Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 10.12.2016, 20:47   #16
totti6169
 
Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? - Standard

Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?



Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-12-2016
durchgeführt von totti (10-12-2016 20:40:48) Run:1
Gestartet von C:\Users\totti\Downloads
Geladene Profile: Thorsten & ttjh1 & totti (Verfügbare Profile: Thorsten & ttjh1 & totti)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
CloseProcesses:
C:\ProgramData\Logishrd\LogiOptions\Software\Current\dma_x64.dll

C:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat

C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat

C:\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe

C:\Users\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm

C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe

C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe

C:\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe

C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm

C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm

C:\Users\Thorsten\Downloads\Options_6.30.80 (1).exe

C:\Users\Thorsten\Downloads\Options_6.30.80.exe

C:\Users\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe

C:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll

C:\Windows.old\Users\Thorsten\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00659b

C:\Windows.old\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\VZR6RD7Z\logioptions_logitech[1].exe

C:\Windows.old\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe

C:\Windows.old\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe

D:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll

D:\Users\Thorsten\Downloads\HP USB Disk Storage Format Tool - CHIP-Installer.exe

D:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll

F:\Documents and Settings\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat

F:\Documents and Settings\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe

F:\Documents and Settings\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm

F:\Documents and Settings\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe

F:\Documents and Settings\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe

F:\Documents and Settings\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe

F:\Documents and Settings\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm

F:\Documents and Settings\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm

F:\Documents and Settings\Thorsten\Downloads\Options_6.30.80 (1).exe

F:\Documents and Settings\Thorsten\Downloads\Options_6.30.80.exe

F:\Documents and Settings\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe

F:\HOME-PC\Backup Set 2015-10-11 200835\Backup Files 2015-10-11 200835\Backup files 8.zip

F:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll

F:\Users\Thorsten\AppData\Local\Temp\is1070216317\MyBabylonTB.exe

F:\Users\Thorsten\AppData\Roaming\OpenCandy\OpenCandy_0181FAC22AA54A5D97FBE1D8AA98F393\LinkuryInstaller.msi

F:\Users\Thorsten\AppData\Roaming\OpenCandy\OpenCandy_0181FAC22AA54A5D97FBE1D8AA98F393\LinkuryInstaller_p1v5.exe

G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R09HRF2.exe

G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R1K4JDO.exe

G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R27UN9B.exe

G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RCK5YYL.exe

G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RLW6BJZ.exe

G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RVOUJKL.exe

G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RXWAU53.exe

G:\Program Files\ConduitEngine\ConduitEngine.dll

G:\Program Files\ConduitEngine\ConduitEngineUninstall.exe

G:\Program Files\DAEMON Tools Pro\DTCommonRes.dll

G:\Program Files\Driver Pro\DPSchedule.exe

G:\Program Files\Driver Pro\DPSmartScan.exe

G:\Program Files\Driver Pro\DPUninstaller.exe

G:\Program Files\Driver Pro\DriverPro.exe

G:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll

G:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\ads_only_5_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\arcadi2_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\corticas_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\cortica_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\coupish_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\dealply_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\intext_fa_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\monetizationLoader[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\monetizationLoader[2].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\resources_background[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\similar_web_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\widdit_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8NFWNK03\pack[2].7z

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\ads_only_5_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\appApiMessage[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\coupish_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\getdeal_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\intext_5_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\intext_adv_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\jollywallet_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\revizer_p_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\similar_web_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\SingAlong_1060-1052_v114[1]

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\superfish_no_coupons_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\superfish_no_coupons_m[2].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\corticas_ru_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\cortica_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\coupons_intext_ads_5_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\icm_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\jollywallet_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\luck_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\superfish_no_search_no_coupons_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\superfish_pricora_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\arcadi3_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\coupons_intext_ads_5_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\CrossriderUtils[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\dealply_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\ibario_pops_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\icm_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\intext_5_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\luck_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\pack[1].7z

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\revizer_ws_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\superfish_m[1].js

G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\superfish_m[2].js

G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\1\92\A5268d01

G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\3\16\CFB4Cd01

G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\4\39\9D74Bd01

G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\6\58\18A64d01

G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\8\AA\ED51Bd01

G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\A\B9\50C7Ed01

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\BrowserHelper.exe

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Interop.SHDocVw.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\MACTrackBarLib.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\NDde.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Newtonsoft.Json.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\QuickShare.exe

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.Base.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.DefaultBrowser.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ShareManagerLocalPlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessEntities.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.PersonalizationSettingsManager.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.PublisherSettingsManager.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.UserSettingsManager.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.BrowserHelperUtils.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.GeneralUtilities.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProductsRemovalLibary.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProductUninstaller.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SetBrowsersSettings.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SetBrowsersSettingsAutoUpdater.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ShortcutsLibrary.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.XmlSerializers.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.Translations.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.UninstallScreen.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.UrlHistorySupplier.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\ar\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\es\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\fr\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\he\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_20.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_21.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_22.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_23.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\it\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\pt\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\ru\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Application\tr\Smartbar.Resources.LanguageSettings.resources.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.DMP.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.NotepadPlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.ScreenCapturePlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.UninstallProductsPlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll

G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WordPlugin.dll

G:\Users\Jaqueline\AppData\Local\Temp\2877.tmp

G:\Users\Jaqueline\AppData\Local\Temp\BackupSetup.exe

G:\Users\Jaqueline\AppData\Local\Temp\che50FF.tmp

G:\Users\Jaqueline\AppData\Local\Temp\MixiDJToolbar.exe

G:\Users\Jaqueline\AppData\Local\Temp\SingAlong.exe

G:\Users\Jaqueline\AppData\Local\Temp\SmartbarExeInstaller.exe

G:\Users\Jaqueline\AppData\Local\Temp\sngalng.exe

G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\BabMaint.exe

G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\BUSolution.dll

G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\CrxInstaller.dll

G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\delta1.crx

G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\IEHelper.dll

G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\MyBabylonTB.exe

G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\Setup.exe

G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BabMaint.exe

G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BExternal.dll

G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BUSolution.dll

G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\CrxInstaller.dll

G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\IEHelper.dll

G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\mixiDj.crx

G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\MyBabylonTB.exe

G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\Setup.exe

G:\Users\Jaqueline\AppData\Local\Temp\bus2A1\CrxUpdater_d.exe

G:\Users\Jaqueline\AppData\Local\Temp\bus2BE0\BUSolution.dll

G:\Users\Jaqueline\AppData\Local\Temp\bus425D\fntupdtr.exe

G:\Users\Jaqueline\AppData\Local\Temp\bus58EA\BUSolution.dll

G:\Users\Jaqueline\AppData\Local\Temp\busA6B\CrxUpdater_d.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\DomaIQ.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\DomaIQ10.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\exes.zip

G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\installer.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Addlyrics.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Delta Babylon.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Format-Factory.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\OptimizerPro.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\DomaIQ.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\DomaIQ10.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\exes.zip

G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\installer.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\DomaIQ.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\DomaIQ10.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\exes.zip

G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\installer.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Driverpro.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Format-Factory

G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Mixi Dj Yahoo.exe

G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\QuickShare1.exe

G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\BExternal.dll

G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\IEHelper.dll

G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Setup.exe

G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\BExternal.dll

G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\IEHelper.dll

G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\MyBabylonTB.exe

G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\Setup.exe

G:\Users\Jaqueline\AppData\Local\Temp\ibtmpc810632\component_612.decrpt

G:\Users\Jaqueline\AppData\Local\Temp\ibtmpc810632\component_625

G:\Users\Jaqueline\AppData\Local\Temp\nseC301.tmp\mt.dll

G:\Users\Jaqueline\AppData\Local\Temp\nsz2378.tmp\mt.dll

G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\LinkuryInstaller.msi

G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\26bd7386-e546-41bb-ba63-886152ebd2d3\LinkuryInstaller.msi

G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\934faaad-8ac9-423b-8166-8e363f9345cd\LinkuryInstaller.msi

G:\Users\Jaqueline\AppData\Local\Temp\upd2348\BabMaint.x

G:\Users\Jaqueline\AppData\Local\Temp\upd2348\BUSolution.x

G:\Users\Jaqueline\AppData\Roaming\BabSolution\CR\delta1.crx

G:\Users\Jaqueline\AppData\Roaming\BabSolution\Shared\BabMaint.exe

G:\Users\Jaqueline\AppData\Roaming\BabSolution\Shared\BUSolution.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_20.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_21.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_22.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_23.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_24.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_20.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_21.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_22.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_23.dll

G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_24.dll

G:\Users\Jaqueline\Downloads\video_downloader.exe

G:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll

G:\Windows\Installer\5916a.msi

G:\Windows\Temp\Optimizer_Pro.exe

H:\Downloads\Dark_Theme - CHIP-Installer (1).exe

H:\Downloads\Dark_Theme - CHIP-Installer (2).exe

H:\Downloads\Dark_Theme - CHIP-Installer.exe

H:\Downloads\MediaPortal - CHIP-Installer.exe

H:\Downloads\micro SIM Schablone PDF Vorlage - CHIP-Installer.exe

H:\Downloads\Nano SIM Schablone PDF Vorlage - CHIP-Installer.exe

H:\Downloads\VLC media player 64 Bit - CHIP-Installer.exe

H:\Downloads\Adobe Creative Cloud Collection 2015\Adobe Creative Cloud Collection 2015\Adobe Creative Cloud Collection 2015\Aktivierung für alle Versionen\XFORCE Cloud 2015\Adobe Block.cmd

H:\Downloads\DAEMON Tools Pro Advanced v6.1.0.0483\DAEMON Tools Pro Advanced v6.1.0.0483.rar

H:\Downloads\DAEMON Tools Pro Advanced v6.1.0.0483\DAEMON Tools Pro Advanced v6.1.0.0483\Activator_DTP\activator.exe

H:\FileHistory\totti\HOME-PC\Data\$OF\979\981 (2015_10_14 22_35_17 UTC).cmd
H:\Neuer Ordner (2)\Program Files (x86)\FunWebProducts\
H:\Neuer Ordner (2)\Program Files (x86)\Conduit
H:\Neuer Ordner (2)\Neuer Ordner\Transcend\Alcohol 120% 2.0.2 Build 5830 Retail\Alcohol120_retail_2.0.2.5830.exe
C:\Users\totti\Downloads\K-Lite_Codec_Pack_1265_Mega_CB-DL-Manager.exe
CreateRestorePoint:
EmptyTemp:


*****************

Prozess erfolgreich geschlossen.
C:\ProgramData\Logishrd\LogiOptions\Software\Current\dma_x64.dll => erfolgreich verschoben
"C:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden.
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe => erfolgreich verschoben
C:\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe => erfolgreich verschoben
C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm => erfolgreich verschoben
C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm => erfolgreich verschoben
C:\Users\Thorsten\Downloads\Options_6.30.80 (1).exe => erfolgreich verschoben
C:\Users\Thorsten\Downloads\Options_6.30.80.exe => erfolgreich verschoben
C:\Users\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe => erfolgreich verschoben
"C:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden.
C:\Windows.old\Users\Thorsten\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00659b => erfolgreich verschoben
C:\Windows.old\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\VZR6RD7Z\logioptions_logitech[1].exe => erfolgreich verschoben
C:\Windows.old\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe => erfolgreich verschoben
C:\Windows.old\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe => erfolgreich verschoben
"D:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden.
D:\Users\Thorsten\Downloads\HP USB Disk Storage Format Tool - CHIP-Installer.exe => erfolgreich verschoben
"D:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden.
"F:\Documents and Settings\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe" => nicht gefunden.
"F:\Documents and Settings\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe" => nicht gefunden.
"F:\Documents and Settings\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm" => nicht gefunden.
"F:\Documents and Settings\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm" => nicht gefunden.
"F:\Documents and Settings\Thorsten\Downloads\Options_6.30.80 (1).exe" => nicht gefunden.
"F:\Documents and Settings\Thorsten\Downloads\Options_6.30.80.exe" => nicht gefunden.
"F:\Documents and Settings\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe" => nicht gefunden.
F:\HOME-PC\Backup Set 2015-10-11 200835\Backup Files 2015-10-11 200835\Backup files 8.zip => erfolgreich verschoben
"F:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden.
F:\Users\Thorsten\AppData\Local\Temp\is1070216317\MyBabylonTB.exe => erfolgreich verschoben
F:\Users\Thorsten\AppData\Roaming\OpenCandy\OpenCandy_0181FAC22AA54A5D97FBE1D8AA98F393\LinkuryInstaller.msi => erfolgreich verschoben
F:\Users\Thorsten\AppData\Roaming\OpenCandy\OpenCandy_0181FAC22AA54A5D97FBE1D8AA98F393\LinkuryInstaller_p1v5.exe => erfolgreich verschoben
G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R09HRF2.exe => erfolgreich verschoben
G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R1K4JDO.exe => erfolgreich verschoben
G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$R27UN9B.exe => erfolgreich verschoben
G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RCK5YYL.exe => erfolgreich verschoben
G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RLW6BJZ.exe => erfolgreich verschoben
G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RVOUJKL.exe => erfolgreich verschoben
G:\$Recycle.Bin\S-1-5-21-841948778-772456818-3102405132-1001\$RXWAU53.exe => erfolgreich verschoben
G:\Program Files\ConduitEngine\ConduitEngine.dll => erfolgreich verschoben
G:\Program Files\ConduitEngine\ConduitEngineUninstall.exe => erfolgreich verschoben
G:\Program Files\DAEMON Tools Pro\DTCommonRes.dll => erfolgreich verschoben
G:\Program Files\Driver Pro\DPSchedule.exe => erfolgreich verschoben
G:\Program Files\Driver Pro\DPSmartScan.exe => erfolgreich verschoben
G:\Program Files\Driver Pro\DPUninstaller.exe => erfolgreich verschoben
G:\Program Files\Driver Pro\DriverPro.exe => erfolgreich verschoben
"G:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll" => nicht gefunden.
G:\Users\Jaqueline\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\ads_only_5_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\arcadi2_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\corticas_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\cortica_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\coupish_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\dealply_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\intext_fa_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\monetizationLoader[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\monetizationLoader[2].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\resources_background[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\similar_web_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\50WHA9YC\widdit_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8NFWNK03\pack[2].7z => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\ads_only_5_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\appApiMessage[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\coupish_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\getdeal_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\intext_5_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\intext_adv_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\jollywallet_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\revizer_p_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\similar_web_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\SingAlong_1060-1052_v114[1] => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\superfish_no_coupons_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCXS9211\superfish_no_coupons_m[2].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\corticas_ru_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\cortica_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\coupons_intext_ads_5_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\icm_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\jollywallet_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\luck_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\superfish_no_search_no_coupons_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PORYTW29\superfish_pricora_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\arcadi3_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\coupons_intext_ads_5_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\CrossriderUtils[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\dealply_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\ibario_pops_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\icm_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\intext_5_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\luck_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\pack[1].7z => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\revizer_ws_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\superfish_m[1].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZD12F3MS\superfish_m[2].js => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\1\92\A5268d01 => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\3\16\CFB4Cd01 => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\4\39\9D74Bd01 => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\6\58\18A64d01 => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\8\AA\ED51Bd01 => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Mozilla\Firefox\Profiles\iuim0fod.default\Cache\A\B9\50C7Ed01 => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\BrowserHelper.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Interop.SHDocVw.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\MACTrackBarLib.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\NDde.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Newtonsoft.Json.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\QuickShare.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.Base.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.DefaultBrowser.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ShareManagerLocalPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessEntities.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.PersonalizationSettingsManager.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.PublisherSettingsManager.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Personalization.Settings.UserSettingsManager.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.BrowserHelperUtils.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.GeneralUtilities.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProductsRemovalLibary.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ProductUninstaller.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SetBrowsersSettings.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SetBrowsersSettingsAutoUpdater.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.ShortcutsLibrary.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.XmlSerializers.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.Translations.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.UninstallScreen.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.UrlHistorySupplier.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\ar\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\es\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\fr\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\he\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_20.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_21.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_22.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_23.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_24.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\it\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\pt\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\ru\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Application\tr\Smartbar.Resources.LanguageSettings.resources.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.DMP.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.NotepadPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.ScreenCapturePlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.UninstallProductsPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WordPlugin.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\2877.tmp => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\BackupSetup.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\che50FF.tmp => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\MixiDJToolbar.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\SingAlong.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\SmartbarExeInstaller.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\sngalng.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\BabMaint.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\BUSolution.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\CrxInstaller.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\delta1.crx => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\IEHelper.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\MyBabylonTB.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\0E9E2FBA-BAB0-7891-AB7A-7036ED40CB4F\Setup.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BabMaint.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BExternal.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\BUSolution.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\CrxInstaller.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\IEHelper.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\mixiDj.crx => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\MyBabylonTB.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\3D780657-BAB0-7891-B4AE-EEEEDF4146C8\Latest\Setup.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\bus2A1\CrxUpdater_d.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\bus2BE0\BUSolution.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\bus425D\fntupdtr.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\bus58EA\BUSolution.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\busA6B\CrxUpdater_d.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\DomaIQ.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\DomaIQ10.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\exes.zip => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\installer.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Addlyrics.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Delta Babylon.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\Format-Factory.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\0lYgaw04EsPjIfy\software\OptimizerPro.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\DomaIQ.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\DomaIQ10.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\exes.zip => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\wqk2oQ5UwIgqAQI\installer.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\DomaIQ.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\DomaIQ10.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\exes.zip => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\installer.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Driverpro.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Format-Factory => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\Mixi Dj Yahoo.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\DM\Y7Zj39RkHOwktM6\software\QuickShare1.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\BExternal.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\IEHelper.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Setup.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\BExternal.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\IEHelper.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\MyBabylonTB.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\F8C7B83F-BAB0-7891-A2AC-3B07A4531600\Latest\Setup.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\ibtmpc810632\component_612.decrpt => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\ibtmpc810632\component_625 => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\nseC301.tmp\mt.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\nsz2378.tmp\mt.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\LinkuryInstaller.msi => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\26bd7386-e546-41bb-ba63-886152ebd2d3\LinkuryInstaller.msi => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\Smartbar\934faaad-8ac9-423b-8166-8e363f9345cd\LinkuryInstaller.msi => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\upd2348\BabMaint.x => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Local\Temp\upd2348\BUSolution.x => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\BabSolution\CR\delta1.crx => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\BabSolution\Shared\BabMaint.exe => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\BabSolution\Shared\BUSolution.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_20.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_21.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_22.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_23.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\staged\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_24.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_20.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_21.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_22.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_23.dll => erfolgreich verschoben
G:\Users\Jaqueline\AppData\Roaming\Mozilla\Firefox\Profiles\iuim0fod.default\extensions\{d0d57ce3-9ce0-4175-aa1d-2823b2807a50}\components\SmartbarFireFoxRemotePlugin_24.dll => erfolgreich verschoben
G:\Users\Jaqueline\Downloads\video_downloader.exe => erfolgreich verschoben
G:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll => erfolgreich verschoben
G:\Windows\Installer\5916a.msi => erfolgreich verschoben
G:\Windows\Temp\Optimizer_Pro.exe => erfolgreich verschoben
H:\Downloads\Dark_Theme - CHIP-Installer (1).exe => erfolgreich verschoben
H:\Downloads\Dark_Theme - CHIP-Installer (2).exe => erfolgreich verschoben
H:\Downloads\Dark_Theme - CHIP-Installer.exe => erfolgreich verschoben
H:\Downloads\MediaPortal - CHIP-Installer.exe => erfolgreich verschoben
H:\Downloads\micro SIM Schablone PDF Vorlage - CHIP-Installer.exe => erfolgreich verschoben
H:\Downloads\Nano SIM Schablone PDF Vorlage - CHIP-Installer.exe => erfolgreich verschoben
H:\Downloads\VLC media player 64 Bit - CHIP-Installer.exe => erfolgreich verschoben
H:\Downloads\Adobe Creative Cloud Collection 2015\Adobe Creative Cloud Collection 2015\Adobe Creative Cloud Collection 2015\Aktivierung für alle Versionen\XFORCE Cloud 2015\Adobe Block.cmd => erfolgreich verschoben
H:\Downloads\DAEMON Tools Pro Advanced v6.1.0.0483\DAEMON Tools Pro Advanced v6.1.0.0483.rar => erfolgreich verschoben
H:\Downloads\DAEMON Tools Pro Advanced v6.1.0.0483\DAEMON Tools Pro Advanced v6.1.0.0483\Activator_DTP\activator.exe => erfolgreich verschoben
H:\FileHistory\totti\HOME-PC\Data\$OF\979\981 (2015_10_14 22_35_17 UTC).cmd => erfolgreich verschoben
H:\Neuer Ordner (2)\Program Files (x86)\FunWebProducts => erfolgreich verschoben
H:\Neuer Ordner (2)\Program Files (x86)\Conduit => erfolgreich verschoben
H:\Neuer Ordner (2)\Neuer Ordner\Transcend\Alcohol 120% 2.0.2 Build 5830 Retail\Alcohol120_retail_2.0.2.5830.exe => erfolgreich verschoben
"C:\Users\totti\Downloads\K-Lite_Codec_Pack_1265_Mega_CB-DL-Manager.exe" => nicht gefunden.
Fehler: (0) Erstellen eines Wiederherstellungspunktes gescheitert.

=========== EmptyTemp: ==========

BITS transfer queue => 32768 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9784726 B
Java, Flash, Steam htmlcache => 1268 B
Windows/system/drivers => 15913094 B
Edge => 136736752 B
Chrome => 488054458 B
Firefox => 25967206 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => -650 B
Thorsten => 453483435 B
ttjh1 => 29144378 B
totti => 228443422 B

RecycleBin => 0 B
EmptyTemp: => 1.3 GB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 20:41:54 ====
         

Alt 11.12.2016, 17:32   #17
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? - Standard

Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?



Gibt es jetzt noch Probleme mit dem PC? Wenn ja, welche?

Schritt 1



Bitte starte FRST erneut, markiere auch die checkbox und drücke auf Untersuchen.
Bitte poste mir den Inhalt der beiden Logs die erstellt werden.
__________________

__________________

Alt 11.12.2016, 18:02   #18
totti6169
 
Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? - Standard

Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?



Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-12-2016
durchgeführt von totti (11-12-2016 17:54:15)
Gestartet von C:\Users\totti\Downloads
Windows 10 Pro Version 1607 (X64) (2016-11-26 22:54:06)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2586767532-3616519997-416612805-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2586767532-3616519997-416612805-503 - Limited - Disabled)
Gast (S-1-5-21-2586767532-3616519997-416612805-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2586767532-3616519997-416612805-1005 - Limited - Enabled)
jenny (S-1-5-21-2586767532-3616519997-416612805-1002 - Limited - Disabled)
Thorsten (S-1-5-21-2586767532-3616519997-416612805-1001 - Limited - Enabled) => C:\Users\Thorsten
totti (S-1-5-21-2586767532-3616519997-416612805-1006 - Administrator - Enabled) => C:\Users\totti
ttjh1 (S-1-5-21-2586767532-3616519997-416612805-1003 - Administrator - Enabled) => C:\Users\ttjh1

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
AI Suite 3 (HKLM-x32\...\{CD36E28B-6023-469A-91E7-049A2874EC13}) (Version: 1.01.49 - ASUSTeK Computer Inc.)
Apple Application Support (32-Bit) (HKLM-x32\...\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Asmedia USB Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.26.1 - Asmedia Technology)
ASUS Boot Setting (HKLM-x32\...\{7AAE9187-C24F-4073-A951-36C370E7A3A5}) (Version: 1.00.22 - ASUSTeK Computer Inc.)
ASUS ROG Connect Plus (HKLM-x32\...\{ECF51D37-52ED-4871-BF8B-FEA34B8B4120}) (Version: 1.00.30 - ASUSTeK Computer Inc.)
Asus Sonic Suite Plugins (HKLM-x32\...\{c5017606-8bde-4f85-94f4-ba61dcf59860}) (Version: 2.2.2801 - ASUSTeKcomputer.Inc)
ASUS(R) Intel(R) Extreme Tuning Utility (HKLM-x32\...\{969659ef-5e6c-4c40-8aec-6b1bd3819fab}) (Version: 6.1.2.208 - Intel Corporation)
ASUS(R) Intel(R) Extreme Tuning Utility (x32 Version: 6.1.2.208 - Intel Corporation) Hidden
BioExcess (HKLM-x32\...\InstallShield_{596DEDA5-FE48-4078-96E0-E449DF5D08B2}) (Version: 7.1.5.27 - Egis Technology Inc.)
BioExcess (Version: 7.1.5.27 - Egis Technology Inc.) Hidden
BioExcess (x32 Version: 7.1.5.27 - Egis Technology Inc.) Hidden
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CheckDevicesConfigurator (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden
EaseUS Todo PCTrans 9.0 (HKLM-x32\...\EaseUS Todo PCTrans_is1) (Version:  - EaseUS)
EgisTec Fingerprint Driver (HKLM-x32\...\InstallShield_{E8C889B8-0A8B-46BA-B433-F7D6968A6543}) (Version: 3.5.1.0 - Egis Technology Inc.)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Fingerprint Driver (x32 Version: 3.5.1.0 - Egis Technology Inc.) Hidden
Front Base Driver (HKLM-x32\...\{3A02F836-5D7E-4DDE-ADAE-28DFA9B278DC}) (Version: 1.01.17 - ASUSTeK Computer Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.99 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HDClone 6 Free Edition (HKLM\...\Miray.HDClone.fe.6.0.7.1031-{9111A38F-76E7-40B5-8E0F-EE2C0E43230D}) (Version: 6 - Miray Software AG)
Intel(R) Network Connections 20.2.4001.0 (HKLM\...\PROSetDX) (Version: 20.2.4001.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
iTunes (HKLM\...\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
K-Lite Mega Codec Pack 12.7.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 12.7.0 - KLCP)
LauncherSetup (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden
Logitech Options (HKLM\...\LogiOptions) (Version:  - Logitech)
Logitech Solar App 1.10 (HKLM\...\SolarApp) (Version: 1.10.3 - Logitech)
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-2586767532-3616519997-416612805-1006\...\OneDriveSetup.exe) (Version: 17.3.6720.1207 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40649 (HKLM-x32\...\{5d0723d3-cff7-4e07-8d0b-ada737deb5e6}) (Version: 12.0.40649.5 - Microsoft Corporation)
Mozilla Firefox 50.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.0.2 (x86 de)) (Version: 50.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.0.2.6177 - Mozilla)
NahimicSettingsConfigurator (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden
ProductDaemonSetup (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7904 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.7 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.7 - VS Revo Group, Ltd.)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.9.7 - Samsung Electronics)
SonicRadarSetup (Version: 1.0.0.0 - ASUSTeKcomputer.Inc) Hidden
SonicStudioSetup (Version: 2.2.2801 - ASUSTeKcomputer.Inc) Hidden
SVLoadSense (HKLM-x32\...\{C4226734-F925-448C-8F15-0D5419F003DF}) (Version: 1.0.12 - SAVITECH)
SyncFileSetup (x86) (x32 Version: 1.3.5949.26210 - Western Digital Technologies, Inc) Hidden
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.71503 - TeamViewer)
TERRATEC Cinergy Hybrid Stick (64 Bit) (HKLM-x32\...\{53DE5511-BBC4-441D-AD55-6B8E23A3AA05}) (Version: 1.00.08.06 - TERRATEC Electronic GmbH)
Terratec Cinergy T2 micro x64 Drivers (HKLM-x32\...\{170CB5DA-C9CB-4220-9044-54AD389EA9D5}) (Version: 10.00.0000 - Terratec)
Terratec Cinergy TC2 x64 Drivers (HKLM-x32\...\{D507B4B1-4DA4-41D1-9F2F-7B2684C8778E}) (Version: 10.00.0000 - Terratec)
WD Access (HKLM-x32\...\{046643f7-6206-46bb-8968-92c37fee39e0}) (Version: 1.4.5949.29996 - Western Digital Technologies, Inc.)
WD Access (x32 Version: 1.4.5949.29996 - Western Digital Technologies, Inc) Hidden
WD My Cloud (HKLM\...\{4B86F896-11DC-4711-BB60-81104832FA44}) (Version: 1.0.7.17 - Western Digital Technologies, Inc.)
WD Quick View (HKLM-x32\...\{BE1B25F9-5A51-4DB8-81FA-CE0CABC14D07}) (Version: 2.4.10.17 - Western Digital Technologies, Inc.)
WD Sync (HKLM-x32\...\{0d591303-bbc5-4645-a03b-1c3f75f1a762}) (Version: 1.3.5949.26210 - Western Digital Technologies, Inc.)
WiFi Station N (HKLM-x32\...\{155314D4-C46C-434A-9297-643E260232C0}) (Version: 3.7.0.0 - Hercules)
Windows-Treiberpaket - TerraTec  (TTHID) HIDClass  (05/21/2009 1.00.01.05) (HKLM\...\7051B1F240802F891754E1EFC6431B0D98C2DA65) (Version: 05/21/2009 1.00.01.05 - TerraTec )
Windows-Treiberpaket - TerraTec  (UDXTTM6010) Media  (05/14/2009 1.00.08.06) (HKLM\...\FCC6C304DBC4CB7CFCC0BEF0BCE1BEC491CD289D) (Version: 05/14/2009 1.00.08.06 - TerraTec )
Windows-Treiberpaket - Terratec (IT9300BDA) Media  (05/11/2015 15.5.11.1) (HKLM\...\0A8AEA4C8078A11CEC9350331C879FDA0D9C649B) (Version: 05/11/2015 15.5.11.1 - Terratec)
Windows-Treiberpaket - Terratec (IT9300BDA) Media  (10/27/2016 10.0.195.447) (HKLM\...\77862757AE61D1BE0CE158F285743CE10665C5DB) (Version: 10/27/2016 10.0.195.447 - Terratec)
Windows-Treiberpaket - Terratec (WUDFRd) Ports  (02/16/2015 6.1.7600.16385) (HKLM\...\5C5EBF24671D248D909BD1C9278836EF94379B62) (Version: 02/16/2015 6.1.7600.16385 - Terratec)
Windows-Treiberpaket - Terratec (WUDFRd) Ports  (10/27/2016 10.0.195.447) (HKLM\...\6CED9945C18ECE0D93909DDB5FFC6F05C125EE60) (Version: 10/27/2016 10.0.195.447 - Terratec)
XTUPackage (HKLM-x32\...\{84D11A20-6E7F-4FBB-A2FB-117FCF871040}) (Version: 1.0.0 - ASUSTeK COMPUTER INC.)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {188B9885-CAC6-4C29-9051-F3FE2C0F4DF4} - System32\Tasks\SS2Svc32Run => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2Svc32.exe [2016-08-12] ()
Task: {188EF076-1076-41D7-875F-1DD8F69606C6} - System32\Tasks\SS2UILauncherRun => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe [2016-08-12] ()
Task: {2F5ACAD3-FDC4-49A4-91BF-D582F5424D5B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-27] (Google Inc.)
Task: {43B6F1BF-91BF-4BDD-BD97-EA8C0BE9C13F} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr.exe [2013-07-24] (ASUSTeK Computer Inc.)
Task: {5F4CF43C-7BEE-49B2-B0A0-8D7E6AC8A788} - System32\Tasks\ASUS\GpuFanHelper => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe [2016-03-07] (TODO: <Company name>)
Task: {81E98030-F60F-430C-AF12-C1A02FE6DF61} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2016-08-11] (ASUSTeK Computer Inc.)
Task: {8C538313-6404-41FF-867D-214170AAA8A1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-27] (Google Inc.)
Task: {8D28B0BE-DF11-4E05-BD63-4D7B59468AB9} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [2015-11-20] (Intel Corporation)
Task: {8DA5F8A2-2102-49F6-B97A-FF4B65DE6B9E} - System32\Tasks\SS2Svc64Run => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2Svc64.exe [2016-08-12] ()
Task: {91F12F09-9090-49DD-BE18-5DC343B5C829} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2016-12-01] ()
Task: {9B4D2772-9992-4DE1-B9B9-6B5BCA519D46} - System32\Tasks\ASUS\RC TweakIt Server Execute => C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsBCLK.exe [2015-06-25] ()
Task: {A7857351-7FC8-4119-8720-ED706A5775D6} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2016-05-13] (Samsung Electronics.)
Task: {B230353A-C381-4FA6-9DF9-0B1C5FBB69CD} - System32\Tasks\ASUS\Push Notice Server Execute => C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe [2014-05-28] (ASUSTeK Computer Inc.)
Task: {B47F2739-667E-4812-8FF0-9BAC6C0FE401} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [2016-07-28] ()
Task: {F0820D76-C981-4B46-AD51-BFF9253FB633} - System32\Tasks\ASUS\WonderBox => C:\Program Files (x86)\ASUS\Front Base Driver\WBoxTT.exe [2015-08-05] ()

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps\Videostream for Google Chromecast™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=cnciopoikihiagdjbjpnocolokfelagl

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2012-06-21 18:12 - 2012-06-21 18:12 - 01407568 _____ () C:\Program Files (x86)\EgisTec BioExcess\x64\LIBEAY32.dll
2016-11-27 04:15 - 2016-11-27 04:15 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2016-10-05 18:17 - 2016-10-05 18:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-11-27 04:16 - 2016-11-27 04:15 - 01360016 _____ () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 ____N () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-09 19:34 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-08-12 12:17 - 2016-08-12 12:17 - 00287760 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll
2016-08-12 12:17 - 2016-08-12 12:17 - 00209936 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll
2016-11-28 23:40 - 2015-06-25 10:42 - 01986872 _____ () C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsBCLK.exe
2016-11-27 04:16 - 2016-07-28 23:33 - 01269208 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
2016-12-09 19:34 - 2016-11-11 11:10 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-12-09 19:21 - 2016-12-09 19:21 - 01678560 _____ () C:\Users\totti\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\ClientTelemetry.dll
2016-09-21 22:27 - 2016-09-07 05:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-12-09 19:34 - 2016-11-11 10:23 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-12-09 19:34 - 2016-11-11 10:23 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll
2016-11-26 23:49 - 2015-11-05 16:08 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-11-27 14:20 - 2016-11-27 14:20 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2016-11-27 14:20 - 2016-11-27 14:20 - 00178688 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2016-11-27 14:20 - 2016-11-27 14:20 - 41609728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2016-11-28 23:39 - 2015-08-05 09:25 - 01384400 _____ () C:\Program Files (x86)\ASUS\Front Base Driver\WBoxTT.exe
2016-11-27 04:16 - 2015-05-14 09:18 - 01075712 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe
2016-11-27 04:16 - 2014-08-28 10:37 - 00033424 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe
2016-11-27 04:16 - 2016-04-21 13:35 - 01529816 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe
2016-11-27 04:50 - 2016-11-27 04:42 - 00105312 _____ () C:\WINDOWS\SYSTEM32\audioLibVc.dll
2016-08-12 12:15 - 2016-08-12 12:15 - 00557072 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe
2016-08-12 12:15 - 2016-08-12 12:15 - 02741760 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2svc32.exe
2016-08-12 12:18 - 2016-08-12 12:18 - 00486400 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2svc64.exe
2016-11-10 00:01 - 2016-11-02 11:21 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-11-10 00:01 - 2016-11-02 11:15 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-11-10 00:01 - 2016-11-02 11:14 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-11-10 00:01 - 2016-11-02 11:15 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-11-10 00:01 - 2016-11-02 11:16 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-10 00:01 - 2016-11-02 11:17 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-11-27 01:08 - 2016-11-08 22:03 - 02367080 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libglesv2.dll
2016-11-27 01:08 - 2016-11-08 22:03 - 00107112 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libegl.dll
2016-11-27 04:15 - 2016-12-11 07:29 - 00040232 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2016-11-27 04:15 - 2016-11-27 04:15 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2016-11-27 04:16 - 2015-09-17 10:58 - 00091648 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Log4cxxWrapper.dll
2016-11-27 04:16 - 2015-09-17 10:58 - 00147456 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AssistFunc.dll
2016-11-27 04:16 - 2015-02-09 17:53 - 00872960 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AI Charger+\AIChargerPlus.dll
2016-11-27 04:16 - 2016-08-15 10:36 - 04712752 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\dip4.dll
2016-11-27 04:16 - 2016-03-07 21:42 - 00091648 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\Log4cxxWrapper.dll
2016-11-27 04:16 - 2015-11-05 11:13 - 01464320 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Mobo Connect\MoboConnect.dll
2016-11-27 04:16 - 2015-09-17 10:58 - 00838456 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Version\Version.dll
2016-11-28 23:49 - 2016-08-02 15:05 - 00061440 _____ () C:\Program Files (x86)\ASUS\VGA COM\1.00.26\Exeio.dll
2016-11-28 23:49 - 2016-08-02 14:51 - 01752576 _____ () C:\Program Files (x86)\ASUS\VGA COM\1.00.26\Vender.dll
2016-11-28 23:48 - 2016-08-05 15:25 - 00669656 _____ () C:\Program Files (x86)\ASUS\AAHM\1.00.25\aaHMLib.dll
2016-11-27 04:17 - 2012-01-19 09:39 - 00028672 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\PEInfo.dll
2016-08-12 12:14 - 2016-08-12 12:14 - 00256016 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2OSD.dll
2016-08-12 12:14 - 2016-08-12 12:14 - 00178704 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2DevProps.dll
2016-11-27 04:16 - 2015-09-17 10:58 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite III\ImageHelper.dll
2016-11-27 04:16 - 2015-09-17 10:58 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite III\pngio.dll
2016-11-27 04:17 - 2010-02-25 14:01 - 00139264 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\Aszip.dll
2016-11-27 04:17 - 2015-10-14 14:47 - 02613248 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\EzULIB_UFB.dll
2016-11-28 23:40 - 2015-06-05 09:37 - 00179712 _____ () C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsusService.dll
2016-11-27 04:16 - 2016-04-20 23:52 - 00260056 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4cTDPAction.dll
2016-11-27 04:16 - 2016-05-04 21:46 - 00786416 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll
2016-11-27 04:16 - 2016-04-20 23:52 - 00878040 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll
2016-11-27 04:16 - 2016-04-20 23:52 - 00828376 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4FanAction.dll
2016-11-27 04:16 - 2016-04-20 23:52 - 00838616 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll
2016-11-27 04:16 - 2013-11-20 10:10 - 00662016 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\aaHMLib.dll
2016-11-27 04:16 - 2013-07-02 10:40 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\pngio.dll
2016-08-12 12:15 - 2016-08-12 12:15 - 00098816 _____ () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\sradarlauncher.dll
2016-12-09 19:21 - 2016-12-09 19:21 - 01244376 _____ () C:\Users\totti\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\ClientTelemetry.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2016-11-26 23:45 - 2016-11-26 23:44 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2586767532-3616519997-416612805-1006\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => LPort=139
FirewallRules: [{54E4918F-A16A-4FA9-9F2F-160EDBB8443A}] => C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE
FirewallRules: [{19192873-968D-4E2F-98DB-E134957E191E}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9C5C5112-6DE2-41AD-A69F-BA05190A96A5}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8483DF55-D597-4E26-BD9B-C06CCC10B227}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{AD27A2B5-5842-4E00-8C06-FF9F7053163E}C:\users\thorsten\desktop\jperf-2.0.2\jperf-2.0.2\bin\iperf.exe] => C:\users\thorsten\desktop\jperf-2.0.2\jperf-2.0.2\bin\iperf.exe
FirewallRules: [UDP Query User{DFB24A96-1288-41E3-B341-14F1E1C3CBE9}C:\users\thorsten\desktop\jperf-2.0.2\jperf-2.0.2\bin\iperf.exe] => C:\users\thorsten\desktop\jperf-2.0.2\jperf-2.0.2\bin\iperf.exe
FirewallRules: [SNMP-In-UDP] => %SystemRoot%\system32\snmp.exe
FirewallRules: [SNMP-Out-UDP] => %SystemRoot%\system32\snmp.exe
FirewallRules: [SNMP-In-UDP-NoScope] => %SystemRoot%\system32\snmp.exe
FirewallRules: [SNMP-Out-UDP-NoScope] => %SystemRoot%\system32\snmp.exe
FirewallRules: [TCP Query User{7B5C2E71-F3E4-4159-8248-FCB8735D3F12}C:\program files (x86)\western digital\wd app manager\wdappmanager.exe] => C:\program files (x86)\western digital\wd app manager\wdappmanager.exe
FirewallRules: [UDP Query User{5930F899-70D2-401D-8760-CDFD22F72C6B}C:\program files (x86)\western digital\wd app manager\wdappmanager.exe] => C:\program files (x86)\western digital\wd app manager\wdappmanager.exe
FirewallRules: [{B5AF83E3-86A9-4279-9DAB-34A9F65B5BFB}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6FE7BDB7-317E-40D9-BA68-E88F174AC1AB}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{20B49414-1915-4941-A2B1-C73B8E532466}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{7EA22D8B-07BB-4F54-8384-E1DC8DCB9A35}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E490789F-B35E-48B2-A406-23F972D5C058}] => C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{6D2571BC-0D6E-45F5-992C-9499BD739CC0}] => C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1E65D46E-9309-4FBF-8FC6-6C6C26FBEDE7}] => C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{27370EAC-C5BD-4802-9745-008EDAADBC30}] => C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{E159694B-A5B6-4723-997D-8131C58D391D}] => C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{92164D59-5689-4281-BB74-7EAA0DE82283}C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe] => C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe
FirewallRules: [UDP Query User{5DBC668B-0188-40A0-9693-12926839932A}C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe] => C:\program files (x86)\easeus\easeus todo pctrans\bin\pctrans.exe
FirewallRules: [{42C30DF6-3DFE-41D1-BA6C-C58524743106}] => C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
FirewallRules: [{A116FCB6-EB63-4F45-857A-1094133606DC}] => C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe

==================== Wiederherstellungspunkte =========================

11-12-2016 05:08:27 Revo Uninstaller Pro's restore point - WiFi Station N

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Unbekanntes USB-Gerät (Fehler beim Anfordern einer Gerätebeschreibung.)
Description: Unbekanntes USB-Gerät (Fehler beim Anfordern einer Gerätebeschreibung.)
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard-USB-Hostcontroller)
Service: 
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. 

Name: Unbekanntes USB-Gerät (Fehler beim Anfordern einer Gerätebeschreibung.)
Description: Unbekanntes USB-Gerät (Fehler beim Anfordern einer Gerätebeschreibung.)
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard-USB-Hostcontroller)
Service: 
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. 


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (12/11/2016 01:11:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 62437

Error: (12/11/2016 01:11:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 62437

Error: (12/11/2016 01:11:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (12/11/2016 01:11:22 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 46797

Error: (12/11/2016 01:11:22 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 46797

Error: (12/11/2016 01:11:22 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (12/11/2016 01:11:07 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 31172

Error: (12/11/2016 01:11:07 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 31172

Error: (12/11/2016 01:11:07 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (12/11/2016 01:10:51 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15578


Systemfehler:
=============
Error: (12/11/2016 04:24:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Logitech Solar Keyboard Service" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/11/2016 04:24:21 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Logitech Solar Keyboard Service" wurde mit dem folgenden dienstspezifischen Fehler beendet: 
Der Vorgang wurde erfolgreich beendet.

Error: (12/11/2016 03:38:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Logitech Solar Keyboard Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (12/11/2016 03:38:36 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Logitech Solar Keyboard Service" wurde mit dem folgenden dienstspezifischen Fehler beendet: 
Der Vorgang wurde erfolgreich beendet.

Error: (12/11/2016 03:38:19 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 und der APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (12/11/2016 03:38:19 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 und der APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (12/11/2016 03:38:19 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 und der APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.

Error: (12/11/2016 01:09:46 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht.

Error: (12/11/2016 01:09:16 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht.

Error: (12/11/2016 01:08:46 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht.


CodeIntegrity:
===================================
  Date: 2016-12-11 15:42:07.555
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements.

  Date: 2016-12-11 15:42:07.550
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll that did not meet the Store signing level requirements.

  Date: 2016-12-11 15:41:30.185
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements.

  Date: 2016-12-11 15:41:30.181
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll that did not meet the Store signing level requirements.

  Date: 2016-12-11 15:41:06.690
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements.

  Date: 2016-12-11 15:41:06.683
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll that did not meet the Store signing level requirements.

  Date: 2016-12-11 15:41:06.571
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements.

  Date: 2016-12-11 15:41:06.563
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2DevProps.dll that did not meet the Store signing level requirements.

  Date: 2016-12-11 07:29:52.923
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-12-11 00:25:36.272
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2OSD.dll that did not meet the Store signing level requirements.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
Prozentuale Nutzung des RAM: 13%
Installierter physikalischer RAM: 32690.58 MB
Verfügbarer physikalischer RAM: 28140.23 MB
Summe virtueller Speicher: 37554.58 MB
Verfügbarer virtueller Speicher: 32568.91 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:464.67 GB) (Free:311.41 GB) NTFS
Drive d: (Samsung850) (Fixed) (Total:232.35 GB) (Free:64.13 GB) NTFS
Drive e: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive f: (WD Black ) (Fixed) (Total:931.41 GB) (Free:652.7 GB) NTFS
Drive g: () (Fixed) (Total:465.66 GB) (Free:294.32 GB) NTFS
Drive h: (WD Elements black) (Fixed) (Total:1862.98 GB) (Free:1318.57 GB) NTFS
Drive i: () (CDROM) (Total:0.06 GB) (Free:0 GB) CDFS
Drive j: () (Fixed) (Total:55.8 GB) (Free:7.84 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 5DAD4F98)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: FD91664C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 55.9 GB) (Disk ID: E1CFC143)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=55.8 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (Size: 931.5 GB) (Disk ID: C032F668)
Partition 1: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: 044B42CF)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 5 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: FB639362)
Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================
         
__________________

Alt 11.12.2016, 18:07   #19
totti6169
 
Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? - Standard

Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?



Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016
durchgeführt von totti (Administrator) auf HOME-PC (11-12-2016 17:53:45)
Gestartet von C:\Users\totti\Downloads
Geladene Profile: totti (Verfügbare Profile: Thorsten & ttjh1 & totti)
Platform: Windows 10 Pro Version 1607 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Edge)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Egis Technology Inc. ) C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.25\aaHMSvc.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Microsoft Corporation) C:\Windows\System32\snmp.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe
() C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsBclk.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe
() C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.261.0_x64__kzf8qxf38zg5c\SkypeHost.exe
() C:\Program Files (x86)\ASUS\Front Base Driver\WBoxTT.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr64.exe
() C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe
() C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
() C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe
(Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
(Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SAVITECH) C:\Program Files (x86)\SAVITECH\SVLoadSense\SVLoadSense.exe
() C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2Svc32.exe
() C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2Svc64.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisTSR.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Sync\App\WDSyncService.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\syswow64\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7705.42037.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7705.42037.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [1735288 2016-09-30] (Logitech, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843784 2016-11-27] (Realtek Semiconductor)
HKLM\...\Run: [SVLoadSense] => c:\Program Files (x86)\SAVITECH\SVLoadSense\SVLoadSense.exe [1762000 2015-09-21] (SAVITECH)
HKLM\...\Run: [SS2UILauncher] => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe [557072 2016-08-12] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-02-12] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] => C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2013-01-28] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [AO Link Server] => C:\Program Files (x86)\ASUS\AI Suite III\Mobo Connect\ALRun.exe -start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21384 2016-04-15] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [424528 2012-08-16] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [198736 2012-08-16] (Egis Technology Inc.)
HKLM-x32\...\Run: [VitaKeyTSR] => C:\Program Files (x86)\EgisTec BioExcess\EgisTSR.exe [384080 2012-12-07] (Egis Technology Inc. )
HKU\S-1-5-21-2586767532-3616519997-416612805-1006\...\Run: [GoogleChromeAutoLaunch_53F0CD5A7C131BABB0ECFA6A491868AF] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1082472 2016-11-08] (Google Inc.)
Lsa: [Notification Packages] scecli C:\Program Files (x86)\EgisTec BioExcess\x64\EgisPwdFilter.dll C:\Program Files (x86)\EgisTec BioExcess\x64\EgisDSPwdFilter.dll

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{278623a9-5409-4fd0-84f9-306d087989c8}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{33feedbb-de7b-4bc4-8b69-96b9e6bac0b6}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{6abf8ccf-8799-4d9f-85cf-650277434338}: [DhcpNameServer] 192.168.178.1

Internet Explorer:
==================
BHO: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files (x86)\EgisTec BioExcess\x64\EgisPBIE.dll [2012-12-07] (Egis Technology Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-27] (Oracle Corporation)
BHO-x32: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dll [2012-12-07] (Egis Technology Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-27] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: t1674hax.default
FF ProfilePath: C:\Users\totti\AppData\Roaming\Mozilla\Firefox\Profiles\t1674hax.default [2016-12-10]
FF HKLM-x32\...\Firefox\Extensions: [{41ecbc0b-34d5-4cd4-935f-253a30e2cb7e}] - C:\Program Files (x86)\EgisTec BioExcess\FFExt
FF Extension: ( Online Accounts Extension ) - C:\Program Files (x86)\EgisTec BioExcess\FFExt [2016-12-06] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files (x86)\EgisTec BioExcess\FFExt20
FF Extension: ( Online Accounts Extension ) - C:\Program Files (x86)\EgisTec BioExcess\FFExt20 [2016-12-06] [ist nicht signiert]
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-27] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-27] (Google Inc.)

Chrome: 
=======
CHR HomePage: Default -> hxxps://www.google.de/
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxps://www.google.de/"
CHR Profile: C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default [2016-12-11]
CHR Extension: (Google Präsentationen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-04]
CHR Extension: (Karte des Himmels) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\acnecepeneiomaebkkagcfbbakcfljdc [2016-12-11]
CHR Extension: (HD for YouTube™) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\akjbfncbadcmnkopckegnmjgihagponf [2016-12-11]
CHR Extension: (Google Docs) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-04]
CHR Extension: (Google Drive) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-04]
CHR Extension: (YouTube) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-04]
CHR Extension: () - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-12-11]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2016-12-11]
CHR Extension: (Webcam) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfpjcegkjhdnnempidlgmeoaiilpidep [2016-12-11]
CHR Extension: () - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dliochdbjfkdbacpmhlcpmleaejidimm [2016-12-11]
CHR Extension: (My JDownloader) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbcohnmimjicjdomonkcbcpbpnhggkip [2016-12-11]
CHR Extension: (Google Tabellen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-04]
CHR Extension: (DealExtreme Official) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gadgkbofaenpeeeffgokgjpnbjbflopl [2016-12-11]
CHR Extension: (Google Docs Offline) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-04]
CHR Extension: (Cr!Box) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjodchcocbnbhfkjeapbdoflbiibnapp [2016-12-11]
CHR Extension: (Core) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkhcgfdghbiidgeccbldhfceleibkkpe [2016-12-11]
CHR Extension: (Google) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihglnnefiimonkjgebeipifpkmblecpd [2016-12-11]
CHR Extension: (Custom Google™ Background) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\jepibmfmhopgkplegmkjgifmhabbjadg [2016-12-11]
CHR Extension: (PlayTo für Chromecast™) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\jngkenaoceimiimeokpdbmejeonaaami [2016-12-11]
CHR Extension: (Online Accounts Extension ) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ladimmjldcgbeamniagencjbodhnmgen [2016-12-07]
CHR Extension: (EXIF Viewer) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2016-12-11]
CHR Extension: (Downloads) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngbcgifdaopbfflfhbcfeomijfbbcadi [2016-12-11]
CHR Extension: (LocalChromecast Player) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmladpigjlinmngadjgfogblnmddndcp [2016-12-11]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-04]
CHR Extension: (MonsterBall) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\oampnkjpomgmmphfoedhihefpbjhjamo [2016-12-11]
CHR Extension: (Mein Chrome-Design) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2016-12-11]
CHR Extension: (Earth map) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\opmibphegngmljhikklndacjdpkmhocp [2016-12-11]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2016-12-11]
CHR Extension: (Google Mail) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-04]
CHR Extension: (Chrome Media Router) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-04]
CHR HKLM-x32\...\Chrome\Extension: [ladimmjldcgbeamniagencjbodhnmgen] - C:\Program Files (x86)\EgisTec BioExcess\ChromeEx\EgisPBChromeExt.crx [2012-12-07]

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2016-11-27] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.25\aaHMSvc.exe [963544 2016-08-05] (ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2016-11-27] () [Datei ist nicht signiert]
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe [419288 2016-05-27] (ASUSTeK Computer Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
R2 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R2 SNMP; C:\WINDOWS\System32\snmp.exe [53248 2016-11-28] (Microsoft Corporation)
R2 SNMP; C:\WINDOWS\SysWOW64\snmp.exe [47104 2016-11-28] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10216688 2016-11-28] (TeamViewer GmbH)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [302968 2015-02-12] (Western Digital Technologies, Inc.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [18232 2016-08-02] (Intel(R) Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.)
R3 AndroidAFD; C:\Windows\SysWow64\drivers\AndroidAFDx64.sys [22192 2015-10-19] (ASUSTek Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2016-11-27] ()
S0 asstahci64; C:\WINDOWS\System32\drivers\asstahci64.sys [88936 2015-06-17] (Asmedia Technology)
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2016-11-27] ()
R3 ASUSfilter; C:\WINDOWS\System32\drivers\ASUSfilter.sys [48384 2013-03-28] (MCCI Corporation)
R3 ASUSfilter; C:\Windows\SysWOW64\drivers\ASUSfilter.sys [46152 2016-11-27] (MCCI Corporation)
S3 ASUSstpt; C:\WINDOWS\System32\drivers\ASUSstpt.sys [27392 2013-03-28] (MCCI Corporation)
S3 ASUSumsc; C:\WINDOWS\System32\drivers\ASUSumsc.sys [151808 2013-03-28] (MCCI Corporation)
S3 ASUSxpsp; C:\WINDOWS\System32\drivers\ASUSxpsp.sys [28416 2013-03-28] (MCCI Corporation)
S3 DSI_SiUSBXp_3_1; C:\WINDOWS\system32\drivers\DSI_SiUSBXp_3_1.sys [16384 2007-09-06] (Silicon Laboratories)
S3 dtultrascsibus; C:\WINDOWS\System32\drivers\dtultrascsibus.sys [30264 2016-04-17] (Disc Soft Ltd)
S3 dtultrausbbus; C:\WINDOWS\System32\drivers\dtultrausbbus.sys [47672 2016-04-17] (Disc Soft Ltd)
R3 e1dexpress; C:\WINDOWS\system32\DRIVERS\e1d65x64.sys [530416 2015-06-18] (Intel Corporation)
R0 FPWinIo; C:\WINDOWS\System32\drivers\FPWinIo.sys [23536 2014-10-07] (Egis Technology Inc.)
S2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [29264 2016-06-09] (Intel Corporation)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [24824 2016-07-12] (ASUSTeK Computer Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-12-11] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R1 SvThLSNS; c:\Program Files (x86)\SAVITECH\SVLoadSense\x64\SvThLSNS.sys [15184 2015-09-21] (Windows (R) Win 7 DDK provider)
S3 TTHID; C:\WINDOWS\System32\drivers\Cinergy_Hybrid-Stick_HID.sys [27944 2012-09-27] (DTV-DVB)
S3 UDXTTM6010; C:\WINDOWS\system32\DRIVERS\UDXTTM6010.sys [841384 2012-09-27] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)
S3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-09-21] (Intel Corporation)

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-12-11 15:57 - 2016-12-11 15:57 - 00000000 ____D C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps
2016-12-11 15:42 - 2016-12-11 15:42 - 00000000 ___HD C:\OneDriveTemp
2016-12-11 07:34 - 2016-12-11 07:34 - 00000000 ____D C:\Users\ttjh1\AppData\Local\EgisTec IPS
2016-12-10 21:50 - 2016-12-10 21:52 - 00000000 ____D C:\Users\totti\AppData\Local\ElevatedDiagnostics
2016-12-10 21:41 - 2016-12-10 21:41 - 00001122 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2016-12-10 21:41 - 2016-12-10 21:41 - 00000000 ____D C:\Users\totti\AppData\Local\VS Revo Group
2016-12-10 21:41 - 2016-12-10 21:41 - 00000000 ____D C:\ProgramData\VS Revo Group
2016-12-10 21:41 - 2016-12-10 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2016-12-10 21:41 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\WINDOWS\system32\Drivers\revoflt.sys
2016-12-10 21:40 - 2016-12-10 21:42 - 00000000 ____D C:\Users\totti\Downloads\Revo Uninstaller Pro 3.1.7
2016-12-10 21:37 - 2016-12-10 21:37 - 11481182 _____ C:\Users\totti\Downloads\Revo Uninstaller Pro 3.1.7.rar
2016-12-10 21:24 - 2016-12-10 21:41 - 00000000 ____D C:\Program Files\VS Revo Group
2016-12-10 21:24 - 2016-12-10 21:24 - 07100088 _____ (VS Revo Group ) C:\Users\totti\Downloads\revosetup201.exe
2016-12-10 20:40 - 2016-12-10 20:41 - 00067674 _____ C:\Users\totti\Downloads\Fixlog.txt
2016-12-10 20:40 - 2016-12-10 20:40 - 00000000 ____D C:\Users\totti\Downloads\FRST-OlderVersion
2016-12-10 04:32 - 2016-12-10 04:32 - 00000000 ____D C:\Users\totti\AppData\Roaming\MPC-HC
2016-12-10 04:25 - 2016-12-10 04:25 - 16885631 _____ ( ) C:\Users\totti\Downloads\klcp_update_1270_20161209.exe
2016-12-10 04:25 - 2016-12-10 04:25 - 00001747 _____ C:\Users\totti\Desktop\klcp_codec_log.txt
2016-12-10 04:24 - 2016-12-10 04:24 - 00001544 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-12-10 04:22 - 2016-12-10 04:22 - 00002776 _____ C:\WINDOWS\System32\Tasks\klcp_update
2016-12-10 04:22 - 2016-12-10 04:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2016-12-10 04:22 - 2016-05-08 11:27 - 03613696 _____ (x264vfw project) C:\WINDOWS\SysWOW64\x264vfw.dll
2016-12-10 04:22 - 2016-05-08 11:19 - 03642880 _____ (x264vfw project) C:\WINDOWS\system32\x264vfw64.dll
2016-12-10 04:22 - 2015-12-18 11:00 - 00755200 _____ C:\WINDOWS\system32\xvidcore.dll
2016-12-10 04:22 - 2015-12-18 11:00 - 00674816 _____ C:\WINDOWS\SysWOW64\xvidcore.dll
2016-12-10 04:22 - 2015-12-18 11:00 - 00309248 _____ C:\WINDOWS\system32\xvidvfw.dll
2016-12-10 04:22 - 2015-12-18 11:00 - 00282112 _____ C:\WINDOWS\SysWOW64\xvidvfw.dll
2016-12-10 04:22 - 2015-10-24 18:00 - 00112128 _____ C:\WINDOWS\SysWOW64\ff_vfw.dll
2016-12-10 04:22 - 2012-07-21 12:55 - 00180736 _____ (fccHandler) C:\WINDOWS\system32\ac3acm.acm
2016-12-10 04:22 - 2012-07-21 12:54 - 00122880 _____ (fccHandler) C:\WINDOWS\SysWOW64\ac3acm.acm
2016-12-10 04:22 - 2011-12-07 19:37 - 00148992 _____ ( ) C:\WINDOWS\system32\lagarith.dll
2016-12-10 04:22 - 2011-12-07 19:32 - 00216064 _____ ( ) C:\WINDOWS\SysWOW64\lagarith.dll
2016-12-10 04:21 - 2016-12-10 04:22 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2016-12-10 04:20 - 2016-12-10 04:21 - 43733412 _____ (KLCP ) C:\Users\totti\Downloads\K-Lite_Codec_Pack_1265_Mega.exe
2016-12-10 03:34 - 2016-12-10 03:34 - 02870984 _____ (ESET) C:\Users\totti\Downloads\esetsmartinstaller_deu (1).exe
2016-12-10 03:19 - 2016-12-10 03:25 - 00000000 ____D C:\ProgramData\HitmanPro
2016-12-10 03:19 - 2016-12-10 03:19 - 11581544 _____ (SurfRight B.V.) C:\Users\totti\Downloads\HitmanPro_x64.exe
2016-12-09 19:34 - 2016-11-11 11:22 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-12-09 19:34 - 2016-11-11 11:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-12-09 19:34 - 2016-11-11 11:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
2016-12-09 19:34 - 2016-11-11 11:14 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2016-12-09 19:34 - 2016-11-11 11:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2016-12-09 19:34 - 2016-11-11 11:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-12-09 19:34 - 2016-11-11 11:13 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-12-09 19:34 - 2016-11-11 11:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-12-09 19:34 - 2016-11-11 11:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-12-09 19:34 - 2016-11-11 11:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2016-12-09 19:34 - 2016-11-11 11:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-12-09 19:34 - 2016-11-11 11:10 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-12-09 19:34 - 2016-11-11 11:09 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-12-09 19:34 - 2016-11-11 11:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll
2016-12-09 19:34 - 2016-11-11 11:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2016-12-09 19:34 - 2016-11-11 11:03 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2016-12-09 19:34 - 2016-11-11 11:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-12-09 19:34 - 2016-11-11 11:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-12-09 19:34 - 2016-11-11 11:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-12-09 19:34 - 2016-11-11 11:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-12-09 19:34 - 2016-11-11 11:01 - 02189152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-12-09 19:34 - 2016-11-11 11:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-12-09 19:34 - 2016-11-11 11:01 - 01738048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-12-09 19:34 - 2016-11-11 11:01 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-12-09 19:34 - 2016-11-11 11:01 - 00658264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-12-09 19:34 - 2016-11-11 11:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-12-09 19:34 - 2016-11-11 11:01 - 00401760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-12-09 19:34 - 2016-11-11 11:00 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-12-09 19:34 - 2016-11-11 11:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-12-09 19:34 - 2016-11-11 11:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2016-12-09 19:34 - 2016-11-11 10:59 - 02913136 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-12-09 19:34 - 2016-11-11 10:59 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-12-09 19:34 - 2016-11-11 10:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2016-12-09 19:34 - 2016-11-11 10:57 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-12-09 19:34 - 2016-11-11 10:57 - 08170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-12-09 19:34 - 2016-11-11 10:57 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-12-09 19:34 - 2016-11-11 10:57 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-12-09 19:34 - 2016-11-11 10:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-12-09 19:34 - 2016-11-11 10:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-12-09 19:34 - 2016-11-11 10:56 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-12-09 19:34 - 2016-11-11 10:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-12-09 19:34 - 2016-11-11 10:56 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2016-12-09 19:34 - 2016-11-11 10:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2016-12-09 19:34 - 2016-11-11 10:56 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-12-09 19:34 - 2016-11-11 10:56 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-12-09 19:34 - 2016-11-11 10:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe
2016-12-09 19:34 - 2016-11-11 10:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll
2016-12-09 19:34 - 2016-11-11 10:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll
2016-12-09 19:34 - 2016-11-11 10:55 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-12-09 19:34 - 2016-11-11 10:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-12-09 19:34 - 2016-11-11 10:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-12-09 19:34 - 2016-11-11 10:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-12-09 19:34 - 2016-11-11 10:51 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2016-12-09 19:34 - 2016-11-11 10:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-12-09 19:34 - 2016-11-11 10:31 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-12-09 19:34 - 2016-11-11 10:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-12-09 19:34 - 2016-11-11 10:29 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-12-09 19:34 - 2016-11-11 10:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-12-09 19:34 - 2016-11-11 10:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll
2016-12-09 19:34 - 2016-11-11 10:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-12-09 19:34 - 2016-11-11 10:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-12-09 19:34 - 2016-11-11 10:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
2016-12-09 19:34 - 2016-11-11 10:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-12-09 19:34 - 2016-11-11 10:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2016-12-09 19:34 - 2016-11-11 10:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll
2016-12-09 19:34 - 2016-11-11 10:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys
2016-12-09 19:34 - 2016-11-11 10:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe
2016-12-09 19:34 - 2016-11-11 10:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
2016-12-09 19:34 - 2016-11-11 10:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-12-09 19:34 - 2016-11-11 10:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-12-09 19:34 - 2016-11-11 10:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2016-12-09 19:34 - 2016-11-11 10:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-12-09 19:34 - 2016-11-11 10:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2016-12-09 19:34 - 2016-11-11 10:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2016-12-09 19:34 - 2016-11-11 10:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-12-09 19:34 - 2016-11-11 10:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2016-12-09 19:34 - 2016-11-11 10:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2016-12-09 19:34 - 2016-11-11 10:23 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2016-12-09 19:34 - 2016-11-11 10:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-12-09 19:34 - 2016-11-11 10:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll
2016-12-09 19:34 - 2016-11-11 10:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-12-09 19:34 - 2016-11-11 10:22 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-12-09 19:34 - 2016-11-11 10:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
2016-12-09 19:34 - 2016-11-11 10:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-12-09 19:34 - 2016-11-11 10:21 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-12-09 19:34 - 2016-11-11 10:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-12-09 19:34 - 2016-11-11 10:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2016-12-09 19:34 - 2016-11-11 10:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2016-12-09 19:34 - 2016-11-11 10:21 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-12-09 19:34 - 2016-11-11 10:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-12-09 19:34 - 2016-11-11 10:20 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2016-12-09 19:34 - 2016-11-11 10:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2016-12-09 19:34 - 2016-11-11 10:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-12-09 19:34 - 2016-11-11 10:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2016-12-09 19:34 - 2016-11-11 10:19 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-12-09 19:34 - 2016-11-11 10:18 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-12-09 19:34 - 2016-11-11 10:18 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-12-09 19:34 - 2016-11-11 10:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2016-12-09 19:34 - 2016-11-11 10:18 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-12-09 19:34 - 2016-11-11 10:18 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2016-12-09 19:34 - 2016-11-11 10:18 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-12-09 19:34 - 2016-11-11 10:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2016-12-09 19:34 - 2016-11-11 10:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2016-12-09 19:34 - 2016-11-11 10:17 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-12-09 19:34 - 2016-11-11 10:17 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-12-09 19:34 - 2016-11-11 10:17 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-12-09 19:34 - 2016-11-11 10:17 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-12-09 19:34 - 2016-11-11 10:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2016-12-09 19:34 - 2016-11-11 10:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2016-12-09 19:34 - 2016-11-11 10:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2016-12-09 19:34 - 2016-11-11 10:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2016-12-09 19:34 - 2016-11-11 10:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-12-09 19:34 - 2016-11-11 10:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2016-12-09 19:34 - 2016-11-11 10:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2016-12-09 19:34 - 2016-11-11 10:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-12-09 19:34 - 2016-11-11 10:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2016-12-09 19:34 - 2016-11-11 10:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-12-09 19:34 - 2016-11-11 10:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-12-09 19:34 - 2016-11-11 10:14 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-12-09 19:34 - 2016-11-11 10:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-12-09 19:34 - 2016-11-11 10:14 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2016-12-09 19:34 - 2016-11-11 10:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2016-12-09 19:34 - 2016-11-11 10:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2016-12-09 19:34 - 2016-11-11 10:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll
2016-12-09 19:34 - 2016-11-11 10:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-12-09 19:34 - 2016-11-11 10:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-12-09 19:34 - 2016-11-11 10:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
2016-12-09 19:34 - 2016-11-11 10:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
2016-12-09 19:34 - 2016-11-11 10:11 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-12-09 19:34 - 2016-11-11 10:11 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-12-09 19:34 - 2016-11-11 10:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-12-09 19:34 - 2016-11-11 10:11 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-12-09 19:34 - 2016-11-11 10:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
2016-12-09 19:34 - 2016-11-11 10:10 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-12-09 19:34 - 2016-11-11 10:10 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-12-09 19:34 - 2016-11-11 10:09 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-12-09 19:34 - 2016-11-11 10:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-12-09 19:34 - 2016-11-11 10:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2016-12-09 19:34 - 2016-11-11 10:08 - 08127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-12-09 19:34 - 2016-11-11 10:08 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2016-12-09 19:34 - 2016-11-11 10:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2016-12-09 19:34 - 2016-11-11 10:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2016-12-09 19:34 - 2016-11-11 10:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2016-12-09 19:34 - 2016-11-11 10:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2016-12-09 19:34 - 2016-11-11 10:06 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-12-09 19:34 - 2016-11-11 10:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-12-09 19:34 - 2016-11-11 10:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-12-09 19:34 - 2016-11-11 10:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2016-12-09 19:34 - 2016-11-11 10:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-12-09 19:34 - 2016-11-11 10:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-12-09 19:34 - 2016-11-11 10:05 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-12-09 19:34 - 2016-11-11 10:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-12-09 19:34 - 2016-11-11 10:05 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-12-09 19:34 - 2016-11-11 10:04 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-12-09 19:34 - 2016-11-11 10:04 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 02317312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2016-12-09 19:34 - 2016-11-11 10:04 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2016-12-09 19:34 - 2016-11-11 10:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-12-09 19:34 - 2016-11-11 10:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-12-09 19:34 - 2016-11-11 10:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2016-12-09 19:34 - 2016-11-11 10:03 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-12-09 19:34 - 2016-11-11 10:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-12-09 19:34 - 2016-11-11 10:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-12-09 19:34 - 2016-11-11 10:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-12-09 19:34 - 2016-11-11 10:02 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-12-09 19:34 - 2016-11-11 10:01 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-12-09 19:34 - 2016-11-11 09:39 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-12-09 19:34 - 2016-11-11 09:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2016-12-09 19:34 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2016-12-09 19:34 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2016-12-09 19:34 - 2016-11-11 09:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-12-09 19:34 - 2016-11-11 08:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-12-09 19:34 - 2016-11-11 08:56 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-12-09 19:34 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll
2016-12-09 19:34 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2016-12-09 19:34 - 2016-11-11 08:49 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2016-12-09 19:34 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-12-09 19:34 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-12-09 19:34 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-12-09 19:34 - 2016-11-11 08:47 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-12-09 19:34 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-12-09 19:34 - 2016-11-11 08:47 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-12-09 19:34 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-12-09 19:34 - 2016-11-11 08:45 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-12-09 19:34 - 2016-11-11 08:45 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 06668032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll
2016-12-09 19:34 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll
2016-12-09 19:34 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-12-09 19:34 - 2016-11-11 08:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe
2016-12-09 19:34 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-12-09 19:34 - 2016-11-11 08:28 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-12-09 19:34 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
2016-12-09 19:34 - 2016-11-11 08:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-12-09 19:34 - 2016-11-11 08:26 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2016-12-09 19:34 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe
2016-12-09 19:34 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-12-09 19:34 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-12-09 19:34 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2016-12-09 19:34 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
2016-12-09 19:34 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-12-09 19:34 - 2016-11-11 08:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2016-12-09 19:34 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2016-12-09 19:34 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2016-12-09 19:34 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-12-09 19:34 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2016-12-09 19:34 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-12-09 19:34 - 2016-11-11 08:21 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-12-09 19:34 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2016-12-09 19:34 - 2016-11-11 08:20 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-12-09 19:34 - 2016-11-11 08:20 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-12-09 19:34 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-12-09 19:34 - 2016-11-11 08:20 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2016-12-09 19:34 - 2016-11-11 08:20 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2016-12-09 19:34 - 2016-11-11 08:19 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-12-09 19:34 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2016-12-09 19:34 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2016-12-09 19:34 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-12-09 19:34 - 2016-11-11 08:19 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-12-09 19:34 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2016-12-09 19:34 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2016-12-09 19:34 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2016-12-09 19:34 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
2016-12-09 19:34 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2016-12-09 19:34 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2016-12-09 19:34 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2016-12-09 19:34 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2016-12-09 19:34 - 2016-11-11 08:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2016-12-09 19:34 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2016-12-09 19:34 - 2016-11-11 08:17 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2016-12-09 19:34 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2016-12-09 19:34 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2016-12-09 19:34 - 2016-11-11 08:16 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-12-09 19:34 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-12-09 19:34 - 2016-11-11 08:16 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-12-09 19:34 - 2016-11-11 08:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-12-09 19:34 - 2016-11-11 08:15 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-12-09 19:34 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-12-09 19:34 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-12-09 19:34 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2016-12-09 19:34 - 2016-11-11 08:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-12-09 19:34 - 2016-11-11 08:14 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-12-09 19:34 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2016-12-09 19:34 - 2016-11-11 08:13 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-12-09 19:34 - 2016-11-11 08:13 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-12-09 19:34 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll
2016-12-09 19:34 - 2016-11-11 08:11 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-12-09 19:34 - 2016-11-11 08:10 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-12-09 19:34 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-12-09 19:34 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
2016-12-09 19:34 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-12-09 19:34 - 2016-11-11 08:09 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2016-12-09 19:34 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2016-12-09 19:34 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll
2016-12-09 19:34 - 2016-11-11 08:06 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2016-12-09 19:34 - 2016-11-11 08:06 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-12-09 19:34 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2016-12-09 19:34 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2016-12-09 19:34 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2016-12-09 19:34 - 2016-11-11 08:06 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2016-12-09 19:34 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2016-12-09 19:34 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll
2016-12-09 19:34 - 2016-11-11 08:05 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-12-09 19:34 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-12-09 19:34 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2016-12-09 19:34 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2016-12-09 19:34 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-12-09 19:34 - 2016-11-11 08:04 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-12-09 19:34 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-12-09 19:34 - 2016-11-11 08:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2016-12-09 19:34 - 2016-11-11 08:04 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2016-12-09 19:34 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-12-09 19:34 - 2016-11-11 08:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2016-12-09 19:34 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2016-12-09 19:34 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-12-09 19:34 - 2016-11-11 08:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-12-09 19:34 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2016-12-09 19:34 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2016-12-09 19:34 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-12-09 19:34 - 2016-11-11 08:03 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2016-12-09 19:34 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2016-12-09 19:34 - 2016-11-11 08:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2016-12-09 19:34 - 2016-11-11 08:01 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-12-09 19:34 - 2016-11-11 07:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2016-12-09 19:22 - 2016-12-09 19:24 - 00287098 _____ C:\TDSSKiller.3.1.0.12_09.12.2016_19.22.22_log.txt
2016-12-09 19:22 - 2016-12-09 19:22 - 04747704 _____ (AO Kaspersky Lab) C:\Users\totti\Downloads\tdsskiller.exe
2016-12-08 01:53 - 2016-12-08 01:55 - 00000000 ____D C:\WINDOWS\Microsoft Antimalware
2016-12-08 01:50 - 2016-12-08 01:50 - 00679784 _____ C:\Users\totti\Downloads\3120677.csv
2016-12-08 01:50 - 2016-12-08 01:50 - 00679784 _____ C:\Users\totti\Downloads\3120677 (1).csv
2016-12-07 22:27 - 2016-12-07 22:27 - 02444400 _____ C:\Users\totti\Downloads\Cinergy_Hybrid_Stick_Drv_Setup_1.00.08.06a_Vista_7_8_64Bit.exe
2016-12-07 22:27 - 2016-12-07 22:27 - 00000000 ____D C:\Program Files (x86)\TERRATEC Electronic GmbH
2016-12-07 22:24 - 2016-12-07 22:24 - 04322312 _____ C:\Users\totti\Downloads\195447-64.exe
2016-12-07 22:21 - 2016-12-07 22:25 - 00000000 ____D C:\Program Files (x86)\Terratec
2016-12-07 22:21 - 2016-12-07 22:21 - 04322240 _____ C:\Users\totti\Downloads\193534-64.exe
2016-12-07 22:21 - 2016-12-07 22:21 - 00000000 ____D C:\Program Files\DIFX
2016-12-07 22:18 - 2016-12-07 22:18 - 10998160 _____ C:\Users\totti\Downloads\TERRATEC_CINERGY_T2_Stick_HD_Driver_Setup_5.2013.0725.0_XP_Vista_7_8.exe
2016-12-07 22:16 - 2016-12-07 22:16 - 00000000 ____D C:\TerraTec
2016-12-07 22:15 - 2016-12-07 22:15 - 00069632 _____ C:\Users\totti\Downloads\Cinergy_T2_Drv_Vista_XP_2.3.0.26.exe
2016-12-07 22:06 - 2016-12-07 22:06 - 01212416 _____ C:\Users\totti\Downloads\42PD7200D.0003.pdf
2016-12-07 04:07 - 2016-12-07 04:07 - 00000000 ____D C:\Users\Thorsten\AppData\Local\EgisTec IPS
2016-12-06 23:09 - 2016-12-06 23:09 - 00000000 ____D C:\Users\totti\AppData\Local\EgisTec IPS
2016-12-06 23:09 - 2016-12-06 23:09 - 00000000 ____D C:\Users\totti\AppData\Local\EgisTec
2016-12-06 22:40 - 2016-12-06 23:09 - 00000000 ____D C:\ProgramData\EgisTec IPS
2016-12-06 22:40 - 2016-12-06 22:40 - 00062776 _____ (Egis Technology Inc.) C:\WINDOWS\system32\Drivers\mwlPSDVDisk.sys
2016-12-06 22:40 - 2016-12-06 22:40 - 00022648 _____ (Egis Technology Inc.) C:\WINDOWS\system32\Drivers\mwlPSDFilter.sys
2016-12-06 22:40 - 2016-12-06 22:40 - 00020520 _____ (Egis Technology Inc.) C:\WINDOWS\system32\Drivers\mwlPSDNserv.sys
2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EgisTec
2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\ProgramData\EgisTec
2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\Program Files\EgisTec IPS
2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\Program Files (x86)\EgisTec IPS
2016-12-06 22:40 - 2016-12-06 22:40 - 00000000 ____D C:\Program Files (x86)\EgisTec BioExcess
2016-12-06 22:16 - 2016-12-06 22:17 - 49911681 _____ C:\Users\totti\Downloads\Fingerprint_EGISTEC_3.5.1.0_W10x64_A.zip
2016-12-06 22:13 - 2016-12-06 22:13 - 00096096 _____ C:\Users\totti\Downloads\serialnumberdetectiontool.exe
2016-12-06 21:10 - 2016-12-07 22:18 - 00000000 ____D C:\Users\totti\AppData\Local\Downloaded Installations
2016-12-06 20:15 - 2016-12-09 19:21 - 00003274 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2016-12-06 03:00 - 2016-12-06 03:00 - 00376528 _____ (Microsoft Corporation) C:\Users\Thorsten\Downloads\RefreshWindowsTool.exe
2016-12-06 00:18 - 2016-12-06 00:18 - 00009218 _____ C:\Users\totti\Desktop\eset.txt
2016-12-05 23:06 - 2016-12-05 23:06 - 00109608 _____ C:\Users\totti\Desktop\FRST.txt
2016-12-05 23:06 - 2016-12-05 23:06 - 00038177 _____ C:\Users\totti\Desktop\Addition.txt
2016-12-05 23:05 - 2016-12-11 17:53 - 00023473 _____ C:\Users\totti\Downloads\FRST.txt
2016-12-05 23:05 - 2016-12-05 23:06 - 00038174 _____ C:\Users\totti\Downloads\Addition.txt
2016-12-05 23:04 - 2016-12-10 20:40 - 02420224 _____ (Farbar) C:\Users\totti\Downloads\FRST64.exe
2016-12-05 22:30 - 2016-12-05 22:30 - 00101330 _____ C:\Users\Thorsten\Desktop\FRST.txt
2016-12-05 22:30 - 2016-12-05 22:30 - 00033068 _____ C:\Users\Thorsten\Desktop\Addition.txt
2016-12-05 22:29 - 2016-12-11 17:53 - 00000000 ____D C:\FRST
2016-12-05 22:29 - 2016-12-05 22:30 - 00101327 _____ C:\Users\Thorsten\Downloads\FRST.txt
2016-12-05 22:29 - 2016-12-05 22:30 - 00033065 _____ C:\Users\Thorsten\Downloads\Addition.txt
2016-12-05 22:28 - 2016-12-05 22:29 - 02419712 _____ (Farbar) C:\Users\Thorsten\Downloads\FRST64.exe
2016-12-05 20:19 - 2016-12-05 20:19 - 00000000 ____D C:\Program Files (x86)\ESET
2016-12-05 20:18 - 2016-12-05 20:18 - 00001741 _____ C:\22222222222222.txt
2016-12-05 20:17 - 2016-12-05 20:17 - 00002309 _____ C:\1111111111111111.txt
2016-12-05 19:02 - 2016-12-05 20:19 - 02870984 _____ (ESET) C:\Users\totti\Downloads\esetsmartinstaller_deu.exe
2016-12-05 18:58 - 2016-12-11 16:06 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-12-05 18:58 - 2016-12-05 18:58 - 00001171 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2016-12-05 18:58 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-12-05 18:58 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-12-05 18:58 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-12-05 18:57 - 2016-12-05 18:57 - 22851472 _____ (Malwarebytes ) C:\Users\totti\Downloads\mbam-setup-2.2.1.1043.exe
2016-12-05 18:45 - 2016-12-05 18:45 - 00000000 ____D C:\Users\totti\AppData\Roaming\Macromedia
2016-12-05 18:38 - 2016-12-07 20:55 - 00000000 ____D C:\Users\totti\AppData\LocalLow\Mozilla
2016-12-05 18:38 - 2016-12-05 18:44 - 00000000 ____D C:\Users\totti\AppData\Local\Mozilla
2016-12-05 18:38 - 2016-12-05 18:38 - 00000000 ____D C:\Users\totti\AppData\Roaming\Mozilla
2016-12-04 23:49 - 2016-12-04 23:49 - 00000000 ____D C:\Users\totti\AppData\Local\PeerDistRepub
2016-12-04 23:07 - 2016-12-04 23:07 - 00030100 _____ C:\Users\totti\Downloads\entschuld13.pdf
2016-12-04 22:39 - 2016-12-04 22:39 - 00001359 _____ C:\Users\Public\Desktop\EaseUS Todo PCTrans.lnk
2016-12-04 22:39 - 2016-12-04 22:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo PCTrans
2016-12-04 22:39 - 2016-12-04 22:39 - 00000000 ____D C:\Program Files (x86)\EaseUS
2016-12-04 22:38 - 2016-12-05 18:44 - 00000000 ____D C:\Users\totti\AppData\Local\MicrosoftEdge
2016-12-04 22:38 - 2016-12-04 22:39 - 05335456 _____ (EaseUS ) C:\Users\totti\Downloads\pctrans.exe
2016-12-04 22:21 - 2016-12-04 21:37 - 02359296 ____H C:\Users\totti\NTUSER (2).DAT
2016-12-04 22:21 - 2016-12-04 21:37 - 02359296 ____H C:\Users\Thorsten\NTUSER - Kopie.DAT
2016-12-04 19:28 - 2016-12-04 19:28 - 00000000 ____D C:\Users\totti\AppData\Roaming\Intel Corporation
2016-12-04 19:27 - 2016-12-11 15:42 - 00000000 ___RD C:\Users\totti\OneDrive
2016-12-04 19:27 - 2016-12-10 17:42 - 00000000 ____D C:\Users\totti\AppData\Local\Comms
2016-12-04 19:27 - 2016-12-09 19:21 - 00002383 _____ C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Skype
2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Logishrd
2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Apple Computer
2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Local\Western_Digital_Technolog
2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Local\SS22.2.28
2016-12-04 19:26 - 2016-12-10 17:41 - 00000000 ____D C:\Users\totti\AppData\Local\Packages
2016-12-04 19:26 - 2016-12-10 03:16 - 00000000 ____D C:\Users\totti
2016-12-04 19:26 - 2016-12-04 19:41 - 00000000 ____D C:\Users\totti\AppData\Local\Google
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Vorlagen
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Startmenü
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Netzwerkumgebung
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Lokale Einstellungen
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Eigene Dateien
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Druckumgebung
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Videos
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Musik
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Bilder
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Local\Verlauf
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Local\Anwendungsdaten
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Anwendungsdaten
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Roaming\Adobe
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\VirtualStore
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\TileDataLayer
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\Publishers
2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\ConnectedDevicesPlatform
2016-12-04 19:26 - 2016-11-27 00:07 - 00000020 ___SH C:\Users\totti\ntuser.ini
2016-12-04 01:23 - 2016-12-04 01:23 - 00000000 ____D C:\Program Files (x86)\Hercules
2016-12-04 01:22 - 2016-12-04 01:23 - 31550240 _____ (Hercules) C:\Users\Thorsten\Downloads\HWNU-300_V3.7.exe
2016-12-04 00:30 - 2016-12-04 00:30 - 04640844 _____ C:\Users\Thorsten\Downloads\WLR-5100v1001-firmware-v30.zip
2016-12-04 00:30 - 2016-12-04 00:30 - 02952963 _____ C:\Users\Thorsten\Downloads\WLR-5100v1001-Full-Manual.pdf
2016-12-04 00:27 - 2016-12-04 00:27 - 02952963 _____ C:\Users\Thorsten\Downloads\manual (2).pdf
2016-12-03 18:32 - 2016-12-03 18:32 - 00000000 ____D C:\Users\Thorsten\AppData\Local\TeamViewer
2016-12-02 23:38 - 2016-12-04 19:15 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-12-02 23:38 - 2016-12-03 18:38 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\TeamViewer
2016-12-02 23:38 - 2016-12-02 23:38 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2016-12-02 23:38 - 2016-12-02 23:38 - 00001100 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
2016-12-02 23:35 - 2015-06-22 12:20 - 00000000 ____D C:\Users\Thorsten\Downloads\DIR-825_fw_revb_210b01_ALL_multi_20150609
2016-12-02 23:34 - 2016-12-02 23:37 - 12877352 _____ (TeamViewer GmbH) C:\Users\Thorsten\Downloads\TeamViewer_Setup_de-agkp.exe
2016-12-02 23:26 - 2016-12-02 23:26 - 05286401 _____ C:\Users\Thorsten\Downloads\DIR-825_fw_revb_210b01_ALL_multi_20150609.zip
2016-12-02 23:23 - 2016-12-02 23:23 - 00029312 _____ C:\Users\Thorsten\Downloads\config.bin
2016-12-02 21:07 - 2016-12-02 21:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\ElevatedDiagnostics
2016-12-02 19:13 - 2016-12-02 19:13 - 00720417 _____ C:\Users\Thorsten\Downloads\Anleitung_WLAN-Router_als_Accesspoint_mit_Hitron_oder_CiscoEPC3208_Kabelmodem.pdf
2016-12-02 02:36 - 2016-12-02 02:36 - 1214701263 _____ C:\WINDOWS\MEMORY.DMP
2016-12-02 02:36 - 2016-12-02 02:36 - 00586244 _____ C:\WINDOWS\Minidump\120216-8265-01.dmp
2016-12-02 02:36 - 2016-12-02 02:36 - 00000000 ____D C:\WINDOWS\Minidump
2016-12-02 01:51 - 2016-12-02 01:51 - 00000000 ____D C:\Users\ttjh1\AppData\Local\PeerDistRepub
2016-12-01 21:31 - 2016-12-01 21:31 - 00166225 _____ C:\Users\Thorsten\Downloads\AVM-Merry-Christmas_2016.zip
2016-12-01 02:33 - 2016-12-01 02:33 - 04851072 _____ C:\Users\Thorsten\Downloads\cfosspeed-v1020.exe
2016-11-30 12:10 - 2016-11-30 12:10 - 00000000 ____D C:\ProgramData\Trymedia
2016-11-30 12:10 - 2016-11-30 12:10 - 00000000 ____D C:\ProgramData\GoBit Games
2016-11-30 10:12 - 2016-11-30 10:12 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Macromedia
2016-11-30 10:12 - 2016-11-30 10:12 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Comms
2016-11-30 10:11 - 2016-11-30 10:11 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Intel Corporation
2016-11-30 10:10 - 2016-12-11 07:32 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Packages
2016-11-30 10:10 - 2016-12-01 19:13 - 00000000 ____D C:\Users\ttjh1\AppData\Local\ConnectedDevicesPlatform
2016-11-30 10:10 - 2016-11-30 16:32 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Google
2016-11-30 10:10 - 2016-11-30 10:11 - 00002383 _____ C:\Users\ttjh1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-11-30 10:10 - 2016-11-30 10:10 - 00000020 ___SH C:\Users\ttjh1\ntuser.ini
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Skype
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Logishrd
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Apple Computer
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Adobe
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Western_Digital_Technolog
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\VirtualStore
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\TileDataLayer
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\SS22.2.28
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Publishers
2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\MicrosoftEdge
2016-11-30 03:08 - 2016-11-30 03:28 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Apple Computer
2016-11-30 03:08 - 2016-11-30 03:08 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-11-30 03:08 - 2016-11-30 03:08 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apple Computer
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apple
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Apple Computer
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\iTunes
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\iPod
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\Bonjour
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-11-30 03:04 - 2016-11-30 03:07 - 177311560 _____ (Apple Inc.) C:\Users\Thorsten\Downloads\iTunes6464Setup.exe
2016-11-30 00:21 - 2016-11-30 00:21 - 00004566 _____ C:\Users\Thorsten\Downloads\oscam_2016-11-30_0021_oscam.log.tgz
2016-11-29 21:28 - 2016-11-29 21:28 - 00000582 _____ C:\Users\Thorsten\Downloads\Enable_Num_Lock_on_Sign-in_screen.reg
2016-11-29 02:32 - 2016-11-29 02:32 - 00003344 _____ C:\WINDOWS\System32\Tasks\SamsungMagician
2016-11-29 02:32 - 2016-11-29 02:32 - 00001298 _____ C:\Users\Public\Desktop\Samsung Magician.lnk
2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\ProgramData\Samsung
2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\Program Files (x86)\Samsung
2016-11-29 02:31 - 2016-05-13 08:52 - 19226728 _____ (Samsung Electronics ) C:\Users\Thorsten\Downloads\Samsung_Magician_Setup_v497.exe
2016-11-29 02:30 - 2016-11-29 02:31 - 18946704 _____ C:\Users\Thorsten\Downloads\Samsung_Magician_Setup_v497.zip
2016-11-29 01:41 - 2016-11-29 01:41 - 00629880 _____ C:\Users\Thorsten\Downloads\oscam-emu-mips-freetz11281-fritz73xxOS62-webif-libusb_st
2016-11-29 01:36 - 2016-11-29 01:36 - 00213602 _____ C:\Users\Thorsten\Downloads\list_smargo-1 (3).20-emu11232-mips-freetz-linux-uclibc-libusb
         

Alt 11.12.2016, 18:09   #20
totti6169
 
Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? - Standard

Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?



Code:
ATTFilter
2016-11-29 00:13 - 2016-11-29 00:13 - 04083028 _____ C:\Users\Thorsten\Downloads\WDAccess_1.4.5949.29996.zip
2016-11-29 00:13 - 2016-11-29 00:13 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Western_Digital_Technolog
2016-11-29 00:11 - 2016-11-29 00:11 - 08497626 _____ C:\Users\Thorsten\Downloads\WDSync_1.3.5949.26210.zip
2016-11-28 23:48 - 2016-11-28 23:48 - 00000000 ____D C:\Users\Thorsten\Downloads\DIP5_10360
2016-11-28 23:43 - 2016-11-28 23:28 - 00404752 _____ (Intel Corporation) C:\WINDOWS\system32\PROUnstl.exe
2016-11-28 23:43 - 2016-11-28 23:28 - 00001904 ____N C:\WINDOWS\system32\SetupBD.din
2016-11-28 23:40 - 2016-11-28 23:40 - 00000000 ____D C:\Users\Thorsten\Downloads\ROGConnectPlus_Win7-81-10_V10030
2016-11-28 23:40 - 2015-06-05 09:37 - 00192512 _____ (ASUSTeK Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\UpdateHelper.dll
2016-11-28 23:39 - 2016-11-28 23:39 - 00001769 _____ C:\WINDOWS\Language_trs.ini
2016-11-28 23:39 - 2016-11-28 23:37 - 00011832 _____ C:\WINDOWS\SysWOW64\Drivers\AsInsHelp64.sys
2016-11-28 23:39 - 2016-11-28 23:37 - 00010216 _____ C:\WINDOWS\SysWOW64\Drivers\AsInsHelp32.sys
2016-11-28 23:37 - 2016-11-28 23:37 - 00000000 ____D C:\Users\Thorsten\Downloads\FRONTBASE-10117
2016-11-28 23:28 - 2016-11-28 23:28 - 00316736 _____ (Intel Corporation) C:\WINDOWS\system32\PRONtObj.dll
2016-11-28 23:28 - 2016-11-28 23:28 - 00155192 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iANSW60e.sys
2016-11-28 23:27 - 2016-11-28 23:27 - 00000000 ____D C:\Users\Thorsten\Downloads\Intel_Gigabit_Ethernet_Win7-81_V20230010_Win10_V20240010
2016-11-28 23:24 - 2016-11-28 23:43 - 00000000 ____D C:\Program Files\Intel
2016-11-28 23:24 - 2016-11-28 23:24 - 02037236 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ____D C:\Users\Thorsten\Intel
2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Intel Corporation
2016-11-28 23:23 - 2016-11-28 23:23 - 00002056 _____ C:\Users\Public\Desktop\ASUS Boot Setting.lnk
2016-11-28 23:23 - 2016-11-28 23:23 - 00000000 ____D C:\Users\Thorsten\Downloads\ASUS_BootSetting_Win7-81-10_VER10022
2016-11-27 16:52 - 2016-11-27 17:02 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0 (2).exe
2016-11-27 16:15 - 2016-12-04 16:38 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4564E7FE-E9AE-4766-8A69-A4964C928904}
2016-11-27 16:15 - 2016-11-27 16:15 - 02722395 _____ C:\Users\Thorsten\Downloads\jperf-2.0.2.zip
2016-11-27 16:15 - 2016-11-27 16:15 - 00000000 ____D C:\Users\Thorsten\Desktop\jperf-2.0.2
2016-11-27 16:12 - 2016-11-27 16:12 - 00606026 _____ C:\Users\Thorsten\Downloads\iperf-master.zip
2016-11-27 16:12 - 2016-11-27 16:12 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Sun
2016-11-27 16:11 - 2016-11-27 16:15 - 00000000 ____D C:\ProgramData\Oracle
2016-11-27 16:11 - 2016-11-27 16:11 - 00737344 _____ (Oracle Corporation) C:\Users\Thorsten\Downloads\JavaSetup8u111.exe
2016-11-27 16:11 - 2016-11-27 16:11 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-11-27 16:11 - 2016-11-27 16:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-11-27 16:11 - 2016-11-27 16:11 - 00000000 ____D C:\Program Files (x86)\Java
2016-11-27 16:09 - 2016-12-05 21:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-11-27 16:09 - 2016-12-05 21:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-11-27 16:09 - 2016-11-27 16:16 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Mozilla
2016-11-27 16:09 - 2016-11-27 16:10 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Mozilla
2016-11-27 16:09 - 2016-11-27 16:09 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-11-27 16:09 - 2016-11-27 16:09 - 00001216 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-11-27 16:08 - 2016-11-27 16:09 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0 (1).exe
2016-11-27 16:05 - 2016-11-27 16:05 - 00248583 _____ C:\Users\Thorsten\Downloads\iperf-2.0.5.tar.gz
2016-11-27 15:42 - 2016-11-29 00:00 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Wireshark
2016-11-27 15:22 - 2016-11-27 15:35 - 49242104 _____ (Wireshark development team) C:\Users\Thorsten\Downloads\Wireshark-win64-2.2.2.exe
2016-11-27 15:16 - 2016-11-27 15:16 - 02970395 _____ C:\Users\Thorsten\Downloads\cacti-0.8.8h.zip
2016-11-27 14:29 - 2016-11-27 14:29 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps
2016-11-27 14:13 - 2016-11-27 14:13 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-11-27 04:53 - 2016-11-27 04:53 - 00000000 ____D C:\Users\Thorsten\Downloads\Asmedia_USB3_V116351
2016-11-27 04:52 - 2016-11-27 14:14 - 00002685 _____ C:\Users\Public\Desktop\ASUS(R) Intel(R) Extreme Tuning Utility.lnk
2016-11-27 04:52 - 2016-11-27 14:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS(R) Intel(R) Extreme Tuning Utility
2016-11-27 04:52 - 2016-11-27 14:13 - 00000000 ____D C:\WINDOWS\System32\Tasks\Intel
2016-11-27 04:52 - 2016-11-27 04:54 - 00000000 ____D C:\Users\Thorsten\AppData\Local\SS22.2.28
2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services
2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-11-27 04:52 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2016-11-27 04:52 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2016-11-27 04:52 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2016-11-27 04:52 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2016-11-27 04:50 - 2016-11-29 00:13 - 00000000 ____D C:\ProgramData\Package Cache
2016-11-27 04:50 - 2016-11-27 04:50 - 00003214 _____ C:\WINDOWS\System32\Tasks\SS2UILauncherRun
2016-11-27 04:50 - 2016-11-27 04:50 - 00003202 _____ C:\WINDOWS\System32\Tasks\SS2Svc64Run
2016-11-27 04:50 - 2016-11-27 04:50 - 00003194 _____ C:\WINDOWS\System32\Tasks\SS2Svc32Run
2016-11-27 04:50 - 2016-11-27 04:50 - 00001338 _____ C:\Users\Public\Desktop\Sonic Studio.lnk
2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonic Suite 2
2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\Program Files\ASUSTeKcomputer.Inc
2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\Program Files (x86)\SAVITECH
2016-11-27 04:50 - 2016-11-27 04:42 - 72520720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2016-11-27 04:50 - 2016-11-27 04:42 - 06879938 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2016-11-27 04:50 - 2016-11-27 04:42 - 05593624 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 03283248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 03203592 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 02895104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2016-11-27 04:50 - 2016-11-27 04:42 - 02073096 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 01360528 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 01003864 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 00689888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 00192992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 00118600 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2016-11-27 04:50 - 2016-11-27 04:42 - 00105312 _____ C:\WINDOWS\system32\audioLibVc.dll
2016-11-27 04:50 - 2016-11-27 04:41 - 00003008 ____N C:\WINDOWS\system32\Drivers\DTSU2P.DAT
2016-11-27 04:48 - 2016-11-27 04:48 - 00000000 ____D C:\Program Files\Realtek
2016-11-27 04:47 - 2016-11-27 04:41 - 02838232 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll
2016-11-27 04:46 - 2016-11-27 04:46 - 00000000 _____ C:\WINDOWS\SysWOW64\Drivers\1043_ASUSTeK_MAXIMUS VIII RANGER.alu
2016-11-27 04:42 - 2016-11-27 04:50 - 00000000 ___HD C:\Program Files (x86)\Temp
2016-11-27 04:42 - 2016-11-27 04:42 - 00000000 ____D C:\Program Files (x86)\Realtek
2016-11-27 04:41 - 2016-12-11 15:38 - 01048576 _____ C:\WINDOWS\PE_Rom.dll
2016-11-27 04:41 - 2016-11-27 04:41 - 00000000 ____D C:\Users\Thorsten\Downloads\V7904_20160815_WHQL_DTS_StudioSound_SonicSuite_2228
2016-11-27 04:41 - 2016-07-12 19:04 - 00024824 ____N (ASUSTeK Computer Inc.) C:\WINDOWS\system32\Drivers\IOMap64.sys
2016-11-27 04:17 - 2016-11-28 23:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2016-11-27 04:17 - 2016-11-27 04:17 - 00000000 ____D C:\Program Files\ASUS
2016-11-27 04:17 - 2016-11-27 04:17 - 00000000 ____D C:\Program Files (x86)\ASM104xUSB3
2016-11-27 04:17 - 2016-11-27 04:15 - 00046152 _____ (MCCI Corporation) C:\WINDOWS\SysWOW64\Drivers\ASUSFILTER.sys
2016-11-27 04:17 - 2016-11-27 04:15 - 00014464 _____ C:\WINDOWS\SysWOW64\Drivers\AsUpIO.sys
2016-11-27 04:16 - 2016-12-06 22:40 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-11-27 04:16 - 2016-11-28 23:49 - 00000000 ____D C:\WINDOWS\System32\Tasks\ASUS
2016-11-27 04:16 - 2016-11-28 23:24 - 00000000 ____D C:\ProgramData\Intel
2016-11-27 04:16 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Intel
2016-11-27 04:16 - 2015-10-19 17:22 - 00022192 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\AndroidAFDx64.sys
2016-11-27 04:16 - 2013-01-28 15:58 - 00014848 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\AiChargerPlus.sys
2016-11-27 04:15 - 2016-11-28 23:40 - 00000000 ____D C:\Program Files (x86)\ASUS
2016-11-27 04:15 - 2016-11-27 04:15 - 00028672 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\AsIO.dll
2016-11-27 04:15 - 2016-11-27 04:15 - 00015232 _____ C:\WINDOWS\SysWOW64\Drivers\AsIO.sys
2016-11-27 04:15 - 2016-11-27 04:15 - 00000000 ____D C:\Users\Thorsten\Downloads\AISuite3_Win7-81-10_MaxVIII_Series_V10130
2016-11-27 04:14 - 2016-11-28 23:50 - 00000000 ____D C:\ProgramData\ASUS
2016-11-27 04:13 - 2016-11-27 04:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-11-27 04:13 - 2016-11-27 04:13 - 00000000 ____D C:\Program Files\7-Zip
2016-11-27 04:11 - 2016-11-27 04:14 - 122808649 _____ C:\Users\Thorsten\Downloads\DIP5_10360.zip
2016-11-27 04:11 - 2016-11-27 04:12 - 37822895 _____ C:\Users\Thorsten\Downloads\ASUS_XTU_V612208.zip
2016-11-27 04:06 - 2016-11-27 04:06 - 00001806 _____ C:\Users\Public\Desktop\HDClone.lnk
2016-11-27 04:06 - 2016-11-27 04:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDClone 6 Free Edition
2016-11-27 04:05 - 2016-11-27 04:06 - 00000000 ____D C:\Program Files (x86)\HDClone 6 Free Edition
2016-11-27 02:54 - 2016-11-27 02:54 - 201326592 _____ C:\Users\Thorsten\Downloads\clonezilla-live-2.5.0-5-amd64.iso
2016-11-27 02:33 - 2016-11-27 02:33 - 00000000 ____D C:\Program Files\Common Files\Logishrd
2016-11-27 02:19 - 2016-11-27 02:19 - 141011376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-11-27 02:19 - 2016-11-27 02:19 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-11-27 02:19 - 2016-11-27 02:09 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-11-27 02:16 - 2016-11-27 02:20 - 71601392 _____ C:\Users\Thorsten\Downloads\mc_windows_setup (1).exe
2016-11-27 01:13 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Apple
2016-11-27 01:13 - 2016-11-29 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital
2016-11-27 01:13 - 2016-11-29 00:11 - 00000000 ____D C:\ProgramData\Western Digital
2016-11-27 01:13 - 2016-11-29 00:11 - 00000000 ____D C:\Program Files (x86)\Western Digital
2016-11-27 01:13 - 2016-11-27 01:13 - 00001226 _____ C:\Users\Public\Desktop\WD My Cloud.lnk
2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\Downloads\WD_Quick_View_Setup_for_Windows
2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Macromedia
2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\com.wd.WDMyCloud
2016-11-27 01:12 - 2016-11-27 01:13 - 63849440 _____ C:\Users\Thorsten\Downloads\WDMyCloud_win.exe
2016-11-27 01:12 - 2016-11-27 01:13 - 04341113 _____ C:\Users\Thorsten\Downloads\WD_Quick_View_Setup_for_Windows.zip
2016-11-27 01:09 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Western Digital
2016-11-27 01:08 - 2016-11-27 02:23 - 00001130 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-27 01:08 - 2016-11-27 02:23 - 00001126 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-27 01:08 - 2016-11-27 01:17 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Google
2016-11-27 01:08 - 2016-11-27 01:09 - 71601392 _____ C:\Users\Thorsten\Downloads\mc_windows_setup.exe
2016-11-27 01:08 - 2016-11-27 01:08 - 01065376 _____ (Google Inc.) C:\Users\Thorsten\Downloads\ChromeSetup.exe
2016-11-27 01:08 - 2016-11-27 01:08 - 00004188 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-11-27 01:08 - 2016-11-27 01:08 - 00003956 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-11-27 01:08 - 2016-11-27 01:08 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-27 01:08 - 2016-11-27 01:08 - 00002324 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-11-27 01:08 - 2016-11-27 01:08 - 00000000 ____D C:\Program Files (x86)\Google
2016-11-27 00:43 - 2016-11-27 02:33 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Logitech
2016-11-27 00:43 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logitech
2016-11-27 00:43 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Deployment
2016-11-27 00:14 - 2016-11-27 00:59 - 00000000 ____D C:\Users\Thorsten\AppData\Local\MicrosoftEdge
2016-11-27 00:11 - 2016-11-27 02:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2016-11-27 00:11 - 2016-11-27 02:34 - 00000000 ____D C:\ProgramData\Logishrd
2016-11-27 00:11 - 2016-11-27 02:33 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Logishrd
2016-11-27 00:11 - 2016-11-27 02:33 - 00000000 ____D C:\Program Files\Logitech
2016-11-27 00:11 - 2016-11-27 00:11 - 00000000 ____D C:\Users\Thorsten\AppData\Local\PeerDistRepub
2016-11-27 00:09 - 2016-12-07 04:08 - 00002392 _____ C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Skype
2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Comms
2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-11-27 00:08 - 2016-11-27 00:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Publishers
2016-11-27 00:07 - 2016-12-02 02:58 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Packages
2016-11-27 00:07 - 2016-11-27 02:30 - 00000000 ____D C:\Users\Thorsten\AppData\Local\ConnectedDevicesPlatform
2016-11-27 00:07 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apps\2.0
2016-11-27 00:07 - 2016-11-27 00:07 - 00000020 ___SH C:\Users\Thorsten\ntuser.ini
2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Adobe
2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Local\VirtualStore
2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Local\TileDataLayer
2016-11-26 23:55 - 2016-12-11 07:35 - 02624340 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Vorlagen
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Startmenü
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\All Users
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Vorlagen
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Startmenü
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Dokumente
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2016-11-26 23:53 - 2016-11-26 23:53 - 00017426 _____ C:\Users\Thorsten\Desktop\Entfernte Apps.html
2016-11-26 23:53 - 2016-11-26 23:53 - 00016796 _____ C:\Users\ttjh1\Desktop\Entfernte Apps.html
2016-11-26 23:53 - 2016-07-16 12:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-11-26 23:50 - 2016-12-11 07:35 - 00000000 ____D C:\Users\ttjh1
2016-11-26 23:50 - 2016-12-04 22:21 - 00000000 ____D C:\Users\Thorsten
2016-11-26 23:50 - 2016-11-27 04:50 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Vorlagen
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Startmenü
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Netzwerkumgebung
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Lokale Einstellungen
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Eigene Dateien
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Druckumgebung
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Local\Verlauf
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Local\Anwendungsdaten
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Anwendungsdaten
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Vorlagen
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Startmenü
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Netzwerkumgebung
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Lokale Einstellungen
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Eigene Dateien
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Druckumgebung
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Videos
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Musik
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Bilder
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Local\Verlauf
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Local\Anwendungsdaten
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Anwendungsdaten
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____D C:\ProgramData\USOShared
2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____D C:\ProgramData\NVIDIA
2016-11-26 23:49 - 2016-12-11 17:51 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-11-26 23:49 - 2016-12-11 07:29 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-26 23:49 - 2016-12-09 19:43 - 00198392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-11-26 23:49 - 2015-11-05 16:08 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-11-26 23:49 - 2015-11-05 16:08 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-11-26 23:49 - 2015-11-05 16:08 - 02554672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-11-26 23:49 - 2015-11-05 16:08 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-11-26 23:49 - 2015-11-05 16:08 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-11-26 23:49 - 2015-11-05 16:08 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-11-26 23:49 - 2015-10-28 14:49 - 06027430 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-11-26 23:48 - 2016-11-27 00:23 - 00000000 ____D C:\Windows.old
2016-11-26 23:48 - 2016-11-26 23:54 - 00000000 ___DC C:\WINDOWS\Panther
2016-11-26 23:48 - 2016-11-26 23:49 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-11-26 23:48 - 2016-11-26 23:48 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-11-26 23:48 - 2016-11-26 23:48 - 00000000 ____D C:\WINDOWS\InfusedApps
2016-11-26 23:47 - 2016-12-11 07:35 - 01218274 _____ C:\WINDOWS\system32\perfh007.dat
2016-11-26 23:47 - 2016-12-11 07:35 - 00283292 _____ C:\WINDOWS\system32\perfc007.dat
2016-11-26 23:47 - 2016-11-26 23:47 - 00305594 _____ C:\WINDOWS\system32\perfi007.dat
2016-11-26 23:47 - 2016-11-26 23:47 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\de
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\winrm
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\WCN
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\de
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\0409
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\Setup
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\OCR
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\MSBuild
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-11-26 23:46 - 2016-10-29 00:56 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-11-26 23:46 - 2016-10-29 00:56 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-26 23:45 - 2016-12-11 15:44 - 00000000 ___HD C:\Program Files\WindowsApps
2016-11-26 23:45 - 2016-12-11 15:44 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-11-26 23:45 - 2016-12-11 04:49 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-11-26 23:45 - 2016-12-11 01:10 - 00000000 ____D C:\WINDOWS\rescache
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-11-26 23:45 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-11-26 23:45 - 2016-12-05 21:16 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-11-26 23:45 - 2016-12-04 00:40 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-11-26 23:45 - 2016-11-29 00:13 - 00000000 ____D C:\WINDOWS\Registration
2016-11-26 23:45 - 2016-11-27 04:55 - 00000000 ____D C:\WINDOWS\appcompat
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___RD C:\Program Files\Windows Defender
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\setup
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\Provisioning
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-11-26 23:45 - 2016-11-27 02:22 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2016-11-26 23:45 - 2016-11-26 23:54 - 00000000 ____D C:\Program Files\Windows NT
2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 __RHD C:\Users\Public\Libraries
2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 ____D C:\WINDOWS\system32\spool
2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2016-11-26 23:45 - 2016-11-26 23:52 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ____D C:\WINDOWS\CSC
2016-11-26 23:45 - 2016-11-26 23:49 - 00000000 ____D C:\WINDOWS\Help
2016-11-26 23:45 - 2016-11-26 23:48 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SystemApps
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\Com
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\IME
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Common Files\System
2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\Program Files\Windows Sidebar
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __RSD C:\WINDOWS\Media
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\system32\Nui
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Web
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Vss
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\tracing
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\TAPI
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SystemResources
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\winevt
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ras
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\IME
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\icsxml
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ias
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\downlevel
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\DDFs
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\System
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SKB
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\security
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\schemas
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SchCache
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Resources
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\RemotePackages
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\PLA
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Performance
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\ModemLogs
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\L2Schemas
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\InputMethod
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Globalization
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\GameBarPresenceWriter
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Cursors
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Branding
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\addins
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\ProgramData\USOPrivate
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\ProgramData\Comms
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Common Files\Services
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows NT
2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-11-26 23:45 - 2016-11-26 23:44 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2016-11-26 23:45 - 2016-11-26 23:44 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2016-11-26 23:45 - 2016-11-26 23:44 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2016-11-26 23:45 - 2016-11-26 23:44 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2016-11-26 23:45 - 2016-11-26 23:44 - 00027136 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
2016-11-26 23:45 - 2016-11-26 23:44 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
2016-11-26 23:45 - 2016-11-26 23:44 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK
2016-11-26 23:45 - 2016-11-26 23:44 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2016-11-26 23:45 - 2016-11-26 23:44 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2016-11-26 23:45 - 2016-11-26 23:44 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2016-11-26 23:45 - 2016-11-26 23:44 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2016-11-26 23:45 - 2016-11-26 23:44 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2016-11-26 23:45 - 2016-11-26 23:44 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2016-11-26 23:45 - 2016-11-26 23:44 - 00000219 _____ C:\WINDOWS\system.ini
2016-11-26 23:45 - 2016-11-26 23:44 - 00000092 _____ C:\WINDOWS\win.ini
2016-11-26 23:44 - 2016-12-09 19:43 - 00000000 ____D C:\WINDOWS\INF
2016-11-26 23:42 - 2016-12-10 20:42 - 01835008 _____ C:\WINDOWS\system32\config\BBI
2016-11-26 23:42 - 2016-12-09 19:41 - 00000000 ____D C:\WINDOWS\servicing
2016-11-26 23:42 - 2016-12-09 19:40 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-11-26 23:42 - 2016-11-26 23:49 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-11-26 23:42 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\SMI
2016-11-26 20:17 - 2016-11-26 20:17 - 00376528 _____ (Microsoft Corporation) C:\Users\Thorsten\Downloads\Nicht bestätigt 574898.crdownload
2016-11-26 04:07 - 2016-11-26 04:07 - 00000000 ____D C:\Users\Thorsten\Desktop\slenf2aw.fmg
2016-11-26 01:31 - 2016-11-26 01:31 - 04147600 _____ ($Co_Name Inc.) C:\Users\Thorsten\Downloads\unifying250.exe
2016-11-20 20:10 - 2016-12-01 23:14 - 00000000 ____D C:\Users\Thorsten\AppData\LocalLow\Mozilla
2016-11-20 20:09 - 2016-11-20 20:09 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0.exe
2016-11-19 00:03 - 2016-11-19 00:03 - 02952963 _____ C:\Users\Thorsten\Downloads\manual (1).pdf
2016-11-19 00:01 - 2016-11-19 00:01 - 02952963 _____ C:\Users\Thorsten\Downloads\manual.pdf
2016-11-17 17:17 - 2016-11-17 17:17 - 00203900 _____ C:\Users\Thorsten\Downloads\3441119-3290097-Feedback.pdf
2016-11-17 17:07 - 2016-11-17 17:07 - 00183388 _____ C:\Users\Thorsten\Downloads\3440522-3289533-Feedback.pdf
2016-11-16 21:15 - 2016-11-16 21:15 - 00001518 _____ C:\Users\Thorsten\Downloads\LifeCam3.60 (1) - Verknüpfung.lnk
2016-11-16 21:15 - 2016-11-16 21:15 - 00001500 _____ C:\Users\Thorsten\Downloads\ifunbox_setup - Verknüpfung.lnk
2016-11-16 21:15 - 2016-11-16 21:15 - 00001482 _____ C:\Users\Thorsten\Downloads\LifeCam3.60 - Verknüpfung.lnk
2016-11-16 21:15 - 2016-11-16 21:15 - 00001080 _____ C:\Users\Thorsten\Downloads\node-v4.6.1.tar.gz - Verknüpfung.lnk
2016-11-14 18:18 - 2016-11-26 23:30 - 00000000 ___RD C:\Users\Thorsten\iCloudDrive
2016-11-13 03:54 - 2016-11-13 03:54 - 00000000 ____D C:\Users\Thorsten\Documents\Ashampoo Burning Studio 16

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-12-11 07:32 - 2016-02-13 18:32 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-12-10 20:41 - 2016-04-22 03:30 - 00000000 ____D C:\Users\Thorsten\AppData\LocalLow\Temp
2016-12-07 04:08 - 2016-04-17 00:15 - 00000000 ___RD C:\Users\Thorsten\OneDrive
2016-11-30 10:11 - 2016-04-17 09:26 - 00000000 ___RD C:\Users\ttjh1\OneDrive
2016-11-28 23:36 - 2016-07-16 12:43 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TFTP.EXE
2016-11-28 23:35 - 2016-10-28 05:24 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmp.exe
2016-11-28 23:35 - 2016-10-28 05:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmp.exe
2016-11-28 23:35 - 2016-07-16 12:44 - 00194560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmpsnap.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntwin.exe
2016-11-28 23:35 - 2016-07-16 12:44 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntwin.exe
2016-11-28 23:35 - 2016-07-16 12:44 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntagnt.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntagnt.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hostmib.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\lmmib2.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hostmib.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lmmib2.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntcmd.exe
2016-11-28 23:35 - 2016-07-16 12:44 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntcmd.exe
2016-11-28 23:35 - 2016-07-16 12:44 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64mib.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmpmib.dll
2016-11-28 23:35 - 2016-07-16 12:44 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmpmib.dll
2016-11-28 23:35 - 2016-07-16 12:43 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmpsnap.dll
2016-11-28 23:35 - 2016-07-16 12:43 - 00107882 _____ C:\WINDOWS\SysWOW64\mib_ii.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00107882 _____ C:\WINDOWS\system32\mib_ii.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00048593 _____ C:\WINDOWS\SysWOW64\hostmib.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00048593 _____ C:\WINDOWS\system32\hostmib.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00034317 _____ C:\WINDOWS\SysWOW64\msiprip2.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00034317 _____ C:\WINDOWS\system32\msiprip2.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00030448 _____ C:\WINDOWS\SysWOW64\mcastmib.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00030448 _____ C:\WINDOWS\system32\mcastmib.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00026236 _____ C:\WINDOWS\SysWOW64\wins.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00026236 _____ C:\WINDOWS\system32\wins.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00026100 _____ C:\WINDOWS\SysWOW64\lmmib2.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00026100 _____ C:\WINDOWS\system32\lmmib2.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00022462 _____ C:\WINDOWS\SysWOW64\rfc2571.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00022462 _____ C:\WINDOWS\system32\rfc2571.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00021271 _____ C:\WINDOWS\SysWOW64\http.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00021271 _____ C:\WINDOWS\system32\http.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00015799 _____ C:\WINDOWS\SysWOW64\ipforwd.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00015799 _____ C:\WINDOWS\system32\ipforwd.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00015032 _____ C:\WINDOWS\SysWOW64\authserv.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00015032 _____ C:\WINDOWS\system32\authserv.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00014032 _____ C:\WINDOWS\SysWOW64\accserv.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00014032 _____ C:\WINDOWS\system32\accserv.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00013767 _____ C:\WINDOWS\SysWOW64\msipbtp.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00013767 _____ C:\WINDOWS\system32\msipbtp.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00006179 _____ C:\WINDOWS\SysWOW64\ftp.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00006179 _____ C:\WINDOWS\system32\ftp.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00004597 _____ C:\WINDOWS\SysWOW64\dhcp.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00004597 _____ C:\WINDOWS\system32\dhcp.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00004411 _____ C:\WINDOWS\SysWOW64\smi.mib
2016-11-28 23:35 - 2016-07-16 12:43 - 00004411 _____ C:\WINDOWS\system32\smi.mib
2016-11-27 04:42 - 2016-08-19 01:05 - 03133144 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2016-11-27 04:42 - 2016-08-19 01:04 - 05793528 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll
2016-11-27 04:42 - 2016-08-19 00:51 - 05258248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2016-11-27 04:42 - 2016-08-19 00:51 - 00023696 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2016-11-27 00:34 - 2016-08-18 01:13 - 00000000 ____D C:\Windows10Upgrade
2016-11-26 23:44 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-11-26 23:29 - 2016-07-06 18:20 - 00009612 _____ C:\CYGWIN_SYSLOG.TXT
2016-11-25 03:26 - 2016-09-15 23:38 - 00000000 ____D C:\Users\Thorsten\Desktop\Cydia
2016-11-14 18:19 - 2016-04-21 21:16 - 00000000 ____D C:\Users\Thorsten\Documents\Outlook-Dateien
2016-11-14 04:00 - 2016-08-18 01:13 - 00000719 _____ C:\Users\Thorsten\Desktop\Windows 10-Upgrade-Assistent.lnk

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\Thorsten\NTUSER - Kopie.DAT
C:\Users\Thorsten\WDMyCloud_win.exe
C:\Users\totti\NTUSER (2).DAT


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2016-12-09 19:38

==================== Ende von FRST.txt ============================
         


Alt 12.12.2016, 17:39   #21
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? - Standard

Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?



Code:
ATTFilter
Administrator (S-1-5-21-2586767532-3616519997-416612805-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2586767532-3616519997-416612805-503 - Limited - Disabled)
Gast (S-1-5-21-2586767532-3616519997-416612805-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2586767532-3616519997-416612805-1005 - Limited - Enabled)
jenny (S-1-5-21-2586767532-3616519997-416612805-1002 - Limited - Disabled)
Thorsten (S-1-5-21-2586767532-3616519997-416612805-1001 - Limited - Enabled) => C:\Users\Thorsten
totti (S-1-5-21-2586767532-3616519997-416612805-1006 - Administrator - Enabled) => C:\Users\totti
ttjh1 (S-1-5-21-2586767532-3616519997-416612805-1003 - Administrator - Enabled) => C:\Users\ttjh1
         
Diese Benutzerkonten sind alle bekannt?
__________________
--> Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?

Antwort

Themen zu Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?
administrator, asus, besitzer, bonjour, computer, defender, desktop, e-mail, explorer, installation, mozilla, nvidia, prozesse, realtek, registry, router, rundll, scan, server, services.exe, software, super, svchost.exe, system, usb, windows, windowsapps, winlogon.exe




Ähnliche Themen: Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?


  1. Shrew Soft VPN-Client plötzlich als neues Benutzerkonto aufgetaucht
    Plagegeister aller Art und deren Bekämpfung - 01.09.2016 (4)
  2. Email Account gehackt?
    Plagegeister aller Art und deren Bekämpfung - 29.08.2016 (3)
  3. Email account gehackt
    Plagegeister aller Art und deren Bekämpfung - 16.03.2016 (1)
  4. Unbekanntes Benutzerkonto, Exe Dateien manipuliert Win 10
    Log-Analyse und Auswertung - 06.01.2016 (11)
  5. unbekanntes Benutzerkonto läßt sich nicht löschen
    Plagegeister aller Art und deren Bekämpfung - 11.12.2015 (12)
  6. Microsoftkonto deinstallieren bzw. wieder auf lokales Konto umstellen
    Alles rund um Windows - 03.12.2015 (0)
  7. Email gehackt! aquilain.com?
    Plagegeister aller Art und deren Bekämpfung - 25.09.2015 (1)
  8. Email Account gehackt: Email Versand an meine Kontakte mit meinem Namen, aber anderer Email Adresse.
    Log-Analyse und Auswertung - 29.07.2015 (3)
  9. Email gehackt
    Plagegeister aller Art und deren Bekämpfung - 03.06.2015 (2)
  10. Windows 7: eBay und eMail "gehackt" - Keine Antivirus Software
    Plagegeister aller Art und deren Bekämpfung - 02.01.2015 (5)
  11. Email-Konto gehackt?
    Plagegeister aller Art und deren Bekämpfung - 02.06.2014 (2)
  12. Email-Konto gehackt?
    Plagegeister aller Art und deren Bekämpfung - 16.05.2014 (1)
  13. Unbekanntes Symbol - verschwindet plötzlich
    Plagegeister aller Art und deren Bekämpfung - 11.04.2014 (9)
  14. Vista 64bit Home Basic unbekanntes Benutzerkonto
    Alles rund um Windows - 18.08.2013 (1)
  15. Email gehackt und merkwürdiges windows update mit Registryänderung?
    Log-Analyse und Auswertung - 08.03.2013 (27)
  16. Email gehackt
    Mülltonne - 29.12.2008 (5)
  17. MSN Wurm? plötzlich neues Benutzerkonto pw-geschützt...PC-Spuk - Hier mein Log
    Log-Analyse und Auswertung - 27.06.2008 (4)

Zum Thema Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? - Code: Alles auswählen Aufklappen ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-12-2016 durchgeführt von totti (10-12-2016 20:40:48) Run:1 Gestartet von C:\Users\totti\Downloads Geladene Profile: Thorsten & ttjh1 & totti - Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?...
Archiv
Du betrachtest: Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.