![]() |
|
Log-Analyse und Auswertung: Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? ich bin etwas verzweifelt. Habe vor ein paar Tagen Win10 neu aufgesetzt. Mein Benutzerkonto wurde wie immer angelegt. Heute habe ich festgestellt, dass meine Windowsanmeldung unter einem mir unbekannten Namen und E-Mail Adresse erfolgt. Bei der Überprüfung der Benutzerkonten musste ich feststellen, das mein angelegtes Konto (mein Bild, meine Zuriffe auf Dateien usw.) anscheinend einen fremden Besitzer hat. "Leider" wird der PC von meiner Frau und Kind mitbenutzt. Ich kann daher nicht genau sagen wann es passiert ist. Ist bei mir jetzt ALLES gehackt ? Hier meine Logfiles: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 05-12-2016 durchgeführt von totti (Administrator) auf HOME-PC (05-12-2016 23:05:16) Gestartet von C:\Users\totti\Downloads Geladene Profile: totti (Verfügbare Profile: Thorsten & ttjh1 & totti) Platform: Windows 10 Pro Version 1607 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Edge) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.25\aaHMSvc.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Windows\System32\snmp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe () C:\Program Files (x86)\ASUS\ASUS ROG Connect Plus\RC TweakIt Server\AsBclk.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotifyServer.exe () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe () C:\Program Files (x86)\ASUS\Front Base Driver\WBoxTT.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr64.exe () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNoticeMonitor.exe () C:\Program Files (x86)\ASUS\AI Suite III\Push Notice\PushNotify_PCCtrl.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe () C:\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\AsPowerBar.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe (Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (SAVITECH) C:\Program Files (x86)\SAVITECH\SVLoadSense\SVLoadSense.exe () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2Svc32.exe () C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\x64\SS2Svc64.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Sync\App\WDSyncService.exe (ESET) C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7466.41227.0_x64__8wekyb3d8bbwe\HxMail.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7466.41227.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe () C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [1735288 2016-09-30] (Logitech, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843784 2016-11-27] (Realtek Semiconductor) HKLM\...\Run: [SVLoadSense] => c:\Program Files (x86)\SAVITECH\SVLoadSense\SVLoadSense.exe [1762000 2015-09-21] (SAVITECH) HKLM\...\Run: [SS2UILauncher] => C:\Program Files\ASUSTeKcomputer.Inc\SS2\UserInterface\SS2UILauncher.exe [557072 2016-08-12] () HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.) HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-02-12] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] => C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2013-01-28] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [AO Link Server] => C:\Program Files (x86)\ASUS\AI Suite III\Mobo Connect\ALRun.exe -start HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21384 2016-04-15] (Western Digital Technologies, Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{278623a9-5409-4fd0-84f9-306d087989c8}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{33feedbb-de7b-4bc4-8b69-96b9e6bac0b6}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{6abf8ccf-8799-4d9f-85cf-650277434338}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-27] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-27] (Oracle Corporation) FireFox: ======== FF DefaultProfile: t1674hax.default FF ProfilePath: C:\Users\totti\AppData\Roaming\Mozilla\Firefox\Profiles\t1674hax.default [2016-12-05] FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-27] (Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-27] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-27] (Google Inc.) Chrome: ======= CHR Profile: C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default [2016-12-05] CHR Extension: (Google Präsentationen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-04] CHR Extension: (Google Docs) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-04] CHR Extension: (Google Drive) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-04] CHR Extension: (YouTube) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-04] CHR Extension: (Google Tabellen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-04] CHR Extension: (Google Docs Offline) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-04] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-04] CHR Extension: (Google Mail) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-04] CHR Extension: (Chrome Media Router) - C:\Users\totti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-04] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.) R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2016-11-27] () R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.25\aaHMSvc.exe [963544 2016-08-05] (ASUSTeK Computer Inc.) R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2016-11-27] () [Datei ist nicht signiert] R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe [419288 2016-05-27] (ASUSTeK Computer Inc.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation) R2 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation) R2 SNMP; C:\WINDOWS\System32\snmp.exe [53248 2016-11-28] (Microsoft Corporation) R2 SNMP; C:\WINDOWS\SysWOW64\snmp.exe [47104 2016-11-28] (Microsoft Corporation) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10216688 2016-11-28] (TeamViewer GmbH) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [302968 2015-02-12] (Western Digital Technologies, Inc.) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [18232 2016-08-02] (Intel(R) Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.) R3 AndroidAFD; C:\Windows\SysWow64\drivers\AndroidAFDx64.sys [22192 2015-10-19] (ASUSTek Computer Inc.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2016-11-27] () S0 asstahci64; C:\WINDOWS\System32\drivers\asstahci64.sys [88936 2015-06-17] (Asmedia Technology) R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2016-11-27] () R3 ASUSfilter; C:\WINDOWS\System32\drivers\ASUSfilter.sys [48384 2013-03-28] (MCCI Corporation) R3 ASUSfilter; C:\Windows\SysWOW64\drivers\ASUSfilter.sys [46152 2016-11-27] (MCCI Corporation) S3 ASUSstpt; C:\WINDOWS\System32\drivers\ASUSstpt.sys [27392 2013-03-28] (MCCI Corporation) S3 ASUSumsc; C:\WINDOWS\System32\drivers\ASUSumsc.sys [151808 2013-03-28] (MCCI Corporation) S3 ASUSxpsp; C:\WINDOWS\System32\drivers\ASUSxpsp.sys [28416 2013-03-28] (MCCI Corporation) S3 DSI_SiUSBXp_3_1; C:\WINDOWS\system32\drivers\DSI_SiUSBXp_3_1.sys [16384 2007-09-06] (Silicon Laboratories) S3 dtultrascsibus; C:\WINDOWS\System32\drivers\dtultrascsibus.sys [30264 2016-04-17] (Disc Soft Ltd) S3 dtultrausbbus; C:\WINDOWS\System32\drivers\dtultrausbbus.sys [47672 2016-04-17] (Disc Soft Ltd) R3 e1dexpress; C:\WINDOWS\system32\DRIVERS\e1d65x64.sys [530416 2015-06-18] (Intel Corporation) S2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [29264 2016-06-09] (Intel Corporation) R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [24824 2016-07-12] (ASUSTeK Computer Inc.) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-12-05] (Malwarebytes) R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R1 SvThLSNS; c:\Program Files (x86)\SAVITECH\SVLoadSense\x64\SvThLSNS.sys [15184 2015-09-21] (Windows (R) Win 7 DDK provider) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) S3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation) S3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-09-21] (Intel Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-05 23:05 - 2016-12-05 23:05 - 00016899 _____ C:\Users\totti\Downloads\FRST.txt 2016-12-05 23:04 - 2016-12-05 23:05 - 02419712 _____ (Farbar) C:\Users\totti\Downloads\FRST64.exe 2016-12-05 22:59 - 2016-12-05 22:59 - 00000000 ___HD C:\OneDriveTemp 2016-12-05 22:30 - 2016-12-05 22:30 - 00101330 _____ C:\Users\Thorsten\Desktop\FRST.txt 2016-12-05 22:30 - 2016-12-05 22:30 - 00033068 _____ C:\Users\Thorsten\Desktop\Addition.txt 2016-12-05 22:29 - 2016-12-05 23:05 - 00000000 ____D C:\FRST 2016-12-05 22:29 - 2016-12-05 22:30 - 00101327 _____ C:\Users\Thorsten\Downloads\FRST.txt 2016-12-05 22:29 - 2016-12-05 22:30 - 00033065 _____ C:\Users\Thorsten\Downloads\Addition.txt 2016-12-05 22:28 - 2016-12-05 22:29 - 02419712 _____ (Farbar) C:\Users\Thorsten\Downloads\FRST64.exe 2016-12-05 20:19 - 2016-12-05 20:19 - 00000000 ____D C:\Program Files (x86)\ESET 2016-12-05 20:18 - 2016-12-05 20:18 - 00001741 _____ C:\22222222222222.txt 2016-12-05 20:17 - 2016-12-05 20:17 - 00002309 _____ C:\1111111111111111.txt 2016-12-05 19:02 - 2016-12-05 20:19 - 02870984 _____ (ESET) C:\Users\totti\Downloads\esetsmartinstaller_deu.exe 2016-12-05 18:58 - 2016-12-05 22:59 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-12-05 18:58 - 2016-12-05 18:58 - 00001171 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-12-05 18:58 - 2016-12-05 18:58 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-12-05 18:58 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2016-12-05 18:58 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-12-05 18:58 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-12-05 18:57 - 2016-12-05 18:57 - 22851472 _____ (Malwarebytes ) C:\Users\totti\Downloads\mbam-setup-2.2.1.1043.exe 2016-12-05 18:45 - 2016-12-05 18:45 - 00000000 ____D C:\Users\totti\AppData\Roaming\Macromedia 2016-12-05 18:38 - 2016-12-05 20:15 - 00000000 ____D C:\Users\totti\AppData\LocalLow\Mozilla 2016-12-05 18:38 - 2016-12-05 18:44 - 00000000 ____D C:\Users\totti\AppData\Local\Mozilla 2016-12-05 18:38 - 2016-12-05 18:38 - 00000000 ____D C:\Users\totti\AppData\Roaming\Mozilla 2016-12-04 23:49 - 2016-12-04 23:49 - 00000000 ____D C:\Users\totti\AppData\Local\PeerDistRepub 2016-12-04 23:07 - 2016-12-04 23:07 - 00030100 _____ C:\Users\totti\Downloads\entschuld13.pdf 2016-12-04 22:39 - 2016-12-04 22:39 - 00001359 _____ C:\Users\Public\Desktop\EaseUS Todo PCTrans.lnk 2016-12-04 22:39 - 2016-12-04 22:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo PCTrans 2016-12-04 22:39 - 2016-12-04 22:39 - 00000000 ____D C:\Program Files (x86)\EaseUS 2016-12-04 22:38 - 2016-12-05 18:44 - 00000000 ____D C:\Users\totti\AppData\Local\MicrosoftEdge 2016-12-04 22:38 - 2016-12-04 22:39 - 05335456 _____ (EaseUS ) C:\Users\totti\Downloads\pctrans.exe 2016-12-04 22:21 - 2016-12-04 21:37 - 02359296 ____H C:\Users\totti\NTUSER (2).DAT 2016-12-04 22:21 - 2016-12-04 21:37 - 02359296 ____H C:\Users\Thorsten\NTUSER - Kopie.DAT 2016-12-04 19:28 - 2016-12-04 19:28 - 00000000 ____D C:\Users\totti\AppData\Roaming\Intel Corporation 2016-12-04 19:27 - 2016-12-05 22:59 - 00000000 ___RD C:\Users\totti\OneDrive 2016-12-04 19:27 - 2016-12-04 19:28 - 00002383 _____ C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Skype 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Logishrd 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Roaming\Apple Computer 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Local\Western_Digital_Technolog 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Local\SS22.2.28 2016-12-04 19:27 - 2016-12-04 19:27 - 00000000 ____D C:\Users\totti\AppData\Local\Comms 2016-12-04 19:26 - 2016-12-05 03:33 - 00000000 ____D C:\Users\totti 2016-12-04 19:26 - 2016-12-04 20:28 - 00000000 ____D C:\Users\totti\AppData\Local\Packages 2016-12-04 19:26 - 2016-12-04 19:41 - 00000000 ____D C:\Users\totti\AppData\Local\Google 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Vorlagen 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Startmenü 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Netzwerkumgebung 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Lokale Einstellungen 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Eigene Dateien 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Druckumgebung 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Videos 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Musik 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Documents\Eigene Bilder 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Local\Verlauf 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\AppData\Local\Anwendungsdaten 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 _SHDL C:\Users\totti\Anwendungsdaten 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Roaming\Adobe 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\VirtualStore 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\TileDataLayer 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\Publishers 2016-12-04 19:26 - 2016-12-04 19:26 - 00000000 ____D C:\Users\totti\AppData\Local\ConnectedDevicesPlatform 2016-12-04 19:26 - 2016-11-27 00:07 - 00000020 ___SH C:\Users\totti\ntuser.ini 2016-12-04 01:23 - 2016-12-04 01:23 - 00000000 ____D C:\Program Files (x86)\Hercules 2016-12-04 01:22 - 2016-12-04 01:23 - 31550240 _____ (Hercules) C:\Users\Thorsten\Downloads\HWNU-300_V3.7.exe 2016-12-04 00:30 - 2016-12-04 00:30 - 04640844 _____ C:\Users\Thorsten\Downloads\WLR-5100v1001-firmware-v30.zip 2016-12-04 00:30 - 2016-12-04 00:30 - 02952963 _____ C:\Users\Thorsten\Downloads\WLR-5100v1001-Full-Manual.pdf 2016-12-04 00:27 - 2016-12-04 00:27 - 02952963 _____ C:\Users\Thorsten\Downloads\manual (2).pdf 2016-12-03 18:32 - 2016-12-03 18:32 - 00000000 ____D C:\Users\Thorsten\AppData\Local\TeamViewer 2016-12-02 23:38 - 2016-12-04 19:15 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-12-02 23:38 - 2016-12-03 18:38 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\TeamViewer 2016-12-02 23:38 - 2016-12-02 23:38 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk 2016-12-02 23:38 - 2016-12-02 23:38 - 00001100 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk 2016-12-02 23:35 - 2015-06-22 12:20 - 00000000 ____D C:\Users\Thorsten\Downloads\DIR-825_fw_revb_210b01_ALL_multi_20150609 2016-12-02 23:34 - 2016-12-02 23:37 - 12877352 _____ (TeamViewer GmbH) C:\Users\Thorsten\Downloads\TeamViewer_Setup_de-agkp.exe 2016-12-02 23:26 - 2016-12-02 23:26 - 05286401 _____ C:\Users\Thorsten\Downloads\DIR-825_fw_revb_210b01_ALL_multi_20150609.zip 2016-12-02 23:23 - 2016-12-02 23:23 - 00029312 _____ C:\Users\Thorsten\Downloads\config.bin 2016-12-02 21:07 - 2016-12-02 21:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\ElevatedDiagnostics 2016-12-02 19:13 - 2016-12-02 19:13 - 00720417 _____ C:\Users\Thorsten\Downloads\Anleitung_WLAN-Router_als_Accesspoint_mit_Hitron_oder_CiscoEPC3208_Kabelmodem.pdf 2016-12-02 02:36 - 2016-12-02 02:36 - 1214701263 _____ C:\WINDOWS\MEMORY.DMP 2016-12-02 02:36 - 2016-12-02 02:36 - 00586244 _____ C:\WINDOWS\Minidump\120216-8265-01.dmp 2016-12-02 02:36 - 2016-12-02 02:36 - 00000000 ____D C:\WINDOWS\Minidump 2016-12-02 01:51 - 2016-12-02 01:51 - 00000000 ____D C:\Users\ttjh1\AppData\Local\PeerDistRepub 2016-12-01 21:31 - 2016-12-01 21:31 - 00166225 _____ C:\Users\Thorsten\Downloads\AVM-Merry-Christmas_2016.zip 2016-12-01 02:33 - 2016-12-01 02:33 - 04851072 _____ C:\Users\Thorsten\Downloads\cfosspeed-v1020.exe 2016-11-30 12:10 - 2016-11-30 12:10 - 00000000 ____D C:\ProgramData\Trymedia 2016-11-30 12:10 - 2016-11-30 12:10 - 00000000 ____D C:\ProgramData\GoBit Games 2016-11-30 10:12 - 2016-11-30 10:12 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Macromedia 2016-11-30 10:12 - 2016-11-30 10:12 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Comms 2016-11-30 10:11 - 2016-11-30 10:11 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Intel Corporation 2016-11-30 10:10 - 2016-12-01 19:13 - 00000000 ____D C:\Users\ttjh1\AppData\Local\ConnectedDevicesPlatform 2016-11-30 10:10 - 2016-11-30 16:32 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Google 2016-11-30 10:10 - 2016-11-30 11:11 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Packages 2016-11-30 10:10 - 2016-11-30 10:11 - 00002383 _____ C:\Users\ttjh1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-11-30 10:10 - 2016-11-30 10:10 - 00000020 ___SH C:\Users\ttjh1\ntuser.ini 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Skype 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Logishrd 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Apple Computer 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Roaming\Adobe 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Western_Digital_Technolog 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\VirtualStore 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\TileDataLayer 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\SS22.2.28 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\Publishers 2016-11-30 10:10 - 2016-11-30 10:10 - 00000000 ____D C:\Users\ttjh1\AppData\Local\MicrosoftEdge 2016-11-30 03:08 - 2016-11-30 03:28 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Apple Computer 2016-11-30 03:08 - 2016-11-30 03:08 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2016-11-30 03:08 - 2016-11-30 03:08 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apple Computer 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apple 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Apple Computer 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\iTunes 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\iPod 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\Common Files\Apple 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files\Bonjour 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files (x86)\Bonjour 2016-11-30 03:08 - 2016-11-30 03:08 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2016-11-30 03:04 - 2016-11-30 03:07 - 177311560 _____ (Apple Inc.) C:\Users\Thorsten\Downloads\iTunes6464Setup.exe 2016-11-30 00:21 - 2016-11-30 00:21 - 00004566 _____ C:\Users\Thorsten\Downloads\oscam_2016-11-30_0021_oscam.log.tgz 2016-11-29 21:28 - 2016-11-29 21:28 - 00000582 _____ C:\Users\Thorsten\Downloads\Enable_Num_Lock_on_Sign-in_screen.reg 2016-11-29 02:32 - 2016-11-29 02:32 - 00003344 _____ C:\WINDOWS\System32\Tasks\SamsungMagician 2016-11-29 02:32 - 2016-11-29 02:32 - 00001298 _____ C:\Users\Public\Desktop\Samsung Magician.lnk 2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\ProgramData\Samsung 2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2016-11-29 02:32 - 2016-11-29 02:32 - 00000000 ____D C:\Program Files (x86)\Samsung 2016-11-29 02:31 - 2016-05-13 08:52 - 19226728 _____ (Samsung Electronics ) C:\Users\Thorsten\Downloads\Samsung_Magician_Setup_v497.exe 2016-11-29 02:30 - 2016-11-29 02:31 - 18946704 _____ C:\Users\Thorsten\Downloads\Samsung_Magician_Setup_v497.zip 2016-11-29 01:41 - 2016-11-29 01:41 - 00629880 _____ C:\Users\Thorsten\Downloads\oscam-emu-mips-freetz11281-fritz73xxOS62-webif-libusb_st 2016-11-29 01:36 - 2016-11-29 01:36 - 00213602 _____ C:\Users\Thorsten\Downloads\list_smargo-1 (3).20-emu11232-mips-freetz-linux-uclibc-libusb 2016-11-29 00:13 - 2016-11-29 00:13 - 04083028 _____ C:\Users\Thorsten\Downloads\WDAccess_1.4.5949.29996.zip 2016-11-29 00:13 - 2016-11-29 00:13 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Western_Digital_Technolog 2016-11-29 00:11 - 2016-11-29 00:11 - 08497626 _____ C:\Users\Thorsten\Downloads\WDSync_1.3.5949.26210.zip 2016-11-28 23:48 - 2016-11-28 23:48 - 00000000 ____D C:\Users\Thorsten\Downloads\DIP5_10360 2016-11-28 23:43 - 2016-11-28 23:43 - 00000000 ____D C:\WINDOWS\LastGood.Tmp 2016-11-28 23:43 - 2016-11-28 23:28 - 00404752 _____ (Intel Corporation) C:\WINDOWS\system32\PROUnstl.exe 2016-11-28 23:43 - 2016-11-28 23:28 - 00001904 ____N C:\WINDOWS\system32\SetupBD.din 2016-11-28 23:40 - 2016-11-28 23:40 - 00000000 ____D C:\Users\Thorsten\Downloads\ROGConnectPlus_Win7-81-10_V10030 2016-11-28 23:40 - 2015-06-05 09:37 - 00192512 _____ (ASUSTeK Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\UpdateHelper.dll 2016-11-28 23:39 - 2016-11-28 23:39 - 00001769 _____ C:\WINDOWS\Language_trs.ini 2016-11-28 23:39 - 2016-11-28 23:37 - 00011832 _____ C:\WINDOWS\SysWOW64\Drivers\AsInsHelp64.sys 2016-11-28 23:39 - 2016-11-28 23:37 - 00010216 _____ C:\WINDOWS\SysWOW64\Drivers\AsInsHelp32.sys 2016-11-28 23:37 - 2016-11-28 23:37 - 00000000 ____D C:\Users\Thorsten\Downloads\FRONTBASE-10117 2016-11-28 23:28 - 2016-11-28 23:28 - 00316736 _____ (Intel Corporation) C:\WINDOWS\system32\PRONtObj.dll 2016-11-28 23:28 - 2016-11-28 23:28 - 00155192 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iANSW60e.sys 2016-11-28 23:27 - 2016-11-28 23:27 - 00000000 ____D C:\Users\Thorsten\Downloads\Intel_Gigabit_Ethernet_Win7-81_V20230010_Win10_V20240010 2016-11-28 23:24 - 2016-11-28 23:43 - 00000000 ____D C:\Program Files\Intel 2016-11-28 23:24 - 2016-11-28 23:24 - 02037236 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ____D C:\Users\Thorsten\Intel 2016-11-28 23:24 - 2016-11-28 23:24 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Intel Corporation 2016-11-28 23:23 - 2016-11-28 23:23 - 00002056 _____ C:\Users\Public\Desktop\ASUS Boot Setting.lnk 2016-11-28 23:23 - 2016-11-28 23:23 - 00000000 ____D C:\Users\Thorsten\Downloads\ASUS_BootSetting_Win7-81-10_VER10022 2016-11-27 16:52 - 2016-11-27 17:02 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0 (2).exe 2016-11-27 16:15 - 2016-12-04 16:38 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4564E7FE-E9AE-4766-8A69-A4964C928904} 2016-11-27 16:15 - 2016-11-27 16:15 - 02722395 _____ C:\Users\Thorsten\Downloads\jperf-2.0.2.zip 2016-11-27 16:15 - 2016-11-27 16:15 - 00000000 ____D C:\Users\Thorsten\Desktop\jperf-2.0.2 2016-11-27 16:12 - 2016-11-27 16:12 - 00606026 _____ C:\Users\Thorsten\Downloads\iperf-master.zip 2016-11-27 16:12 - 2016-11-27 16:12 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Sun 2016-11-27 16:11 - 2016-11-27 16:15 - 00000000 ____D C:\ProgramData\Oracle 2016-11-27 16:11 - 2016-11-27 16:11 - 00737344 _____ (Oracle Corporation) C:\Users\Thorsten\Downloads\JavaSetup8u111.exe 2016-11-27 16:11 - 2016-11-27 16:11 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-11-27 16:11 - 2016-11-27 16:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-11-27 16:11 - 2016-11-27 16:11 - 00000000 ____D C:\Program Files (x86)\Java 2016-11-27 16:09 - 2016-12-05 21:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-11-27 16:09 - 2016-12-05 21:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-11-27 16:09 - 2016-11-27 16:16 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Mozilla 2016-11-27 16:09 - 2016-11-27 16:10 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Mozilla 2016-11-27 16:09 - 2016-11-27 16:09 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-11-27 16:09 - 2016-11-27 16:09 - 00001216 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-11-27 16:08 - 2016-11-27 16:09 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0 (1).exe 2016-11-27 16:05 - 2016-11-27 16:05 - 00248583 _____ C:\Users\Thorsten\Downloads\iperf-2.0.5.tar.gz 2016-11-27 15:42 - 2016-11-29 00:00 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Wireshark 2016-11-27 15:22 - 2016-11-27 15:35 - 49242104 _____ (Wireshark development team) C:\Users\Thorsten\Downloads\Wireshark-win64-2.2.2.exe 2016-11-27 15:16 - 2016-11-27 15:16 - 02970395 _____ C:\Users\Thorsten\Downloads\cacti-0.8.8h.zip 2016-11-27 14:29 - 2016-11-27 14:29 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps 2016-11-27 14:13 - 2016-11-27 14:13 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2016-11-27 04:53 - 2016-11-27 04:53 - 00000000 ____D C:\Users\Thorsten\Downloads\Asmedia_USB3_V116351 2016-11-27 04:52 - 2016-11-27 14:14 - 00002685 _____ C:\Users\Public\Desktop\ASUS(R) Intel(R) Extreme Tuning Utility.lnk 2016-11-27 04:52 - 2016-11-27 14:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS(R) Intel(R) Extreme Tuning Utility 2016-11-27 04:52 - 2016-11-27 14:13 - 00000000 ____D C:\WINDOWS\System32\Tasks\Intel 2016-11-27 04:52 - 2016-11-27 04:54 - 00000000 ____D C:\Users\Thorsten\AppData\Local\SS22.2.28 2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2016-11-27 04:52 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2016-11-27 04:52 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll 2016-11-27 04:52 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll 2016-11-27 04:52 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll 2016-11-27 04:52 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll 2016-11-27 04:50 - 2016-11-29 00:13 - 00000000 ____D C:\ProgramData\Package Cache 2016-11-27 04:50 - 2016-11-27 04:50 - 00003214 _____ C:\WINDOWS\System32\Tasks\SS2UILauncherRun 2016-11-27 04:50 - 2016-11-27 04:50 - 00003202 _____ C:\WINDOWS\System32\Tasks\SS2Svc64Run 2016-11-27 04:50 - 2016-11-27 04:50 - 00003194 _____ C:\WINDOWS\System32\Tasks\SS2Svc32Run 2016-11-27 04:50 - 2016-11-27 04:50 - 00001338 _____ C:\Users\Public\Desktop\Sonic Studio.lnk 2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonic Suite 2 2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\Program Files\ASUSTeKcomputer.Inc 2016-11-27 04:50 - 2016-11-27 04:50 - 00000000 ____D C:\Program Files (x86)\SAVITECH 2016-11-27 04:50 - 2016-11-27 04:42 - 72520720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat 2016-11-27 04:50 - 2016-11-27 04:42 - 06879938 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT 2016-11-27 04:50 - 2016-11-27 04:42 - 05593624 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 03283248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 03203592 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 02895104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl 2016-11-27 04:50 - 2016-11-27 04:42 - 02073096 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 01360528 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 01003864 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00689888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00192992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00118600 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll 2016-11-27 04:50 - 2016-11-27 04:42 - 00105312 _____ C:\WINDOWS\system32\audioLibVc.dll 2016-11-27 04:50 - 2016-11-27 04:41 - 00003008 ____N C:\WINDOWS\system32\Drivers\DTSU2P.DAT 2016-11-27 04:48 - 2016-11-27 04:48 - 00000000 ____D C:\Program Files\Realtek 2016-11-27 04:47 - 2016-11-27 04:41 - 02838232 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll 2016-11-27 04:46 - 2016-11-27 04:46 - 00000000 _____ C:\WINDOWS\SysWOW64\Drivers\1043_ASUSTeK_MAXIMUS VIII RANGER.alu 2016-11-27 04:42 - 2016-11-27 04:50 - 00000000 ___HD C:\Program Files (x86)\Temp 2016-11-27 04:42 - 2016-11-27 04:42 - 00000000 ____D C:\Program Files (x86)\Realtek 2016-11-27 04:41 - 2016-12-05 22:59 - 01048576 _____ C:\WINDOWS\PE_Rom.dll 2016-11-27 04:41 - 2016-11-27 04:41 - 00000000 ____D C:\Users\Thorsten\Downloads\V7904_20160815_WHQL_DTS_StudioSound_SonicSuite_2228 2016-11-27 04:41 - 2016-07-12 19:04 - 00024824 ____N (ASUSTeK Computer Inc.) C:\WINDOWS\system32\Drivers\IOMap64.sys 2016-11-27 04:17 - 2016-11-28 23:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2016-11-27 04:17 - 2016-11-27 04:17 - 00000000 ____D C:\Program Files\ASUS 2016-11-27 04:17 - 2016-11-27 04:17 - 00000000 ____D C:\Program Files (x86)\ASM104xUSB3 2016-11-27 04:17 - 2016-11-27 04:15 - 00046152 _____ (MCCI Corporation) C:\WINDOWS\SysWOW64\Drivers\ASUSFILTER.sys 2016-11-27 04:17 - 2016-11-27 04:15 - 00014464 _____ C:\WINDOWS\SysWOW64\Drivers\AsUpIO.sys 2016-11-27 04:16 - 2016-12-04 01:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-11-27 04:16 - 2016-11-28 23:49 - 00000000 ____D C:\WINDOWS\System32\Tasks\ASUS 2016-11-27 04:16 - 2016-11-28 23:24 - 00000000 ____D C:\ProgramData\Intel 2016-11-27 04:16 - 2016-11-27 04:52 - 00000000 ____D C:\Program Files (x86)\Intel 2016-11-27 04:16 - 2015-10-19 17:22 - 00022192 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\AndroidAFDx64.sys 2016-11-27 04:16 - 2013-01-28 15:58 - 00014848 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\AiChargerPlus.sys 2016-11-27 04:15 - 2016-11-28 23:40 - 00000000 ____D C:\Program Files (x86)\ASUS 2016-11-27 04:15 - 2016-11-27 04:15 - 00028672 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\AsIO.dll 2016-11-27 04:15 - 2016-11-27 04:15 - 00015232 _____ C:\WINDOWS\SysWOW64\Drivers\AsIO.sys 2016-11-27 04:15 - 2016-11-27 04:15 - 00000000 ____D C:\Users\Thorsten\Downloads\AISuite3_Win7-81-10_MaxVIII_Series_V10130 2016-11-27 04:14 - 2016-11-28 23:50 - 00000000 ____D C:\ProgramData\ASUS 2016-11-27 04:13 - 2016-11-27 04:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2016-11-27 04:13 - 2016-11-27 04:13 - 00000000 ____D C:\Program Files\7-Zip 2016-11-27 04:11 - 2016-11-27 04:14 - 122808649 _____ C:\Users\Thorsten\Downloads\DIP5_10360.zip 2016-11-27 04:11 - 2016-11-27 04:12 - 37822895 _____ C:\Users\Thorsten\Downloads\ASUS_XTU_V612208.zip 2016-11-27 04:06 - 2016-11-27 04:06 - 00001806 _____ C:\Users\Public\Desktop\HDClone.lnk 2016-11-27 04:06 - 2016-11-27 04:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDClone 6 Free Edition 2016-11-27 04:05 - 2016-11-27 04:06 - 00000000 ____D C:\Program Files (x86)\HDClone 6 Free Edition 2016-11-27 02:54 - 2016-11-27 02:54 - 201326592 _____ C:\Users\Thorsten\Downloads\clonezilla-live-2.5.0-5-amd64.iso 2016-11-27 02:33 - 2016-11-27 02:33 - 00000000 ____D C:\Program Files\Common Files\Logishrd 2016-11-27 02:19 - 2016-11-27 02:19 - 141011376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-11-27 02:19 - 2016-11-27 02:19 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-11-27 02:19 - 2016-11-27 02:09 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2016-11-27 02:16 - 2016-11-27 02:20 - 71601392 _____ C:\Users\Thorsten\Downloads\mc_windows_setup (1).exe 2016-11-27 01:13 - 2016-11-30 03:08 - 00000000 ____D C:\ProgramData\Apple 2016-11-27 01:13 - 2016-11-29 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital 2016-11-27 01:13 - 2016-11-29 00:11 - 00000000 ____D C:\ProgramData\Western Digital 2016-11-27 01:13 - 2016-11-29 00:11 - 00000000 ____D C:\Program Files (x86)\Western Digital 2016-11-27 01:13 - 2016-11-27 01:13 - 00001226 _____ C:\Users\Public\Desktop\WD My Cloud.lnk 2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\Downloads\WD_Quick_View_Setup_for_Windows 2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Macromedia 2016-11-27 01:13 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\com.wd.WDMyCloud 2016-11-27 01:12 - 2016-11-27 01:13 - 63849440 _____ C:\Users\Thorsten\Downloads\WDMyCloud_win.exe 2016-11-27 01:12 - 2016-11-27 01:13 - 04341113 _____ C:\Users\Thorsten\Downloads\WD_Quick_View_Setup_for_Windows.zip 2016-11-27 01:09 - 2016-11-27 01:13 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Western Digital 2016-11-27 01:08 - 2016-11-27 02:23 - 00001130 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-11-27 01:08 - 2016-11-27 02:23 - 00001126 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-11-27 01:08 - 2016-11-27 01:17 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Google 2016-11-27 01:08 - 2016-11-27 01:09 - 71601392 _____ C:\Users\Thorsten\Downloads\mc_windows_setup.exe 2016-11-27 01:08 - 2016-11-27 01:08 - 01065376 _____ (Google Inc.) C:\Users\Thorsten\Downloads\ChromeSetup.exe 2016-11-27 01:08 - 2016-11-27 01:08 - 00004188 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-11-27 01:08 - 2016-11-27 01:08 - 00003956 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-11-27 01:08 - 2016-11-27 01:08 - 00002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-11-27 01:08 - 2016-11-27 01:08 - 00002324 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-11-27 01:08 - 2016-11-27 01:08 - 00000000 ____D C:\Program Files (x86)\Google 2016-11-27 00:43 - 2016-11-27 02:33 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Logitech 2016-11-27 00:43 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logitech 2016-11-27 00:43 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Deployment 2016-11-27 00:14 - 2016-11-27 00:59 - 00000000 ____D C:\Users\Thorsten\AppData\Local\MicrosoftEdge 2016-11-27 00:11 - 2016-11-27 02:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2016-11-27 00:11 - 2016-11-27 02:34 - 00000000 ____D C:\ProgramData\Logishrd 2016-11-27 00:11 - 2016-11-27 02:33 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Logishrd 2016-11-27 00:11 - 2016-11-27 02:33 - 00000000 ____D C:\Program Files\Logitech 2016-11-27 00:11 - 2016-11-27 00:11 - 00000000 ____D C:\Users\Thorsten\AppData\Local\PeerDistRepub 2016-11-27 00:10 - 2016-11-27 00:10 - 00003338 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task 2016-11-27 00:09 - 2016-11-27 00:10 - 00002392 _____ C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Skype 2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Comms 2016-11-27 00:09 - 2016-11-27 00:09 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2016-11-27 00:08 - 2016-11-27 00:08 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Publishers 2016-11-27 00:07 - 2016-12-02 02:58 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Packages 2016-11-27 00:07 - 2016-11-27 02:30 - 00000000 ____D C:\Users\Thorsten\AppData\Local\ConnectedDevicesPlatform 2016-11-27 00:07 - 2016-11-27 00:43 - 00000000 ____D C:\Users\Thorsten\AppData\Local\Apps\2.0 2016-11-27 00:07 - 2016-11-27 00:07 - 00000020 ___SH C:\Users\Thorsten\ntuser.ini 2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Roaming\Adobe 2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Local\VirtualStore 2016-11-27 00:07 - 2016-11-27 00:07 - 00000000 ____D C:\Users\Thorsten\AppData\Local\TileDataLayer 2016-11-26 23:55 - 2016-12-05 22:39 - 02390820 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Vorlagen 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Startmenü 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Eigene Dateien 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Druckumgebung 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\Default User 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Users\All Users 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Vorlagen 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Startmenü 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Dokumente 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten 2016-11-26 23:54 - 2016-11-26 23:54 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien 2016-11-26 23:53 - 2016-11-26 23:53 - 00017426 _____ C:\Users\Thorsten\Desktop\Entfernte Apps.html 2016-11-26 23:53 - 2016-11-26 23:53 - 00016796 _____ C:\Users\ttjh1\Desktop\Entfernte Apps.html 2016-11-26 23:53 - 2016-07-16 12:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2016-11-26 23:50 - 2016-12-04 22:21 - 00000000 ____D C:\Users\Thorsten 2016-11-26 23:50 - 2016-12-02 23:35 - 00000000 ____D C:\Users\ttjh1 2016-11-26 23:50 - 2016-11-27 04:50 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Vorlagen 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Startmenü 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Netzwerkumgebung 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Lokale Einstellungen 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Eigene Dateien 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Druckumgebung 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Local\Verlauf 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\AppData\Local\Anwendungsdaten 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\ttjh1\Anwendungsdaten 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Vorlagen 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Startmenü 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Netzwerkumgebung 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Lokale Einstellungen 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Eigene Dateien 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Druckumgebung 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Videos 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Musik 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Documents\Eigene Bilder 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Local\Verlauf 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\AppData\Local\Anwendungsdaten 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 _SHDL C:\Users\Thorsten\Anwendungsdaten 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____D C:\ProgramData\USOShared 2016-11-26 23:50 - 2016-11-26 23:50 - 00000000 ____D C:\ProgramData\NVIDIA 2016-11-26 23:49 - 2016-12-05 22:59 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2016-11-26 23:49 - 2016-12-05 22:35 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-11-26 23:49 - 2016-12-05 19:07 - 00198392 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-11-26 23:49 - 2016-11-26 23:49 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-11-26 23:49 - 2015-11-05 16:08 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 02554672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2016-11-26 23:49 - 2015-11-05 16:08 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2016-11-26 23:49 - 2015-11-05 16:08 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2016-11-26 23:49 - 2015-10-28 14:49 - 06027430 _____ C:\WINDOWS\system32\nvcoproc.bin 2016-11-26 23:48 - 2016-11-27 00:23 - 00000000 ____D C:\Windows.old 2016-11-26 23:48 - 2016-11-26 23:54 - 00000000 ___DC C:\WINDOWS\Panther 2016-11-26 23:48 - 2016-11-26 23:49 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2016-11-26 23:48 - 2016-11-26 23:48 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2016-11-26 23:48 - 2016-11-26 23:48 - 00000000 ____D C:\WINDOWS\InfusedApps 2016-11-26 23:47 - 2016-12-05 22:39 - 01092770 _____ C:\WINDOWS\system32\perfh007.dat 2016-11-26 23:47 - 2016-12-05 22:39 - 00247148 _____ C:\WINDOWS\system32\perfc007.dat 2016-11-26 23:47 - 2016-11-26 23:47 - 00305594 _____ C:\WINDOWS\system32\perfi007.dat 2016-11-26 23:47 - 2016-11-26 23:47 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\de 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\0409 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\winrm 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\WCN 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\slmgr 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\de 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\0409 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\Setup 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\OCR 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\DigitalLocker 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Reference Assemblies 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\MSBuild 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2016-11-26 23:47 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files (x86)\MSBuild 2016-11-26 23:46 - 2016-10-29 00:56 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-11-26 23:46 - 2016-10-29 00:56 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-11-26 23:45 - 2016-12-05 21:16 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-11-26 23:45 - 2016-12-05 20:30 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-11-26 23:45 - 2016-12-04 00:40 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-11-26 23:45 - 2016-12-03 20:00 - 00000000 ___HD C:\Program Files\WindowsApps 2016-11-26 23:45 - 2016-11-30 00:16 - 00000000 ____D C:\WINDOWS\rescache 2016-11-26 23:45 - 2016-11-29 00:13 - 00000000 ____D C:\WINDOWS\Registration 2016-11-26 23:45 - 2016-11-27 04:55 - 00000000 ____D C:\WINDOWS\appcompat 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\F12 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\dsc 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ___RD C:\Program Files\Windows Defender 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\SysWOW64\setup 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\setup 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\migwiz 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\Provisioning 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2016-11-26 23:45 - 2016-11-27 02:23 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2016-11-26 23:45 - 2016-11-27 02:22 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2016-11-26 23:45 - 2016-11-26 23:54 - 00000000 ____D C:\Program Files\Windows NT 2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 __RHD C:\Users\Public\Libraries 2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 ____D C:\WINDOWS\system32\spool 2016-11-26 23:45 - 2016-11-26 23:53 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2016-11-26 23:45 - 2016-11-26 23:52 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ___RD C:\WINDOWS\PrintDialog 2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ___RD C:\WINDOWS\MiracastView 2016-11-26 23:45 - 2016-11-26 23:50 - 00000000 ____D C:\WINDOWS\CSC 2016-11-26 23:45 - 2016-11-26 23:49 - 00000000 ____D C:\WINDOWS\Help 2016-11-26 23:45 - 2016-11-26 23:48 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Com 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\SystemApps 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\MUI 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\system32\Com 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\IME 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Common Files\System 2016-11-26 23:45 - 2016-11-26 23:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\Program Files\Windows Sidebar 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 __RSD C:\WINDOWS\Media 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\system32\Nui 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\system32\Configuration 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___RD C:\WINDOWS\Offline Web Pages 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Web 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Vss 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\tracing 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\TAPI 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\ras 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SystemResources 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\WinMetadata 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\winevt 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ras 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ProximityToast 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\PointOfService 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\MsDtc 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Ipmi 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\inetsrv 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\IME 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\icsxml 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\ias 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\downlevel 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\DDFs 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\config\Journal 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\Bthprops 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\AppLocker 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\System 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SKB 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\security 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\schemas 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\SchCache 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Resources 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\RemotePackages 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\PLA 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Performance 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\ModemLogs 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\L2Schemas 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\InputMethod 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Globalization 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\GameBarPresenceWriter 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Cursors 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\Branding 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\addins 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\ProgramData\USOPrivate 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\ProgramData\Comms 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Windows Portable Devices 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files\Common Files\Services 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows NT 2016-11-26 23:45 - 2016-11-26 23:45 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-11-26 23:45 - 2016-11-26 23:44 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2016-11-26 23:45 - 2016-11-26 23:44 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat 2016-11-26 23:45 - 2016-11-26 23:44 - 00215943 _____ C:\WINDOWS\system32\dssec.dat 2016-11-26 23:45 - 2016-11-26 23:44 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2016-11-26 23:45 - 2016-11-26 23:44 - 00027136 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll 2016-11-26 23:45 - 2016-11-26 23:44 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services 2016-11-26 23:45 - 2016-11-26 23:44 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK 2016-11-26 23:45 - 2016-11-26 23:44 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam 2016-11-26 23:45 - 2016-11-26 23:44 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol 2016-11-26 23:45 - 2016-11-26 23:44 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json 2016-11-26 23:45 - 2016-11-26 23:44 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT 2016-11-26 23:45 - 2016-11-26 23:44 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT 2016-11-26 23:45 - 2016-11-26 23:44 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks 2016-11-26 23:45 - 2016-11-26 23:44 - 00000219 _____ C:\WINDOWS\system.ini 2016-11-26 23:45 - 2016-11-26 23:44 - 00000092 _____ C:\WINDOWS\win.ini 2016-11-26 23:44 - 2016-11-30 03:08 - 00000000 ____D C:\WINDOWS\INF 2016-11-26 23:42 - 2016-12-05 22:34 - 01835008 _____ C:\WINDOWS\system32\config\BBI 2016-11-26 23:42 - 2016-11-28 23:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-11-26 23:42 - 2016-11-26 23:49 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2016-11-26 23:42 - 2016-11-26 23:47 - 00000000 ____D C:\WINDOWS\servicing 2016-11-26 23:42 - 2016-11-26 23:45 - 00000000 ____D C:\WINDOWS\system32\SMI 2016-11-26 20:17 - 2016-11-26 20:17 - 00376528 _____ (Microsoft Corporation) C:\Users\Thorsten\Downloads\Nicht bestätigt 574898.crdownload 2016-11-26 04:07 - 2016-11-26 04:07 - 00000000 ____D C:\Users\Thorsten\Desktop\slenf2aw.fmg 2016-11-26 01:48 - 2016-11-26 01:48 - 25401064 _____ (Logitech Inc.) C:\Users\Thorsten\Downloads\Options_6.30.80 (1).exe 2016-11-26 01:31 - 2016-11-26 01:31 - 04147600 _____ ($Co_Name Inc.) C:\Users\Thorsten\Downloads\unifying250.exe 2016-11-25 18:57 - 2016-11-25 18:57 - 25401064 _____ (Logitech Inc.) C:\Users\Thorsten\Downloads\Options_6.30.80.exe 2016-11-20 20:10 - 2016-12-01 23:14 - 00000000 ____D C:\Users\Thorsten\AppData\LocalLow\Mozilla 2016-11-20 20:09 - 2016-11-20 20:09 - 00243656 _____ C:\Users\Thorsten\Downloads\Firefox Setup Stub 50.0.exe 2016-11-19 00:03 - 2016-11-19 00:03 - 02952963 _____ C:\Users\Thorsten\Downloads\manual (1).pdf 2016-11-19 00:01 - 2016-11-19 00:01 - 02952963 _____ C:\Users\Thorsten\Downloads\manual.pdf 2016-11-17 17:17 - 2016-11-17 17:17 - 00203900 _____ C:\Users\Thorsten\Downloads\3441119-3290097-Feedback.pdf 2016-11-17 17:07 - 2016-11-17 17:07 - 00183388 _____ C:\Users\Thorsten\Downloads\3440522-3289533-Feedback.pdf 2016-11-16 21:15 - 2016-11-16 21:15 - 00001518 _____ C:\Users\Thorsten\Downloads\LifeCam3.60 (1) - Verknüpfung.lnk 2016-11-16 21:15 - 2016-11-16 21:15 - 00001500 _____ C:\Users\Thorsten\Downloads\ifunbox_setup - Verknüpfung.lnk 2016-11-16 21:15 - 2016-11-16 21:15 - 00001482 _____ C:\Users\Thorsten\Downloads\LifeCam3.60 - Verknüpfung.lnk 2016-11-16 21:15 - 2016-11-16 21:15 - 00001080 _____ C:\Users\Thorsten\Downloads\node-v4.6.1.tar.gz - Verknüpfung.lnk 2016-11-14 18:18 - 2016-11-26 23:30 - 00000000 ___RD C:\Users\Thorsten\iCloudDrive 2016-11-13 03:54 - 2016-11-13 03:54 - 00000000 ____D C:\Users\Thorsten\Documents\Ashampoo Burning Studio 16 2016-11-10 03:48 - 2016-11-10 03:48 - 00504109 _____ C:\Users\Thorsten\Downloads\smartset (4).zip 2016-11-10 03:34 - 2016-11-10 03:35 - 00081878 _____ C:\Users\Thorsten\Downloads\TouchPro_Pro-G_DS_1.pdf 2016-11-10 00:02 - 2016-11-02 13:01 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-11-10 00:02 - 2016-11-02 13:01 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-11-10 00:02 - 2016-11-02 12:22 - 01570672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-11-10 00:02 - 2016-11-02 12:20 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-11-10 00:02 - 2016-11-02 12:13 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-11-10 00:02 - 2016-11-02 12:13 - 00773720 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2016-11-10 00:02 - 2016-11-02 12:12 - 00376672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2016-11-10 00:02 - 2016-11-02 12:12 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-11-10 00:02 - 2016-11-02 12:10 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2016-11-10 00:02 - 2016-11-02 12:09 - 02257104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-11-10 00:02 - 2016-11-02 12:08 - 00576408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2016-11-10 00:02 - 2016-11-02 12:08 - 00186424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll 2016-11-10 00:02 - 2016-11-02 12:05 - 06657176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-11-10 00:02 - 2016-11-02 12:05 - 03892352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-11-10 00:02 - 2016-11-02 12:05 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-11-10 00:02 - 2016-11-02 12:05 - 00951904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-11-10 00:02 - 2016-11-02 12:05 - 00405856 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-11-10 00:02 - 2016-11-02 12:04 - 04312248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2016-11-10 00:02 - 2016-11-02 12:03 - 00714592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2016-11-10 00:02 - 2016-11-02 12:02 - 00682816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2016-11-10 00:02 - 2016-11-02 12:02 - 00238056 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll 2016-11-10 00:02 - 2016-11-02 12:01 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-11-10 00:02 - 2016-11-02 12:01 - 00545936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-11-10 00:02 - 2016-11-02 12:00 - 08156080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-11-10 00:02 - 2016-11-02 12:00 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-11-10 00:02 - 2016-11-02 12:00 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2016-11-10 00:02 - 2016-11-02 11:59 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2016-11-10 00:02 - 2016-11-02 11:50 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-11-10 00:02 - 2016-11-02 11:49 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2016-11-10 00:02 - 2016-11-02 11:49 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-11-10 00:02 - 2016-11-02 11:47 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2016-11-10 00:02 - 2016-11-02 11:46 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2016-11-10 00:02 - 2016-11-02 11:44 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-11-10 00:02 - 2016-11-02 11:44 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthExt.dll 2016-11-10 00:02 - 2016-11-02 11:43 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-11-10 00:02 - 2016-11-02 11:42 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll 2016-11-10 00:02 - 2016-11-02 11:42 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2016-11-10 00:02 - 2016-11-02 11:42 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-11-10 00:02 - 2016-11-02 11:40 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll 2016-11-10 00:02 - 2016-11-02 11:39 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2016-11-10 00:02 - 2016-11-02 11:38 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl 2016-11-10 00:02 - 2016-11-02 11:37 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe 2016-11-10 00:02 - 2016-11-02 11:36 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-11-10 00:02 - 2016-11-02 11:36 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe 2016-11-10 00:02 - 2016-11-02 11:33 - 12349952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-11-10 00:02 - 2016-11-02 11:33 - 03307520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-11-10 00:02 - 2016-11-02 11:32 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll 2016-11-10 00:02 - 2016-11-02 11:31 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-11-10 00:02 - 2016-11-02 11:31 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe 2016-11-10 00:02 - 2016-11-02 11:31 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll 2016-11-10 00:02 - 2016-11-02 11:31 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-11-10 00:02 - 2016-11-02 11:30 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-11-10 00:02 - 2016-11-02 11:30 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2016-11-10 00:02 - 2016-11-02 11:30 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll 2016-11-10 00:02 - 2016-11-02 11:30 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-11-10 00:02 - 2016-11-02 11:29 - 07469056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2016-11-10 00:02 - 2016-11-02 11:29 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2016-11-10 00:02 - 2016-11-02 11:29 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll 2016-11-10 00:02 - 2016-11-02 11:29 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2016-11-10 00:02 - 2016-11-02 11:28 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2016-11-10 00:02 - 2016-11-02 11:28 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll 2016-11-10 00:02 - 2016-11-02 11:28 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll 2016-11-10 00:02 - 2016-11-02 11:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2016-11-10 00:02 - 2016-11-02 11:28 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll 2016-11-10 00:02 - 2016-11-02 11:28 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2016-11-10 00:02 - 2016-11-02 11:28 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-11-10 00:02 - 2016-11-02 11:28 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chartv.dll 2016-11-10 00:02 - 2016-11-02 11:27 - 02458112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll 2016-11-10 00:02 - 2016-11-02 11:27 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2016-11-10 00:02 - 2016-11-02 11:27 - 00580608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll 2016-11-10 00:02 - 2016-11-02 11:27 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl 2016-11-10 00:02 - 2016-11-02 11:27 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-11-10 00:02 - 2016-11-02 11:27 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll 2016-11-10 00:02 - 2016-11-02 11:26 - 02747392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll 2016-11-10 00:02 - 2016-11-02 11:26 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll 2016-11-10 00:02 - 2016-11-02 11:26 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2016-11-10 00:02 - 2016-11-02 11:26 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-11-10 00:02 - 2016-11-02 11:26 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll 2016-11-10 00:02 - 2016-11-02 11:26 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2016-11-10 00:02 - 2016-11-02 11:26 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2016-11-10 00:02 - 2016-11-02 11:26 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2016-11-10 00:02 - 2016-11-02 11:25 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-11-10 00:02 - 2016-11-02 11:25 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-11-10 00:02 - 2016-11-02 11:25 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll 2016-11-10 00:02 - 2016-11-02 11:25 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll 2016-11-10 00:02 - 2016-11-02 11:24 - 00940032 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll 2016-11-10 00:02 - 2016-11-02 11:23 - 03106304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2016-11-10 00:02 - 2016-11-02 11:23 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys 2016-11-10 00:02 - 2016-11-02 11:22 - 13441024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-11-10 00:02 - 2016-11-02 11:22 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-11-10 00:02 - 2016-11-02 11:22 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2016-11-10 00:02 - 2016-11-02 11:21 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-11-10 00:02 - 2016-11-02 11:19 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\chartv.dll 2016-11-10 00:02 - 2016-11-02 11:19 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2016-11-10 00:02 - 2016-11-02 11:18 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2016-11-10 00:02 - 2016-11-02 11:18 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll 2016-11-10 00:02 - 2016-11-02 11:18 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll 2016-11-10 00:02 - 2016-11-02 11:17 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-11-10 00:02 - 2016-11-02 11:17 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-11-10 00:02 - 2016-11-02 11:17 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl 2016-11-10 00:02 - 2016-11-02 11:17 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2016-11-10 00:02 - 2016-11-02 11:16 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll 2016-11-10 00:02 - 2016-11-02 11:16 - 03133440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll 2016-11-10 00:02 - 2016-11-02 11:16 - 02512384 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll 2016-11-10 00:02 - 2016-11-02 11:16 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-11-10 00:02 - 2016-11-02 11:16 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2016-11-10 00:02 - 2016-11-02 11:16 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll 2016-11-10 00:02 - 2016-11-02 11:16 - 00308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll 2016-11-10 00:02 - 2016-11-02 11:15 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll 2016-11-10 00:02 - 2016-11-02 11:15 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll 2016-11-10 00:02 - 2016-11-02 11:14 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-11-10 00:02 - 2016-11-02 09:20 - 00446896 _____ C:\WINDOWS\system32\ApnDatabase.xml 2016-11-10 00:01 - 2016-11-02 12:22 - 00601712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2016-11-10 00:01 - 2016-11-02 12:20 - 00378720 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-11-10 00:01 - 2016-11-02 12:15 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-11-10 00:01 - 2016-11-02 12:15 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-11-10 00:01 - 2016-11-02 12:14 - 07816544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-11-10 00:01 - 2016-11-02 12:13 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-11-10 00:01 - 2016-11-02 12:13 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-11-10 00:01 - 2016-11-02 12:13 - 00423776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe 2016-11-10 00:01 - 2016-11-02 12:12 - 02255712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2016-11-10 00:01 - 2016-11-02 12:08 - 00602464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-11-10 00:01 - 2016-11-02 12:08 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-11-10 00:01 - 2016-11-02 12:05 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-11-10 00:01 - 2016-11-02 12:04 - 02678056 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2016-11-10 00:01 - 2016-11-02 12:04 - 00596832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2016-11-10 00:01 - 2016-11-02 12:03 - 02750936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-11-10 00:01 - 2016-11-02 12:02 - 00848736 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-11-10 00:01 - 2016-11-02 12:02 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll 2016-11-10 00:01 - 2016-11-02 12:01 - 01425000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2016-11-10 00:01 - 2016-11-02 12:01 - 01415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2016-11-10 00:01 - 2016-11-02 12:01 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll 2016-11-10 00:01 - 2016-11-02 12:01 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2016-11-10 00:01 - 2016-11-02 12:00 - 22223968 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-11-10 00:01 - 2016-11-02 12:00 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-11-10 00:01 - 2016-11-02 12:00 - 01061968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-11-10 00:01 - 2016-11-02 11:56 - 01609920 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2016-11-10 00:01 - 2016-11-02 11:56 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2016-11-10 00:01 - 2016-11-02 11:56 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-11-10 00:01 - 2016-11-02 11:56 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-11-10 00:01 - 2016-11-02 11:56 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll 2016-11-10 00:01 - 2016-11-02 11:55 - 00048992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iorate.sys 2016-11-10 00:01 - 2016-11-02 11:48 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll 2016-11-10 00:01 - 2016-11-02 11:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2016-11-10 00:01 - 2016-11-02 11:48 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll 2016-11-10 00:01 - 2016-11-02 11:47 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll 2016-11-10 00:01 - 2016-11-02 11:47 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-11-10 00:01 - 2016-11-02 11:46 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll 2016-11-10 00:01 - 2016-11-02 11:45 - 00492032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-11-10 00:01 - 2016-11-02 11:45 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll 2016-11-10 00:01 - 2016-11-02 11:45 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll 2016-11-10 00:01 - 2016-11-02 11:44 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2016-11-10 00:01 - 2016-11-02 11:43 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8.dll 2016-11-10 00:01 - 2016-11-02 11:43 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2016-11-10 00:01 - 2016-11-02 11:43 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll 2016-11-10 00:01 - 2016-11-02 11:43 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2016-11-10 00:01 - 2016-11-02 11:42 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-11-10 00:01 - 2016-11-02 11:42 - 00549376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll 2016-11-10 00:01 - 2016-11-02 11:42 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-11-10 00:01 - 2016-11-02 11:42 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll 2016-11-10 00:01 - 2016-11-02 11:41 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2016-11-10 00:01 - 2016-11-02 11:40 - 00548352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll 2016-11-10 00:01 - 2016-11-02 11:40 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-11-10 00:01 - 2016-11-02 11:39 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll 2016-11-10 00:01 - 2016-11-02 11:39 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll 2016-11-10 00:01 - 2016-11-02 11:38 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-11-10 00:01 - 2016-11-02 11:37 - 19415040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-11-10 00:01 - 2016-11-02 11:36 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-11-10 00:01 - 2016-11-02 11:36 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetailsUpdate.dll 2016-11-10 00:01 - 2016-11-02 11:35 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msinfo32.exe 2016-11-10 00:01 - 2016-11-02 11:34 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll 2016-11-10 00:01 - 2016-11-02 11:34 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-11-10 00:01 - 2016-11-02 11:33 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-11-10 00:01 - 2016-11-02 11:32 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-11-10 00:01 - 2016-11-02 11:31 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2016-11-10 00:01 - 2016-11-02 11:31 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll 2016-11-10 00:01 - 2016-11-02 11:31 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-11-10 00:01 - 2016-11-02 11:31 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2016-11-10 00:01 - 2016-11-02 11:31 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll 2016-11-10 00:01 - 2016-11-02 11:31 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2016-11-10 00:01 - 2016-11-02 11:30 - 12175360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-11-10 00:01 - 2016-11-02 11:30 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll 2016-11-10 00:01 - 2016-11-02 11:30 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2016-11-10 00:01 - 2016-11-02 11:30 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2016-11-10 00:01 - 2016-11-02 11:30 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetails.dll 2016-11-10 00:01 - 2016-11-02 11:29 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-11-10 00:01 - 2016-11-02 11:29 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll 2016-11-10 00:01 - 2016-11-02 11:29 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2016-11-10 00:01 - 2016-11-02 11:29 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll 2016-11-10 00:01 - 2016-11-02 11:29 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll 2016-11-10 00:01 - 2016-11-02 11:29 - 00276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2016-11-10 00:01 - 2016-11-02 11:29 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-11-10 00:01 - 2016-11-02 11:29 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-11-10 00:01 - 2016-11-02 11:28 - 00240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2016-11-10 00:01 - 2016-11-02 11:28 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2016-11-10 00:01 - 2016-11-02 11:27 - 23677952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-11-10 00:01 - 2016-11-02 11:27 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll 2016-11-10 00:01 - 2016-11-02 11:27 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-11-10 00:01 - 2016-11-02 11:27 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-11-10 00:01 - 2016-11-02 11:26 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-11-10 00:01 - 2016-11-02 11:26 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-11-10 00:01 - 2016-11-02 11:26 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2016-11-10 00:01 - 2016-11-02 11:26 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2016-11-10 00:01 - 2016-11-02 11:26 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll 2016-11-10 00:01 - 2016-11-02 11:26 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-11-10 00:01 - 2016-11-02 11:25 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-11-10 00:01 - 2016-11-02 11:25 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2016-11-10 00:01 - 2016-11-02 11:25 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2016-11-10 00:01 - 2016-11-02 11:25 - 00541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2016-11-10 00:01 - 2016-11-02 11:24 - 03778560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-11-10 00:01 - 2016-11-02 11:23 - 02356736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll 2016-11-10 00:01 - 2016-11-02 11:23 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2016-11-10 00:01 - 2016-11-02 11:23 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll 2016-11-10 00:01 - 2016-11-02 11:23 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetailsUpdate.dll 2016-11-10 00:01 - 2016-11-02 11:22 - 13081600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-11-10 00:01 - 2016-11-02 11:22 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinfo32.exe 2016-11-10 00:01 - 2016-11-02 11:21 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2016-11-10 00:01 - 2016-11-02 11:20 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-11-10 00:01 - 2016-11-02 11:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll 2016-11-10 00:01 - 2016-11-02 11:19 - 08127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-11-10 00:01 - 2016-11-02 11:19 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2016-11-10 00:01 - 2016-11-02 11:19 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll 2016-11-10 00:01 - 2016-11-02 11:19 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2016-11-10 00:01 - 2016-11-02 11:19 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll 2016-11-10 00:01 - 2016-11-02 11:19 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2016-11-10 00:01 - 2016-11-02 11:18 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-11-10 00:01 - 2016-11-02 11:18 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll 2016-11-10 00:01 - 2016-11-02 11:17 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-11-10 00:01 - 2016-11-02 11:17 - 00982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 04148736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2016-11-10 00:01 - 2016-11-02 11:16 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-11-10 00:01 - 2016-11-02 11:15 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2016-11-10 00:01 - 2016-11-02 11:15 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-11-10 00:01 - 2016-11-02 11:15 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-11-10 00:01 - 2016-11-02 11:15 - 01348608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2016-11-10 00:01 - 2016-11-02 11:15 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2016-11-10 00:01 - 2016-11-02 11:13 - 03496960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll 2016-11-10 00:01 - 2016-11-02 11:13 - 03299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2016-11-10 00:01 - 2016-11-02 11:13 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll 2016-11-10 00:01 - 2016-11-02 10:11 - 00788624 _____ C:\WINDOWS\SysWOW64\locale.nls 2016-11-10 00:01 - 2016-11-02 10:11 - 00788624 _____ C:\WINDOWS\system32\locale.nls 2016-11-10 00:01 - 2016-08-02 05:30 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-11-08 18:21 - 2016-11-08 18:21 - 00201634 _____ C:\Users\Thorsten\Downloads\3422476-3265030-Feedback.pdf 2016-11-08 17:42 - 2016-11-08 17:42 - 00204175 _____ C:\Users\Thorsten\Downloads\3422449-3264996-Feedback.pdf 2016-11-08 17:29 - 2016-11-08 17:29 - 00184545 _____ C:\Users\Thorsten\Downloads\3422436-3264967-Feedback.pdf 2016-11-08 17:27 - 2016-11-08 17:27 - 00207692 _____ C:\Users\Thorsten\Downloads\3422408-3264956-Feedback.pdf 2016-11-08 16:58 - 2016-11-08 16:58 - 00213136 _____ C:\Users\Thorsten\Downloads\3422285-3264895-Feedback.pdf 2016-11-07 19:57 - 2016-11-07 19:57 - 00410392 _____ (Logitech) C:\Users\Thorsten\Downloads\MyHarmony-App (1).exe 2016-11-07 03:25 - 2016-11-07 03:25 - 02804122 _____ C:\Users\Thorsten\Downloads\enigma2-plugin-extensions-mediaportal_7.3.1_all.ipk 2016-11-07 03:23 - 2016-11-07 03:23 - 00820030 _____ C:\Users\Thorsten\Downloads\python-requests_2.11.1_git0_58d855e193-r1.1_mips32el.ipk 2016-11-07 03:23 - 2016-11-07 03:23 - 00184102 _____ C:\Users\Thorsten\Downloads\python-js2py_0.39_git0_144b1701fa-r1.1_mips32el.ipk 2016-11-07 03:23 - 2016-11-07 03:23 - 00016894 _____ C:\Users\Thorsten\Downloads\python-six_1.7.3-r1_mips32el.ipk 2016-11-07 02:41 - 2016-11-07 02:41 - 00000000 ____D C:\Users\Thorsten\Desktop\Neuer Ordner (2) ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-12-04 19:26 - 2016-02-13 18:32 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-11-30 10:11 - 2016-04-17 09:26 - 00000000 ___RD C:\Users\ttjh1\OneDrive 2016-11-28 23:36 - 2016-07-16 12:43 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TFTP.EXE 2016-11-28 23:35 - 2016-10-28 05:24 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmp.exe 2016-11-28 23:35 - 2016-10-28 05:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmp.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00194560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmpsnap.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntwin.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntwin.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntagnt.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntagnt.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hostmib.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\lmmib2.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hostmib.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lmmib2.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\evntcmd.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evntcmd.exe 2016-11-28 23:35 - 2016-07-16 12:44 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64mib.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmpmib.dll 2016-11-28 23:35 - 2016-07-16 12:44 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\snmpmib.dll 2016-11-28 23:35 - 2016-07-16 12:43 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmpsnap.dll 2016-11-28 23:35 - 2016-07-16 12:43 - 00107882 _____ C:\WINDOWS\SysWOW64\mib_ii.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00107882 _____ C:\WINDOWS\system32\mib_ii.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00048593 _____ C:\WINDOWS\SysWOW64\hostmib.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00048593 _____ C:\WINDOWS\system32\hostmib.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00034317 _____ C:\WINDOWS\SysWOW64\msiprip2.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00034317 _____ C:\WINDOWS\system32\msiprip2.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00030448 _____ C:\WINDOWS\SysWOW64\mcastmib.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00030448 _____ C:\WINDOWS\system32\mcastmib.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00026236 _____ C:\WINDOWS\SysWOW64\wins.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00026236 _____ C:\WINDOWS\system32\wins.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00026100 _____ C:\WINDOWS\SysWOW64\lmmib2.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00026100 _____ C:\WINDOWS\system32\lmmib2.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00022462 _____ C:\WINDOWS\SysWOW64\rfc2571.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00022462 _____ C:\WINDOWS\system32\rfc2571.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00021271 _____ C:\WINDOWS\SysWOW64\http.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00021271 _____ C:\WINDOWS\system32\http.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00015799 _____ C:\WINDOWS\SysWOW64\ipforwd.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00015799 _____ C:\WINDOWS\system32\ipforwd.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00015032 _____ C:\WINDOWS\SysWOW64\authserv.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00015032 _____ C:\WINDOWS\system32\authserv.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00014032 _____ C:\WINDOWS\SysWOW64\accserv.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00014032 _____ C:\WINDOWS\system32\accserv.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00013767 _____ C:\WINDOWS\SysWOW64\msipbtp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00013767 _____ C:\WINDOWS\system32\msipbtp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00006179 _____ C:\WINDOWS\SysWOW64\ftp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00006179 _____ C:\WINDOWS\system32\ftp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00004597 _____ C:\WINDOWS\SysWOW64\dhcp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00004597 _____ C:\WINDOWS\system32\dhcp.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00004411 _____ C:\WINDOWS\SysWOW64\smi.mib 2016-11-28 23:35 - 2016-07-16 12:43 - 00004411 _____ C:\WINDOWS\system32\smi.mib 2016-11-27 04:42 - 2016-08-19 01:05 - 03133144 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll 2016-11-27 04:42 - 2016-08-19 01:04 - 05793528 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll 2016-11-27 04:42 - 2016-08-19 00:51 - 05258248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys 2016-11-27 04:42 - 2016-08-19 00:51 - 00023696 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll 2016-11-27 00:34 - 2016-08-18 01:13 - 00000000 ____D C:\Windows10Upgrade 2016-11-27 00:10 - 2016-04-17 00:15 - 00000000 ___RD C:\Users\Thorsten\OneDrive 2016-11-26 23:29 - 2016-07-06 18:20 - 00009612 _____ C:\CYGWIN_SYSLOG.TXT 2016-11-25 03:26 - 2016-09-15 23:38 - 00000000 ____D C:\Users\Thorsten\Desktop\Cydia 2016-11-14 18:19 - 2016-04-21 21:16 - 00000000 ____D C:\Users\Thorsten\Documents\Outlook-Dateien 2016-11-14 04:00 - 2016-08-18 01:13 - 00000719 _____ C:\Users\Thorsten\Desktop\Windows 10-Upgrade-Assistent.lnk 2016-11-10 02:55 - 2016-05-06 17:19 - 00000000 ____D C:\Users\Thorsten\.dreamstream Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\Thorsten\NTUSER - Kopie.DAT C:\Users\Thorsten\WDMyCloud_win.exe C:\Users\totti\NTUSER (2).DAT ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-11-26 23:49 ==================== Ende von FRST.txt ============================ Code:
ATTFilter eset online scan C:\ProgramData\Logishrd\LogiOptions\Software\Current\dma_x64.dll Variante von Win64/WebBar.B evtl. unerwünschte Anwendung C:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll Variante von Win64/WebBar.B evtl. unerwünschte Anwendung C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\b\00000601000000073701.dat Win32/Trustezeb.K Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\20000702000000073701.dat Variante von Win32/Kryptik.DHWI Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\b0000702000000073701.dat Win32/Trustezeb.J Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\c\e0000502000000073701.dat Variante von Win32/Injector.CQON Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\d\e0000503000000073701.dat Variante von Win32/Injector.CQON Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\f\40000905000000073701.dat Variante von Win32/Injector.UXF Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\h\40000907000000073701.dat Win32/Trustezeb.B Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\i\40000908000000073701.dat Win32/Trustezeb.B Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\40000909000000073701.dat Win32/Trustezeb.B Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\j\f0000709000000073701.dat Win32/Trustezeb.F Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\k\4000090a000000073701.dat Win32/Trustezeb.C Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\l\4000090b000000073701.dat Win32/Trustezeb.C Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\2000070c000000073701.dat Variante von MSIL/Injector.IFD Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\m\4000090c000000073701.dat Win32/Trustezeb.A Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\2000070d000000073701.dat Variante von MSIL/Injector.IBM Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\n\4000090d000000073701.dat Win32/Trustezeb.A Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\o\4000090e000000073701.dat Win32/Trustezeb.A Trojaner C:\Users\Thorsten\AppData\Local\Comms\Unistore\data\7\p\4000090f000000073701.dat Win32/Trustezeb.A Trojaner C:\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\1IKI76C9\logioptions_logitech[1].exe Variante von Win32/WebBar.D evtl. unerwünschte Anwendung C:\Users\Thorsten\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\TM8BD2KG\request[1].htm HTML/Refresh.BC Trojaner C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung C:\Users\Thorsten\AppData\Local\Temp\DMR\dmr_76.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung C:\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe Variante von Win32/WebBar.D evtl. unerwünschte Anwendung C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Share-Online.biz.htm HTML/ScrInject.B Trojaner C:\Users\Thorsten\Desktop\Neuer Ordner\Wiiu\games\Super_Mario_3D_World_EUR_WiiU-ABSTRAKT\Uploaded.htm HTML/ScrInject.B Trojaner C:\Users\Thorsten\Downloads\Options_6.30.80 (1).exe Variante von Win32/WebBar.D evtl. unerwünschte Anwendung C:\Users\Thorsten\Downloads\Options_6.30.80.exe Variante von Win32/WebBar.D evtl. unerwünschte Anwendung C:\Users\ttjh1\Downloads\NetSpeedMonitor 64 Bit - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung C:\Windows.old\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll Variante von Win64/WebBar.B evtl. unerwünschte Anwendung C:\Windows.old\Users\Thorsten\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00659b Variante von Win32/WebBar.D evtl. unerwünschte Anwendung C:\Windows.old\Users\Thorsten\AppData\Local\Microsoft\Windows\INetCache\IE\VZR6RD7Z\logioptions_logitech[1].exe Variante von Win32/WebBar.D evtl. unerwünschte Anwendung C:\Windows.old\Users\Thorsten\AppData\Local\Temp\DMR\dmr_72.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung C:\Windows.old\Users\Thorsten\AppData\Local\Temp\lu\nada_264_logioptions_logitech.exe Variante von Win32/WebBar.D evtl. unerwünschte Anwendung D:\Users\All Users\Logishrd\LogiOptions\Software\Current\dma_x64.dll Variante von Win64/WebBar.B evtl. unerwünschte Anwendung D:\Users\Thorsten\Downloads\HP USB Disk Storage Format Tool - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung |
Themen zu Windows 10 plötzlich unbekanntes Benutzerkonto/eMail. Microsoftkonto gehackt? |
administrator, asus, besitzer, bonjour, computer, defender, desktop, e-mail, explorer, installation, mozilla, nvidia, prozesse, realtek, registry, router, rundll, scan, server, services.exe, software, super, svchost.exe, system, usb, windows, windowsapps, winlogon.exe |