-12-09 19:34 - 2016-11-11 08:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2016-12-09 19:34 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll 2016-12-09 19:34 - 2016-11-11 08:17 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2016-12-09 19:34 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2016-12-09 19:34 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe 2016-12-09 19:34 - 2016-11-11 08:16 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-12-09 19:34 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-12-09 19:34 - 2016-11-11 08:16 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-12-09 19:34 - 2016-11-11 08:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-12-09 19:34 - 2016-11-11 08:15 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-12-09 19:34 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-12-09 19:34 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-12-09 19:34 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2016-12-09 19:34 - 2016-11-11 08:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2016-12-09 19:34 - 2016-11-11 08:14 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-12-09 19:34 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2016-12-09 19:34 - 2016-11-11 08:13 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-12-09 19:34 - 2016-11-11 08:13 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-12-09 19:34 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll 2016-12-09 19:34 - 2016-11-11 08:11 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-12-09 19:34 - 2016-11-11 08:10 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-12-09 19:34 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-12-09 19:34 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll 2016-12-09 19:34 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-12-09 19:34 - 2016-11-11 08:09 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2016-12-09 19:34 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2016-12-09 19:34 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll 2016-12-09 19:34 - 2016-11-11 08:06 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2016-12-09 19:34 - 2016-11-11 08:06 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-12-09 19:34 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2016-12-09 19:34 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2016-12-09 19:34 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-12-09 19:34 - 2016-11-11 08:06 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2016-12-09 19:34 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2016-12-09 19:34 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll 2016-12-09 19:34 - 2016-11-11 08:05 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-12-09 19:34 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-12-09 19:34 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2016-12-09 19:34 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2016-12-09 19:34 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-12-09 19:34 - 2016-11-11 08:04 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-12-09 19:34 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-12-09 19:34 - 2016-11-11 08:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-12-09 19:34 - 2016-11-11 08:04 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2016-12-09 19:34 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-12-09 19:34 - 2016-11-11 08:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2016-12-09 19:34 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-12-09 19:34 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-12-09 19:34 - 2016-11-11 08:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-12-09 19:34 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-12-09 19:34 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-12-09 19:34 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-12-09 19:34 - 2016-11-11 08:03 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2016-12-09 19:34 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2016-12-09 19:34 - 2016-11-11 08:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-12-09 19:34 - 2016-11-11 08:01 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-12-09 19:34 - 2016-11-11 07:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-12-09 19:22 - 2016-12-09 19:24 - 00287098 _____ C:\TDSSKiller.3.1.0.12_09.12.2016_19.22.22_log.txt 2016-12-09 19:22 - 2016-12-09 19:22 - 04747704 _____ (AO Kaspersky Lab) C:\Users\totti\Downloads\tdsskiller.exe 2016-12-08 01:53 - 2016-12-08 01:55 - 00000000 ____D C:\WINDOWS\Microsoft Antimalware 2016-12-08 01:50 - 2016-12-08 01:50 - 00679784 _____ C:\Users\totti\Downloads\3120677.csv 2016-12-08 01:50 - 2016-12-08 01:50 - 00679784 _____ C:\Users\totti\Downloads\3120677 (1).csv 2016-12-07 22:27 - 2016-12-07 22:27 - 02444400 _____ C:\Users\totti\Downloads\Cinergy_Hybrid_Stick_Drv_Setup_1.00.08.06a_Vista_7_8_64Bit.exe 2016-12-07 22:27 - 2016-12-07 22:27 - 00000000 ____D C:\Program Files (x86)\TERRATEC Electronic GmbH 2016-12-07 22:24 - 2016-12-07 22:24 - 04322312 _____ C:\Users\totti\Downloads\195447-64.exe 2016-12-07 22:21 - 2016-12-07 22:25 - 00000000 ____D C:\Program Files (x86)\Terratec 2016-12-07 22:21 - 2016-12-07 22:21 - 04322240 _____ C:\Users\totti\Downloads\193534-64.exe 2016-12-07 22:21 - 2016-12-07 22:21 - 00000000 ____D C:\Program Files\DIFX 2016-12-07 22:18 - 2016-12-07 22:18 - 10998160 _____ C:\Users\totti\Downloads\TERRATEC_CINERGY_T2_Stick_HD_Driver_Setup_5.2013.0725.0_XP_Vista_7_8.exe 2016-12-07 22:16 - 2016-12-07 22:16 - 00000000 ____D C:\TerraTec 2016-12-07 22:15 - 2016-12-07 22:15 - 00069632 _____ C:\Users\totti\Downloads\Cinergy_T2_Drv_Vista_XP_2.3.0.26.exe 2016-12-07 22:06 - 2016-12-07 22:06 - 01212416 _____ C:\Users\totti\Downloads\42PD7200D.0003.pdf 2016-12-07 04:07 - 2016-12-07 04:07 - 00000000 ____D C:\Users\Thorsten\AppData\Local\EgisTec IPS 2016-12-06 23:09 - 2016-12-06 23:09 - 00000000 ____D C:\Users\totti\AppData\Local\EgisTec IPS 2016-12-06 23:09 - 2016-12-06 23:09 - 00000000 ____D C:\Users\totti\AppData\Local\EgisTec 2016-12-06 22:40 - 2016-12-06 23:09 - 00000000 ____D C:\ProgramData\EgisTec IPS 2016-12-06 22:40 - 2016-12-06 22:40 - 00062776 _____ (Egis Technology Inc.) C:\WINDOWS\system32\Drivers\mwlPSDVDisk.sys 2016-12-06 22:40 - 2016-12-06 22:40 - 00022648 _____ (Egis Technology Inc.) C:\WINDOWS\system32\Drivers\mwlPSDFilter.sys 2016-12-06 22:40 - 2016-12-06 22:40 - 00020520 _____ (Egis Technology Inc.) C:\WINDOWS\system32\Drivers\mwlPSDNserv.sys 2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EgisTec 2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\ProgramData\EgisTec 2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\Program Files\EgisTec IPS 2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\Program Files (x86)\EgisTec IPS 2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\Program Files (x86)\EgisTec BioExcess 2016-12-06 22:16 - 2016-12-06 22:17 - 49911681 _____ C:\Users\totti\Downloads\Fingerprint_EGISTEC_3.5.1.0_W10x64_A.zip 2016-12-06 22:13 - 2016-12-06 22:13 - 00096096 _____ C:\Users\totti\Downloads\serialnumberdetectiontool.exe 2016-12-06 21:10 - 2016-12-07 22:18 - 00000000 ____D C:\Users\totti\AppData\Local\Downloaded Installations 2016-12-06 20:15 - 2016-12-09 19:21 - 00003274 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2016-12-06 03:00 - 2016-12-06 03:00 - 00376528 _____ (Microsoft Corporation) C:\Users\Thorsten\Downloads\RefreshWindowsTool.exe 2016-12-06 00:18 - 2016-12-06 00:18 - 00009218 _____ C:\Users\totti\Desktop\eset.txt 2016-12-05 23:06 - 2016-12-05 23:06 - 00109608 _____ C:\Users\totti\Desktop\FRST.txt 2016-12-05 23:06 - 2016-12-05 23:06 - 00038177 _____ C:\Users\totti\Desktop\Addition.txt 2016-12-05 23:05 - 2016-12-11 17:53 - 00023473 _____ C:\Users\totti\Downloads\FRST.txt 2016-12-05 23:05 - 2016-12-05 23:06 - 00038174 _____ C:\Users\totti\Downloads\Addition.txt 2016-12-05 23:04 - 2016-12-10 20:40 - 02420224 _____ (Farbar) C:\Users\totti\Downloads\FRST64.exe 2016-12-05 22:30 - 2016-12-05 22:30 - 00101330 _____ C:\Users\Thorsten\Desktop\FRST.txt 2016-12-05 22:30 - 2016-12-05 22:30 - 00033068 _____ C:\Users\Thorsten\Desktop\Addition.txt 2016-12-05 22:29 - 2016-12-11 17:53 - 00000000 ____D C:\FRST 2016-12-05 22:29 - 2016-12-05 22:30 - 00101327 _____ C:\Users\Thorsten\Downloads\FRST.txt 2016-12-05 22:29 - 2016-12-05 22:30 - 00033065 _____ C:\Users\Thorsten\Downloads\Addition.txt 2016-12-05 22:28 - 2016-12-05 22:29 - 02419712 _____ (Farbar) C:\Users\Thorsten\Downloads\FRST64.exe 2016-12-05 20:19 - 2016-12-05 20:19 - 00000000 ____D C:\Program Files (x86)\ESET 2016-12-05 20:18 - 2016-12-05 20:18 - 00001741 _____ C:\22222222222222.txt 2016-12-05 20:17 - 2016-12-05 20:17 - 00002309 _____ C:\1111111111111111.txt 2016-12-05 19:02 - 2016-12-05 20:19 - 02870984 _____ (ESET) C:\Users\totti\Downloads\esetsmartinstaller_deu.exe 2016-12-05 18:58 - 2016-12-11 16:06 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-12-05 18:58 - 2016-12-05 18:58 - 00001171 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-12-05 18:58 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2016-12-05 18:58 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-12-05 18:58 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-12-05 18:57 - 2016-12-05 18:57 - 22851472 _____ (Malwarebytes ) C:\Users\totti\Downloads\mbam-setup-2.2.1.1043.exe 2016-12-05 18:45 - 2016-12-05 18:45 - 00000000 ____D C:\Users\totti\AppData\Roaming\Macromedia 2016-12-05 18:38 - 2016-12-07 20:55 - 00000000 ____D C:\Users\totti\AppData\LocalLow\Mozilla 2016-12-05 18:38 - 2016-12-05 18:44 - 00000000 ____D C:\Users\totti\AppData\Local\Mozilla 2016-12-05 18:38 - 2016-12-05 18:38 - 00000000 ____D C:\Users\totti\AppData\Roaming\Mozilla 2016-12-04 23:49 - 2016-12-04 23:49 - 00000000 ____D C:\Users\totti\AppData\Local\PeerDistRepub 2016-12-04 23:07 - 2016-12-04 23:07 - 00030100 _____ C:\Users\totti\Downloads\entschuld13.pdf 2016-12-04 22:39 - 2016-12-04 22:39 - 00001359 _____ C:\Users\Public\Desktop\EaseUS Todo PCTrans.lnk 2016-12-04 22:39 - 2016-12-04 22:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo PCTrans 2016-12-04 22:39 - 2016-12-04 22:39 - 00000000 ____D C:\Program Files (x86)\EaseUS 2016-12-04 22:38 - 2016-12-05 18:44 - 00000000 ____D C:\Users\totti\AppData\Local\MicrosoftEdge 2016-12-04 22:38 - 2016-12-04 22:39 - 05335456 _____ (EaseUS ) C:\Users\totti\Downloads\pctrans.exe 2016-12-04 22:21 - 2016-12-04 21:37 - 02359296 ____H C:\Users\totti\NTUSER (2).DAT 2016-12-04 22:21 - 2016-12-04 21:37 - 02359296 ____H C:\Users\Thorsten\NTUSER - Kopie.DAT 2016-12-04 19:28 - 2016-12-04 19:28 - 00000000 ____D C:\Users\totti\AppData\Roaming\Intel Corporation 2016-12-04 19:27 - 2016-12-11 15:42 - 00000000 ___RD C:\Users\totti\OneDrive 2016-12-04 19:27 - 2016-12-10 17:42 - 00000000 ____D C:\Users\totti\AppData\Local\Comms 2016-12-04 19:27 - 2016-12-09 19:21 - 00002383 _____ C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Skype 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Logishrd 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Apple Computer 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Local\Western_Digital_Technolog 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Local\SS22.2.28 2016-12-04 19:26 - 2016-12-10 17:41 - 00000000 ____D C:\Users\totti\AppData\Local\Packages 2016-12-04 19:26 - 2016-12-10 03:16 - 00000000 ____D C:\Users\totti 2016-12-04 19:26 - 2016-12-04 19:41 - 00000000 ____D C:\Users\totti\AppData\Local\Google 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Vorlagen 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Startmenü 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Netzwerkumgebung 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Lokale Einstellungen 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Eigene Dateien 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Druckumgebung 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Videos 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Musik 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Bilder 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Local\Verlauf 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Local\Anwendungsdaten 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Anwendungsdaten 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Roaming\Adobe 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\VirtualStore 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\TileDataLayer 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\Publishers 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\ConnectedDevicesPlatform 2016-12-04 19:26 - 2016-11-27 00:07 - 00000020 ___SH C:\Users\totti\ntuser.ini 2016-12-04 01:23 - 2016-12-04 01:23 - 00000000 ____D C:\Program Files (x86)\Hercules 2016-12-04 01:22 - 2016-12-04 01:23 - 31550240 _____ (Hercules) C:\Users\Thorsten\Downloads\HWNU-300_V3.7.exe 2016-12-04 00:30 - 2016-12-04 00:30 - 04640844 _____ C:\Users\Thorsten\Downloads\WLR-5100v1001-firmware-v30.zip 2016-12-04 00:30 - 2016-12-04 00:30 - 02952963 _____ C:\Users\Thorsten\Downloads\WLR-5100v1001-Full-Manual.pdf 2016-12-04 00:27 - 2016-12-04 00:27 - 02952963 _____ C:\Users\Thorsten\Downloads\manual (2).pdf 2016-12-03 18:32 - 2016-12-03 18:32 - 00000000 ____D C:\Users\Thorsten\AppData\Local\TeamViewer 2016-12-02 23:38 - 2016-12-04 19:15 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-12-02 23:38 - 2016-12-03 18:38 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\TeamViewer 2016-12-02 23:38 - 2016-12-02 23:38 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk 2016-12-02 23:38 - 2016-12-02 23:38 - 00001100 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk 2016-12-02 23:35 - 2015-06-22 12:20 - 00000000 ____D C:\Users\Thorsten\Downloads\DIR-825_fw_revb_210b01_ALL_multi_20150609 2016-12-02 23:34 - 2016-12-02 23:37 - 12877352 _____ (TeamViewer GmbH) C:\Users\Thorsten\Downloads\TeamViewer_Setup_de-agkp.exe 2016-12-02 23:26 - 2016-12-02 23:26 - 05286401 _____ C:\Users\Thorsten\Downloads\DIR-825_fw_revb_210b01_ALL_multi_20150609.zip 2016-12-02 23:23 - 2016-12-02 23:23 - 00029312 _____ C:\Users\Thorsten\Downloads\config.bin 2016-12-02 21:07 - 2016-12-02 21:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\ElevatedDiagnostics 2016-12-02 19:13 - 2016-12-02 19:13 - 00720417 _____ C:\Users\Thorsten\Downloads\Anleitung_WLAN-Router_als_Accesspoint_mit_Hitron_oder_CiscoEPC3208_Kabelmodem.pdf 2016-12-02 02:36 - 2016-12-02 02:36 - 1214701263 _____ C:\WINDOWS\MEMORY.DMP 2016-12-02 02:36 - 2016-12-02 02:36 - 00586244 _____ C:\WINDOWS\Minidump\120216-8265-01.dmp 2016-12-02 02:36 - 2016-12-02 02:36 - 00000000 ____D C:\WINDOWS\Minidump 2016-12-02 01:51 - 2016-12-02 01:51 - 00000000 ____D C:\Users\ttjh1\AppData\Local\PeerDistRepub 2016-12-01 21:31 - 2016-12-01 21:31 - 00166225 _____ C:\Users\Thorsten\Downloads\AVM-Merry-Christmas_2016.zip 2016-12-01 02:33 - 2016-12-01 02:33 - 04851072 _____ C:\Users\Thorsten\Downloads\cfosspeed-v1020.exe 2016-11-30 12:10 - 2016-11-30 12:10 - 00000000 ____D C:\ProgramData\Trymedia 2016-11-30 12:10 - 2016-11-30 12:10 - 00000000 ____D C:\ProgramData\GoBit Games 2016-11-30 10:12 - 2016-11-30 10:12 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Macromedia 2016-11-30 10:12 - 2016-11-30 10:12 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Comms 2016-11-30 10:11 - 2016-11-30 10:11 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Intel Corporation 2016-11-30 10:10 - 2016-12-11 07:32 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Packages 2016-11-30 10:10 - 2016-12-01 19:13 - 00000000 ____D C:\Users\ttjh1\AppData\Local\ConnectedDevicesPlatform 2016-11-30 10:10 - 2016-11-30 16:32 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Google 2016-11-30 10:10 - 2016-11-30 10:11 - 00002383 _____ C:\Users\ttjh1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-11-30 10:10 - 2016-11-30 10:10 - 00000020 ___SH C:\Users\ttjh1\ntuser.ini 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Skype 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Logishrd 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Apple Computer 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Adobe 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Western_Digital_Technolog 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\VirtualStore 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\TileDataLayer 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\SS22.2.28 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Publishers 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\MicrosoftEdge 2016-11-30 03:08 - 2016-11-30 03:28 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Apple Computer 2016-11-30 03:08 - 2016-11-30 03:08 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2016-11-30 03:08 - 2016-11-30 03:08 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apple Computer 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apple 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Apple Computer 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\iTunes 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\iPod 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\Common Files\Apple 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\Bonjour 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files (x86)\Bonjour 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2016-11-30 03:04 - 2016-11-30 03:07 - 177311560 _____ (Apple Inc.) C:\Users\Thorsten\Downloads\iTunes6464Setup.exe 2016-11-30 00:21 - 2016-11-30 00:21 - 00004566 _____ C:\Users\Thorsten\Downloads\oscam_2016-11-30_0021_oscam.log.tgz 2016-11-29 21:28 - 2016-11-29 21:28 - 00000582 _____ C:\Users\Thorsten\Downloads\Enable_Num_Lock_on_Sign-in_screen.reg 2016-11-29 02:32 - 2016-11-29 02:32 - 00003344 _____ C:\WINDOWS\System32\Tasks\SamsungMagician 2016-11-29 02:32 - 2016-11-29 02:32 - 00001298 _____ C:\Users\Public\Desktop\Samsung Magician.lnk 2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\ProgramData\Samsung 2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\Program Files (x86)\Samsung 2016-11-29 02:31 - 2016-05-13 08:52 - 19226728 _____ (Samsung Electronics ) C:\Users\Thorsten\Downloads\Samsung_Magician_Setup_v497.exe 2016-11-29 02:30 - 2016-11-29 02:31 - 18946704 _____ C:\Users\Thorsten\Downloads\Samsung_Magician_Setup_v497.zip 2016-11-29 01:41 - 2016-11-29 01:41 - 00629880 _____ C:\Users\Thorsten\Downloads\oscam-emu-mips-freetz11281-fritz73xxOS62-webif-libusb_st 2016-11-29 01:36 - 2016-11-29 01:36 - 00213602 _____ C:\Users\Thorsten\Downloads\list_smargo-1 (3).20-emu11232-mips-freetz-linux-uclibc-libusb |
11.12.2016, 18:09 | #20 |
| Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?Code:
ATTFilter 2016-11-29 00:13 - 2016-11-29 00:13 - 04083028 _____ C:\Users\Thorsten\Downloads\WDAccess_1.4.5949.29996.zip 2016-11-29 00:13 - 2016-11-29 00:13 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Western_Digital_Technolog 2016-11-29 00:11 - 2016-11-29 00:11 - 08497626 _____ C:\Users\Thorsten\Downloads\WDSync_1.3.5949.26210.zip 2016-11-28 23:48 - 2016-11-28 23:48 - 00000000 ____D C:\Users\Thorsten\Downloads\DIP5_10360 2016-11-28 23:43 - 2016-11-28 23:28 - 00404752 _____ (Intel Corporation) C:\WINDOWS\system32\PROUnstl.exe 2016-11-28 23:43 - 2016-11-28 23:28 - 00001904 ____N C:\WINDOWS\system32\SetupBD.din 2016-11-28 23:40 - 2016-11-28 23:40 - 00000000 ____D C:\Users\Thorsten\Downloads\ROGConnectPlus_Win7-81-10_V10030 2016-11-28 23:40 - 2015-06-05 09:37 - 00192512 _____ (ASUSTeK Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\UpdateHelper.dll 2016-11-28 23:39 - 2016-11-28 23:39 - 00001769 _____ C:\WINDOWS\Language_trs.ini 2016-11-28 23:39 - 2016-11-28 23:37 - 00011832 _____ C:\WINDOWS\SysWOW64\Drivers\AsInsHelp64.sys 2016-11-28 23:39 - 2016-11-28 23:37 - 00010216 _____ C:\WINDOWS\SysWOW64\Drivers\AsInsHelp32.sys 2016-11-28 23:37 - 2016-11-28 23:37 - 00000000 ____D C:\Users\Thorsten\Downloads\FRONTBASE-10117 2016-11-28 23:28 - 2016-11-28 23:28 - 00316736 _____ (Intel Corporation) C:\WINDOWS\system32\PRONtObj.dll 2016-11-28 23:28 - 2016-11-28 23:28 - 00155192 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iANSW60e.sys 2016-11-28 23:27 - 2016-11-28 23:27 - 00000000 ____D C:\Users\Thorsten\Downloads\Intel_Gigabit_Ethernet_Win7-81_V20230010_Win10_V20240010 2016-11-28 23:24 - 2016-11-28 23:43 - 00000000 ____D C:\Program Files\Intel 2016-11-28 23:24 - 2016-11-28 23:24 - 02037236 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ____D C:\Users\Thorsten\Intel 2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Intel Corporation 2016-11-28 23:23 - 2016-11-28 23:23 - 00002056 _____ C:\Users\Public\Desktop\ASUS Boot Setting.lnk 2016-11-28 23:23 - 2016-11-28 23:23 - 00000000 ____D C:\Users\Thorsten\Downloads\ASUS_BootSetting_Win7-81-10_VER10022 2016-11-27 16:52 - 2016-11-27 17:02 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0 (2).exe 2016-11-27 16:15 - 2016-12-04 16:38 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4564E7FE-E9AE-4766-8A69-A4964C928904} 2016-11-27 16:15 - 2016-11-27 16:15 - 02722395 _____ C:\Users\Thorsten\Downloads\jperf-2.0.2.zip 2016-11-27 16:15 - 2016-11-27 16:15 - 00000000 ____D C:\Users\Thorsten\Desktop\jperf-2.0.2 2016-11-27 16:12 - 2016-11-27 16:12 - 00606026 _____ C:\Users\Thorsten\Downloads\iperf-master.zip 2016-11-27 16:12 - 2016-11-27 16:12 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Sun 2016-11-27 16:11 - 2016-11-27 16:15 - 00000000 ____D C:\ProgramData\Oracle 2016-11-27 16:11 - 2016-11-27 16:11 - 00737344 _____ (Oracle Corporation) C:\Users\Thorsten\Downloads\JavaSetup8u111.exe 2016-11-27 16:11 - 2016-11-27 16:11 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-11-27 16:11 - 2016-11-27 16:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-11-27 16:11 - 2016-11-27 16:11 - 00000000 ____D C:\Program Files (x86)\Java 2016-11-27 16:09 - 2016-12-05 21:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-11-27 16:09 - 2016-12-05 21:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-11-27 16:09 - 2016-11-27 16:16 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Mozilla 2016-11-27 16:09 - 2016-11-27 16:10 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Mozilla 2016-11-27 16:09 - 2016-11-27 16:09 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-11-27 16:09 - 2016-11-27 16:09 - 00001216 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-11-27 16:08 - 2016-11-27 16:09 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0 (1).exe 2016-11-27 16:05 - 2016-11-27 16:05 - 00248583 _____ C:\Users\Thorsten\Downloads\iperf-2.0.5.tar.gz 2016-11-27 15:42 - 2016-11-29 00:00 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Wireshark 2016-11-27 15:22 - 2016-11-27 15:35 - 49242104 _____ (Wireshark development team) C:\Users\Thorsten\Downloads\Wireshark-win64-2.2.2.exe 2016-11-27 15:16 - 2016-11-27 15:16 - 02970395 _____ C:\Users\Thorsten\Downloads\cacti-0.8.8h.zip 2016-11-27 14:29 - 2016-11-27 14:29 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps 2016-11-27 14:13 - 2016-11-27 14:13 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2016-11-27 04:53 - 2016-11-27 04:53 - 00000000 ____D C:\Users\Thorsten\Downloads\Asmedia_USB3_V116351 2016-11-27 04:52 - 2016-11-27 14:14 - 00002685 _____ C:\Users\Public\Desktop\ASUS(R) Intel(R) Extreme Tuning Utility.lnk 2016-11-27 04:52 - 2016-11-27 14:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS(R) Intel(R) Extreme Tuning Utility 2016-11-27 04:52 - 2016-11-27 14:13 - 00000000 ____D C:\WINDOWS\System32\Tasks\Intel 2016-11-27 04:52 - 2016-11-27 04:54 - 00000000 ____D C:\Users\Thorsten\AppData\Local\SS22.2.28 2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2016-11-27 04:52 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll 2016-11-27 04:52 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll 2016-11-27 04:52 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll 2016-11-27 04:52 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll 2016-11-27 04:50 - 2016-11-29 00:13 - 00000000 ____D C:\ProgramData\Package Cache 2016-11-27 04:50 - 2016-11-27 04:50 - 00003214 _____ C:\WINDOWS\System32\Tasks\SS2UILauncherRun 2016-11-27 04:50 - 2016-11-27 04:50 - 00003202 _____ C:\WINDOWS\System32\Tasks\SS2Svc64Run 2016-11-27 04:50 - 2016-11-27 04:50 - 00003194 _____ C:\WINDOWS\System32\Tasks\SS2Svc32Run 2016-11-27 04:50 - 2016-11-27 04:50 - 00001338 _____ C:\Users\Public\Desktop\Sonic Studio.lnk 2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonic Suite 2 2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\Program Files\ASUSTeKcomputer.Inc 2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\Program Files (x86)\SAVITECH 2016-11-27 04:50 - 2016-11-27 04:42 - 72520720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat 2016-11-27 04:50 - 2016-11-27 04:42 - 06879938 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT 2016-11-27 04:50 - 2016-11-27 04:42 - 05593624 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 03283248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 03203592 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 02895104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl 2016-11-27 04:50 - 2016-11-27 04:42 - 02073096 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 01360528 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 01003864 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00689888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00192992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00118600 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00105312 _____ C:\WINDOWS\system32\audioLibVc.dll 2016-11-27 04:50 - 2016-11-27 04:41 - 00003008 ____N C:\WINDOWS\system32\Drivers\DTSU2P.DAT 2016-11-27 04:48 - 2016-11-27 04:48 - 00000000 ____D C:\Program Files\Realtek 2016-11-27 04:47 - 2016-11-27 04:41 - 02838232 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll 2016-11-27 04:46 - 2016-11-27 04:46 - 00000000 _____ C:\WINDOWS\SysWOW64\Drivers\1043_ASUSTeK_MAXIMUS VIII RANGER.alu 2016-11-27 04:42 - 2016-11-27 04:50 - 00000000 ___HD C:\Program Files (x86)\Temp 2016-11-27 04:42 - 2016-11-27 04:42 - 00000000 ____D C:\Program Files (x86)\Realtek 2016-11-27 04:41 - 2016-12-11 15:38 - 01048576 _____ C:\WINDOWS\PE_Rom.dll 2016-11-27 04:41 - 2016-11-27 04:41 - 00000000 ____D C:\Users\Thorsten\Downloads\V7904_20160815_WHQL_DTS_StudioSound_SonicSuite_2228 2016-11-27 04:41 - 2016-07-12 19:04 - 00024824 ____N (ASUSTeK Computer Inc.) C:\WINDOWS\system32\Drivers\IOMap64.sys 2016-11-27 04:17 - 2016-11-28 23:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2016-11-27 04:17 - 2016-11-27 04:17 - 00000000 ____D C:\Program Files\ASUS 2016-11-27 04:17 - 2016-11-27 04:17 - 00000000 ____D C:\Program Files (x86)\ASM104xUSB3 2016-11-27 04:17 - 2016-11-27 04:15 - 00046152 _____ (MCCI Corporation) C:\WINDOWS\SysWOW64\Drivers\ASUSFILTER.sys 2016-11-27 04:17 - 2016-11-27 04:15 - 00014464 _____ C:\WINDOWS\SysWOW64\Drivers\AsUpIO.sys 2016-11-27 04:16 - 2016-12-06 22:40 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-11-27 04:16 - 2016-11-28 23:49 - 00000000 ____D C:\WINDOWS\System32\Tasks\ASUS 2016-11-27 04:16 - 2016-11-28 23:24 - 00000000 ____D C:\ProgramData\Intel 2016-11-27 04:16 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Intel 2016-11-27 04:16 - 2015-10-19 17:22 - 00022192 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\AndroidAFDx64.sys 2016-11-27 04:16 - 2013-01-28 15:58 - 00014848 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\AiChargerPlus.sys 2016-11-27 04:15 - 2016-11-28 23:40 - 00000000 ____D C:\Program Files (x86)\ASUS 2016-11-27 04:15 - 2016-11-27 04:15 - 00028672 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\AsIO.dll 2016-11-27 04:15 - 2016-11-27 04:15 - 00015232 _____ C:\WINDOWS\SysWOW64\Drivers\AsIO.sys 2016-11-27 04:15 - 2016-11-27 04:15 - 00000000 ____D C:\Users\Thorsten\Downloads\AISuite3_Win7-81-10_MaxVIII_Series_V10130 2016-11-27 04:14 - 2016-11-28 23:50 - 00000000 ____D C:\ProgramData\ASUS 2016-11-27 04:13 - 2016-11-27 04:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2016-11-27 04:13 - 2016-11-27 04:13 - 00000000 ____D C:\Program Files\7-Zip 2016-11-27 04:11 - 2016-11-27 04:14 - 122808649 _____ C:\Users\Thorsten\Downloads\DIP5_10360.zip 2016-11-27 04:11 - 2016-11-27 04:12 - 37822895 _____ C:\Users\Thorsten\Downloads\ASUS_XTU_V612208.zip 2016-11-27 04:06 - 2016-11-27 04:06 - 00001806 _____ C:\Users\Public\Desktop\HDClone.lnk 2016-11-27 04:06 - 2016-11-27 04:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDClone 6 Free Edition 2016-11-27 04:05 - 2016-11-27 04:06 - 00000000 ____D C:\Program Files (x86)\HDClone 6 Free Edition 2016-11-27 02:54 - 2016-11-27 02:54 - 201326592 _____ C:\Users\Thorsten\Downloads\clonezilla-live-2.5.0-5-amd64.iso 2016-11-27 02:33 - 2016-11-27 02:33 - 00000000 ____D C:\Program Files\Common Files\Logishrd 2016-11-27 02:19 - 2016-11-27 02:19 - 141011376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-11-27 02:19 - 2016-11-27 02:19 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-11-27 02:19 - 2016-11-27 02:09 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2016-11-27 02:16 - 2016-11-27 02:20 - 71601392 _____ C:\Users\Thorsten\Downloads\mc_windows_setup (1).exe 2016-11-27 01:13 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Apple 2016-11-27 01:13 - 2016-11-29 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital 2016-11-27 01:13 - 2016-11-29 00:11 - 00000000 ____D C:\ProgramData\Western Digital 2016-11-27 01:13 - 2016-11-29 00:11 - 00000000 ____D C:\Program Files (x86)\Western Digital 2016-11-27 01:13 - 2016-11-27 01:13 - 00001226 _____ C:\Users\Public\Desktop\WD My Cloud.lnk 2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\Downloads\WD_Quick_View_Setup_for_Windows 2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Macromedia 2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\com.wd.WDMyCloud 2016-11-27 01:12 - 2016-11-27 01:13 - 63849440 _____ C:\Users\Thorsten\Downloads\WDMyCloud_win.exe 2016-11-27 01:12 - 2016-11-27 01:13 - 04341113 _____ C:\Users\Thorsten\Downloads\WD_Quick_View_Setup_for_Windows.zip 2016-11-27 01:09 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Western Digital 2016-11-27 01:08 - 2016-11-27 02:23 - 00001130 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-11-27 01:08 - 2016-11-27 02:23 - 00001126 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-11-27 01:08 - 2016-11-27 01:17 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Google 2016-11-27 01:08 - 2016-11-27 01:09 - 71601392 _____ C:\Users\Thorsten\Downloads\mc_windows_setup.exe 2016-11-27 01:08 - 2016-11-27 01:08 - 01065376 _____ (Google Inc.) C:\Users\Thorsten\Downloads\ChromeSetup.exe 2016-11-27 01:08 - 2016-11-27 01:08 - 00004188 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-11-27 01:08 - 2016-11-27 01:08 - 00003956 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-11-27 01:08 - 2016-11-27 01:08 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-11-27 01:08 - 2016-11-27 01:08 - 00002324 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-11-27 01:08 - 2016-11-27 01:08 - 00000000 ____D C:\Program Files (x86)\Google 2016-11-27 00:43 - 2016-11-27 02:33 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Logitech 2016-11-27 00:43 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logitech 2016-11-27 00:43 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Deployment 2016-11-27 00:14 - 2016-11-27 00:59 - 00000000 ____D C:\Users\Thorsten\AppData\Local\MicrosoftEdge 2016-11-27 00:11 - 2016-11-27 02:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2016-11-27 00:11 - 2016-11-27 02:34 - 00000000 ____D C:\ProgramData\Logishrd 2016-11-27 00:11 - 2016-11-27 02:33 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Logishrd 2016-11-27 00:11 - 2016-11-27 02:33 - 00000000 ____D C:\Program Files\Logitech 2016-11-27 00:11 - 2016-11-27 00:11 - 00000000 ____D C:\Users\Thorsten\AppData\Local\PeerDistRepub 2016-11-27 00:09 - 2016-12-07 04:08 - 00002392 _____ C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Skype 2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Comms 2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2016-11-27 00:08 - 2016-11-27 00:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Publishers 2016-11-27 00:07 - 2016-12-02 02:58 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Packages 2016-11-27 00:07 - 2016-11-27 02:30 - 00000000 ____D C:\Users\Thorsten\AppData\Local\ConnectedDevicesPlatform 2016-11-27 00:07 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apps\2.0 2016-11-27 00:07 - 2016-11-27 00:07 - 00000020 ___SH C:\Users\Thorsten\ntuser.ini 2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Adobe 2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Local\VirtualStore 2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Local\TileDataLayer 2016-11-26 23:55 - 2016-12-11 07:35 - 02624340 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Vorlagen 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Startmenü 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\All Users 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Vorlagen 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Startmenü 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Dokumente 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2016-11-26 23:53 - 2016-11-26 23:53 - 00017426 _____ C:\Users\Thorsten\Desktop\Entfernte Apps.html 2016-11-26 23:53 - 2016-11-26 23:53 - 00016796 _____ C:\Users\ttjh1\Desktop\Entfernte Apps.html 2016-11-26 23:53 - 2016-07-16 12:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2016-11-26 23:50 - 2016-12-11 07:35 - 00000000 ____D C:\Users\ttjh1 2016-11-26 23:50 - 2016-12-04 22:21 - 00000000 ____D C:\Users\Thorsten 2016-11-26 23:50 - 2016-11-27 04:50 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Vorlagen 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Startmenü 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Netzwerkumgebung 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Lokale Einstellungen 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Eigene Dateien 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Druckumgebung 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Local\Verlauf 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Local\Anwendungsdaten 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Anwendungsdaten 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Vorlagen 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Startmenü 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Netzwerkumgebung 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Lokale Einstellungen 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Eigene Dateien 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Druckumgebung 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Videos 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Musik 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Bilder 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Local\Verlauf 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Local\Anwendungsdaten 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Anwendungsdaten 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____D C:\ProgramData\USOShared 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____D C:\ProgramData\NVIDIA 2016-11-26 23:49 - 2016-12-11 17:51 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2016-11-26 23:49 - 2016-12-11 07:29 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-11-26 23:49 - 2016-12-09 19:43 - 00198392 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-11-26 23:49 - 2015-11-05 16:08 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 02554672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2016-11-26 23:49 - 2015-11-05 16:08 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2016-11-26 23:49 - 2015-10-28 14:49 - 06027430 _____ C:\WINDOWS\system32\nvcoproc.bin 2016-11-26 23:48 - 2016-11-27 00:23 - 00000000 ____D C:\Windows.old 2016-11-26 23:48 - 2016-11-26 23:54 - 00000000 ___DC C:\WINDOWS\Panther 2016-11-26 23:48 - 2016-11-26 23:49 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2016-11-26 23:48 - 2016-11-26 23:48 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2016-11-26 23:48 - 2016-11-26 23:48 - 00000000 ____D C:\WINDOWS\InfusedApps 2016-11-26 23:47 - 2016-12-11 07:35 - 01218274 _____ C:\WINDOWS\system32\perfh007.dat 2016-11-26 23:47 - 2016-12-11 07:35 - 00283292 _____ C:\WINDOWS\system32\perfc007.dat 2016-11-26 23:47 - 2016-11-26 23:47 - 00305594 _____ C:\WINDOWS\system32\perfi007.dat 2016-11-26 23:47 - 2016-11-26 23:47 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\de 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\0409 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\winrm 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\WCN 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\slmgr 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\de 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\0409 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\Setup 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\OCR 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\DigitalLocker 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Reference Assemblies 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\MSBuild 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files (x86)\MSBuild 2016-11-26 23:46 - 2016-10-29 00:56 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-11-26 23:46 - 2016-10-29 00:56 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-11-26 23:45 - 2016-12-11 15:44 - 00000000 ___HD C:\Program Files\WindowsApps 2016-11-26 23:45 - 2016-12-11 15:44 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-11-26 23:45 - 2016-12-11 04:49 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2016-11-26 23:45 - 2016-12-11 01:10 - 00000000 ____D C:\WINDOWS\rescache 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-11-26 23:45 - 2016-12-05 21:16 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-11-26 23:45 - 2016-12-04 00:40 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-11-26 23:45 - 2016-11-29 00:13 - 00000000 ____D C:\WINDOWS\Registration 2016-11-26 23:45 - 2016-11-27 04:55 - 00000000 ____D C:\WINDOWS\appcompat 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\F12 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\dsc 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___RD C:\Program Files\Windows Defender 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\SysWOW64\setup 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\setup 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\migwiz 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\Provisioning 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2016-11-26 23:45 - 2016-11-27 02:22 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2016-11-26 23:45 - 2016-11-26 23:54 - 00000000 ____D C:\Program Files\Windows NT 2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 __RHD C:\Users\Public\Libraries 2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 ____D C:\WINDOWS\system32\spool 2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2016-11-26 23:45 - 2016-11-26 23:52 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ___RD C:\WINDOWS\PrintDialog 2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ___RD C:\WINDOWS\MiracastView 2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ____D C:\WINDOWS\CSC 2016-11-26 23:45 - 2016-11-26 23:49 - 00000000 ____D C:\WINDOWS\Help 2016-11-26 23:45 - 2016-11-26 23:48 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Com 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SystemApps 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\MUI 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\Com 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\IME 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Common Files\System 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\Program Files\Windows Sidebar 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __RSD C:\WINDOWS\Media 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\system32\Nui 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\system32\Configuration 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___RD C:\WINDOWS\Offline Web Pages 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Web 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Vss 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\tracing 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\TAPI 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\ras 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SystemResources 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\WinMetadata 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\winevt 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ras 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ProximityToast 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\PointOfService 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\MsDtc 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Ipmi 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\inetsrv 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\IME 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\icsxml 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ias 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\downlevel 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\DDFs 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\config\Journal 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Bthprops 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\AppLocker 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\System 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SKB 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\security 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\schemas 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SchCache 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Resources 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\RemotePackages 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\PLA 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Performance 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\ModemLogs 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\L2Schemas 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\InputMethod 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Globalization 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\GameBarPresenceWriter 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Cursors 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Branding 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\addins 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\ProgramData\USOPrivate 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\ProgramData\Comms 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Windows Portable Devices 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Common Files\Services 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows NT 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-11-26 23:45 - 2016-11-26 23:44 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2016-11-26 23:45 - 2016-11-26 23:44 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat 2016-11-26 23:45 - 2016-11-26 23:44 - 00215943 _____ C:\WINDOWS\system32\dssec.dat 2016-11-26 23:45 - 2016-11-26 23:44 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2016-11-26 23:45 - 2016-11-26 23:44 - 00027136 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll 2016-11-26 23:45 - 2016-11-26 23:44 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services 2016-11-26 23:45 - 2016-11-26 23:44 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK 2016-11-26 23:45 - 2016-11-26 23:44 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam 2016-11-26 23:45 - 2016-11-26 23:44 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol 2016-11-26 23:45 - 2016-11-26 23:44 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json 2016-11-26 23:45 - 2016-11-26 23:44 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT 2016-11-26 23:45 - 2016-11-26 23:44 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT 2016-11-26 23:45 - 2016-11-26 23:44 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks 2016-11-26 23:45 - 2016-11-26 23:44 - 00000219 _____ C:\WINDOWS\system.ini 2016-11-26 23:45 - 2016-11-26 23:44 - 00000092 _____ C:\WINDOWS\win.ini 2016-11-26 23:44 - 2016-12-09 19:43 - 00000000 ____D C:\WINDOWS\INF 2016-11-26 23:42 - 2016-12-10 20:42 - 01835008 _____ C:\WINDOWS\system32\config\BBI 2016-11-26 23:42 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\servicing 2016-11-26 23:42 - 2016-12-09 19:40 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-11-26 23:42 - 2016-11-26 23:49 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2016-11-26 23:42 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\SMI 2016-11-26 20:17 - 2016-11-26 20:17 - 00376528 _____ (Microsoft Corporation) C:\Users\Thorsten\Downloads\Nicht bestätigt 574898.crdownload 2016-11-26 04:07 - 2016-11-26 04:07 - 00000000 ____D C:\Users\Thorsten\Desktop\slenf2aw.fmg 2016-11-26 01:31 - 2016-11-26 01:31 - 04147600 _____ ($Co_Name Inc.) C:\Users\Thorsten\Downloads\unifying250.exe 2016-11-20 20:10 - 2016-12-01 23:14 - 00000000 ____D C:\Users\Thorsten\AppData\LocalLow\Mozilla 2016-11-20 20:09 - 2016-11-20 20:09 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0.exe 2016-11-19 00:03 - 2016-11-19 00:03 - 02952963 _____ C:\Users\Thorsten\Downloads\manual (1).pdf 2016-11-19 00:01 - 2016-11-19 00:01 - 02952963 _____ C:\Users\Thorsten\Downloads\manual.pdf 2016-11-17 17:17 - 2016-11-17 17:17 - 00203900 _____ C:\Users\Thorsten\Downloads\3441119-3290097-Feedback.pdf 2016-11-17 17:07 - 2016-11-17 17:07 - 00183388 _____ C:\Users\Thorsten\Downloads\3440522-3289533-Feedback.pdf 2016-11-16 21:15 - 2016-11-16 21:15 - 00001518 _____ C:\Users\Thorsten\Downloads\LifeCam3.60 (1) - Verknüpfung.lnk 2016-11-16 21:15 - 2016-11-16 21:15 - 00001500 _____ C:\Users\Thorsten\Downloads\ifunbox_setup - Verknüpfung.lnk 2016-11-16 21:15 - 2016-11-16 21:15 - 00001482 _____ C:\Users\Thorsten\Downloads\LifeCam3.60 - Verknüpfung.lnk 2016-11-16 21:15 - 2016-11-16 21:15 - 00001080 _____ C:\Users\Thorsten\Downloads\node-v4.6.1.tar.gz - Verknüpfung.lnk 2016-11-14 18:18 - 2016-11-26 23:30 - 00000000 ___RD C:\Users\Thorsten\iCloudDrive 2016-11-13 03:54 - 2016-11-13 03:54 - 00000000 ____D C:\Users\Thorsten\Documents\Ashampoo Burning Studio 16 ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-11 07:32 - 2016-02-13 18:32 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-12-10 20:41 - 2016-04-22 03:30 - 00000000 ____D C:\Users\Thorsten\AppData\LocalLow\Temp 2016-12-07 04:08 - 2016-04-17 00:15 - 00000000 ___RD C:\Users\Thorsten\OneDrive 2016-11-30 10:11 - 2016-04-17 09:26 - 00000000 ___RD C:\Users\ttjh1\OneDrive 2016-11-28 23:36 - 2016-07-16 12:43 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TFTP.EXE 2016-11-28 23:35 - 2016-10-28 05:24 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmp.exe 2016-11-28 23:35 - 2016-10-28 05:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmp.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00194560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmpsnap.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntwin.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntwin.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntagnt.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntagnt.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hostmib.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\lmmib2.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hostmib.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lmmib2.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntcmd.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntcmd.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64mib.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmpmib.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmpmib.dll 2016-11-28 23:35 - 2016-07-16 12:43 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmpsnap.dll 2016-11-28 23:35 - 2016-07-16 12:43 - 00107882 _____ C:\WINDOWS\SysWOW64\mib_ii.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00107882 _____ C:\WINDOWS\system32\mib_ii.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00048593 _____ C:\WINDOWS\SysWOW64\hostmib.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00048593 _____ C:\WINDOWS\system32\hostmib.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00034317 _____ C:\WINDOWS\SysWOW64\msiprip2.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00034317 _____ C:\WINDOWS\system32\msiprip2.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00030448 _____ C:\WINDOWS\SysWOW64\mcastmib.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00030448 _____ C:\WINDOWS\system32\mcastmib.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00026236 _____ C:\WINDOWS\SysWOW64\wins.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00026236 _____ C:\WINDOWS\system32\wins.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00026100 _____ C:\WINDOWS\SysWOW64\lmmib2.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00026100 _____ C:\WINDOWS\system32\lmmib2.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00022462 _____ C:\WINDOWS\SysWOW64\rfc2571.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00022462 _____ C:\WINDOWS\system32\rfc2571.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00021271 _____ C:\WINDOWS\SysWOW64\http.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00021271 _____ C:\WINDOWS\system32\http.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00015799 _____ C:\WINDOWS\SysWOW64\ipforwd.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00015799 _____ C:\WINDOWS\system32\ipforwd.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00015032 _____ C:\WINDOWS\SysWOW64\authserv.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00015032 _____ C:\WINDOWS\system32\authserv.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00014032 _____ C:\WINDOWS\SysWOW64\accserv.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00014032 _____ C:\WINDOWS\system32\accserv.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00013767 _____ C:\WINDOWS\SysWOW64\msipbtp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00013767 _____ C:\WINDOWS\system32\msipbtp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00006179 _____ C:\WINDOWS\SysWOW64\ftp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00006179 _____ C:\WINDOWS\system32\ftp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00004597 _____ C:\WINDOWS\SysWOW64\dhcp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00004597 _____ C:\WINDOWS\system32\dhcp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00004411 _____ C:\WINDOWS\SysWOW64\smi.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00004411 _____ C:\WINDOWS\system32\smi.mib 2016-11-27 04:42 - 2016-08-19 01:05 - 03133144 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll 2016-11-27 04:42 - 2016-08-19 01:04 - 05793528 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll 2016-11-27 04:42 - 2016-08-19 00:51 - 05258248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys 2016-11-27 04:42 - 2016-08-19 00:51 - 00023696 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll 2016-11-27 00:34 - 2016-08-18 01:13 - 00000000 ____D C:\Windows10Upgrade 2016-11-26 23:44 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-11-26 23:29 - 2016-07-06 18:20 - 00009612 _____ C:\CYGWIN_SYSLOG.TXT 2016-11-25 03:26 - 2016-09-15 23:38 - 00000000 ____D C:\Users\Thorsten\Desktop\Cydia 2016-11-14 18:19 - 2016-04-21 21:16 - 00000000 ____D C:\Users\Thorsten\Documents\Outlook-Dateien 2016-11-14 04:00 - 2016-08-18 01:13 - 00000719 _____ C:\Users\Thorsten\Desktop\Windows 10-Upgrade-Assistent.lnk Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\Thorsten\NTUSER - Kopie.DAT C:\Users\Thorsten\WDMyCloud_win.exe C:\Users\totti\NTUSER (2).DAT ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-12-09 19:38 ==================== Ende von FRST.txt ============================ |
12.12.2016, 17:39 | #21 |
/// TB-Ausbilder /// Anleitungs-Guru | Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?Code:
ATTFilter Administrator (S-1-5-21-2586767532-3616519997-416612805-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2586767532-3616519997-416612805-503 - Limited - Disabled) Gast (S-1-5-21-2586767532-3616519997-416612805-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2586767532-3616519997-416612805-1005 - Limited - Enabled) jenny (S-1-5-21-2586767532-3616519997-416612805-1002 - Limited - Disabled) Thorsten (S-1-5-21-2586767532-3616519997-416612805-1001 - Limited - Enabled) => C:\Users\Thorsten totti (S-1-5-21-2586767532-3616519997-416612805-1006 - Administrator - Enabled) => C:\Users\totti ttjh1 (S-1-5-21-2586767532-3616519997-416612805-1003 - Administrator - Enabled) => C:\Users\ttjh1
__________________ --> Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? |
Themen zu Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? |
administrator, asus, besitzer, bonjour, computer, defender, desktop, e-mail, explorer, installation, mozilla, nvidia, prozesse, realtek, registry, router, rundll, scan, server, services.exe, software, super, svchost.exe, system, usb, windows, windowsapps, winlogon.exe |