|
Log-Analyse und Auswertung: Zertifikatfehler, NavigationWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
18.09.2017, 15:53 | #1 |
| Zertifikatfehler, Navigation Zertifikatfehler Navigation. Internetseiten wie zu Beispiel ''Web.de'' nicht aufrufbar. AVIRA zeigt keinen Befall. Systemwiderherstellung zu einem früheren Zeitpunkt habe ich im Eifer des Gefechts vorgenommen. Kein aktuelles Datum mehr. FRST und Addition-Editor kann ich nicht senden. Code einfügen nicht möglich. Symbol # reagiert nicht. https://www.trojaner-board.de/images/smilies/dankeschoen.gif |
18.09.2017, 22:32 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Zertifikatfehler, Navigation Scan mit Farbar's Recovery Scan Tool (FRST)
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
19.09.2017, 10:37 | #3 |
| Zertifikatfehler, NavigationCode:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 17-09-2017 01 durchgeführt von Rudi (01-01-2011 04:57:04) Gestartet von C:\Users\Rudi\Documents Windows 7 Home Premium Service Pack 1 (X64) (2011-09-26 13:39:21) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3229228620-787667599-3763351482-500 - Administrator - Disabled) Gast (S-1-5-21-3229228620-787667599-3763351482-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3229228620-787667599-3763351482-1006 - Limited - Enabled) Rudi (S-1-5-21-3229228620-787667599-3763351482-1001 - Administrator - Enabled) => C:\Users\Rudi ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F} AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Ability Office 6 (HKLM-x32\...\{91D48D8B-EEEB-4B26-848E-8AAD0D0C0A20}) (Version: 6.0.14 - Ability Software International) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.130 - Adobe Systems Incorporated) ALDI TALK Verbindungsassistent (HKLM-x32\...\ALDITALKVerbindungsassistent) (Version: 5.0 - ALDI TALK Verbindungsassistent) ArcSoft TotalMedia 3.5 (HKLM-x32\...\{29E44E9D-ACB2-4D2D-849F-5361C941B7E1}) (Version: 3.5.7.282 - ArcSoft) Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros) ATI Catalyst Install Manager (HKLM\...\{E04A3037-2F82-C518-D6CA-A63497D3872F}) (Version: 3.0.808.0 - ATI Technologies, Inc.) Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.30.29 - Avira Operations GmbH & Co. KG) Avira Connect (HKLM-x32\...\{14d00649-a178-473f-bf48-eec016dc4bfa}) (Version: 1.2.89.29905 - Avira Operations GmbH & Co. KG) Avira Connect (HKLM-x32\...\{271D5399-34AF-4611-BCD9-B09185B2BBE0}) (Version: 1.2.89.29905 - Avira Operations GmbH & Co. KG) Hidden BDE (HKLM-x32\...\{C3EC469F-6296-42BF-B282-2EA2C6B80B06}) (Version: 1.0 - ) Hidden BDE (HKLM-x32\...\BDE) (Version: - ) Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.02.000.55 - Atheros Communications) ccc-core-static (HKLM-x32\...\{687DB473-1A0F-5B1D-D0E0-A73258207AB2}) (Version: 2011.0304.1135.20703 - Ihr Firmenname) Hidden Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.2.1.3726 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard) ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Evernote v. 4.2.2 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.2.3979 - Evernote Corp.) GPS Information (HKLM-x32\...\{219BB7DF-83BA-44C6-A362-D17981FBD285}) (Version: - ) Hewlett-Packard ACLM.NET v1.2.1.1 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Deskjet 1000 J110 series - Grundlegende Software für das Gerät (HKLM\...\{CED47C99-8892-4956-BCA7-CC3123531371}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Documentation (HKLM-x32\...\{2BF8B295-A214-42AC-B4EC-2AE15E08B0E7}) (Version: 1.1.0.0 - Hewlett-Packard) HP On Screen Display (HKLM-x32\...\{124DB96E-CBF5-44FB-AB59-7D2444DEC777}) (Version: 1.0.7 - Hewlett-Packard Company) HP Power Manager (HKLM-x32\...\{B97E3520-C726-475E-BC0C-7561952633AB}) (Version: 1.2.1 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{EB58480C-0721-483C-B354-9D35A147999F}) (Version: 2.3.6 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company) HP Software Framework (HKLM-x32\...\{825C4BE0-5C73-4B05-A0BC-CB16F0C100D3}) (Version: 4.1.8.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) IRRecevie (HKLM-x32\...\{F6BC20A5-3C48-4675-BDE6-E2E6FED30B9D}) (Version: 1.00.0000 - Mygica) Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft AutoRoute 2006 mit GPS Empfänger (HKLM-x32\...\{83ED1E80-A1B7-4236-BCF1-AC4A88151A6B}) (Version: 13.00.08.2400 - Microsoft Corporation) Microsoft AutoRoute 2007 (HKLM-x32\...\{C82185E8-C27B-4EF4-2007-3333BC2C2B6D}) (Version: 14.0.09.1100 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation) Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) RealSpeak Solo fur Deutsch - Steffi (HKLM-x32\...\{BFBB91DB-9F0F-4A9C-9669-A97DA3512CF2}) (Version: 4.00.0000 - Nuance) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.42.304.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6287 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.77 - Realtek Semiconductor Corp.) Recovery Manager (HKLM-x32\...\{C7231F7C-6530-4E65-ADA6-5B392CF5BEB1}) (Version: 1.0.22 - Hewlett-Packard) Hidden Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version: - Silicon Laboratories) Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7 (HKLM-x32\...\{D0483FD0-3AEB-4207-81EF-502B6E6F9374}) (Version: 6.5 - Silicon Laboratories, Inc.) USB Video Device (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.54400.104 - Sonix) VLC media player 1.0.0 (HKLM-x32\...\VLC media player) (Version: 1.0.0 - VideoLAN Team) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) WinRAR 4.01 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) WISO steuer:Sparbuch 2016 (HKLM-x32\...\{38FF9F68-301F-44C7-9171-E4C4029CCDB8}) (Version: 23.00.1146 - Buhl Data Service GmbH) WISO steuer:Sparbuch 2017 (HKLM-x32\...\{A409FDB7-7E4D-4DC4-8992-B0BFE752C47A}) (Version: 24.00.1375 - Buhl Data Service GmbH) WMV9/VC-1 Video Playback (HKLM\...\{6E6BEFE9-0AFF-C09F-24A8-AA1CB05869BF}) (Version: 1.00.0000 - ATI Technologies Inc.) Hidden Xobni (HKLM-x32\...\XobniMain) (Version: 1.9.5.13209 - Xobni Corp.) Xobni Core (HKLM-x32\...\{8DC069E7-893C-41E1-9442-DE89FEC33371}) (Version: 1.0.0 - Xobni, Inc.) Hidden ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ContextMenuHandlers1: [Atheros] -> {B8952421-0E55-400B-94A6-FA858FC0A39F} => C:\Program Files (x86)\Bluetooth Suite\BtvAppExt.dll [2011-01-06] (Atheros Commnucations) ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\AntiVir Desktop\shlext64.dll [2011-01-01] (Avira Operations GmbH & Co. KG) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2011-05-28] () ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2011-05-28] () ContextMenuHandlers1-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing, S.L.) ContextMenuHandlers3: [FTShellContext] -> {AFF81F7B-6942-40c4-AADA-7214EF7B6DD1} => C:\Program Files (x86)\Bluetooth Suite\ShellContextExt.dll [2011-01-06] (Atheros Commnucations) ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2011-05-28] () ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2011-05-28] () ContextMenuHandlers4-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing, S.L.) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2011-03-04] (Advanced Micro Devices, Inc.) ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\AntiVir Desktop\shlext64.dll [2011-01-01] (Avira Operations GmbH & Co. KG) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2011-05-28] () ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2011-05-28] () ContextMenuHandlers6-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing, S.L.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {00925380-52C9-464D-8B75-CB41AD4B9651} - System32\Tasks\HPCeeScheduleForRUDI-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard) Task: {0ABAD761-69BF-4D3B-B989-DB6189E57EAE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-09-01] (HP Inc.) Task: {0CD4DCC2-E737-457E-A36E-641D091EE3B0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2016-12-07] (HP Inc.) Task: {22660BBF-5513-41EE-86B5-A994F0F3B1A6} - System32\Tasks\{10A56367-DD8B-4A3F-997E-741937A033D0} => C:\Windows\system32\pcalua.exe -a "C:\Users\Rudi\Documents\Arbeitsdateien\Kopie AutoMapa\AutoMapa 6.6.0 EU Final\Setup.exe" -d "C:\Users\Rudi\Documents\Arbeitsdateien\Kopie AutoMapa\AutoMapa 6.6.0 EU Final" Task: {3F23FC50-4520-45E0-8F1E-627A2FF1D794} - System32\Tasks\{B18FA98A-E82C-4A91-8381-F27EE8F93E80} => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe Task: {41A216F4-364C-4A28-8E96-EFD885FE407E} - System32\Tasks\{B8475E7F-7DC6-4E2A-9211-0988C160EF29} => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe Task: {4BC86048-D73D-494C-9097-787B4204F419} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe [2012-09-27] (Hewlett-Packard Company) Task: {5ACE409D-46FE-4438-BFC1-F8CF7AE6F9BD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-09-16] (Adobe Systems Incorporated) Task: {5B5355C3-EE67-42A1-B7CF-483F811A8760} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-02-09] (CyberLink) Task: {6571D27E-385D-4F41-B00C-5215795FED74} - System32\Tasks\{42894C95-CACE-48E5-8FA9-03180ABC6D82} => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe Task: {68CA80D4-1FF7-492E-BD65-760A143AE7EC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {6D5BFAAA-275C-4D0E-A9BB-91E2061AAFE5} - System32\Tasks\{86259AB4-CAA0-43BB-B56E-53709CCA447D} => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe Task: {6E711631-98AA-43F3-8118-743390CFC489} - System32\Tasks\{1D96B393-3B3C-4731-8BBE-C2A5818DD354} => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe Task: {7B83BDCF-7C23-436A-8267-17ABA62CE60D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Critical Actions Pending => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {7D0247AD-5E74-4FA5-9769-55A2D7258C6A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {8169F1E9-C2E8-49DD-BB2F-C22EAD139BF4} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-01-25] () Task: {8BAF0E94-1164-4AA1-9246-1A4BCEF80CEC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2017-08-22] (Microsoft) Task: {9B5A52DD-5DE6-42A1-8F04-8B444E98F642} - System32\Tasks\{47336EC5-94B1-4769-AFED-39EDEF2A6709} => C:\Windows\system32\pcalua.exe -a E:\Welcome.exe -d E:\ Task: {A98FEF5B-1F03-4F67-A197-486DC3390D76} - System32\Tasks\{C1DBE46F-1E15-4A65-9A75-42E1DF8ADE50} => C:\Windows\system32\pcalua.exe -a G:\Setup.exe -d G:\ -c AUTORUN=1 Task: {AD09541C-96BD-4B9F-BCBA-EBC056C95054} - System32\Tasks\{763FF240-EEDA-4A2C-A2D0-8619FFE41BCB} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\ Task: {B7E5A2D2-F895-411F-BA60-34030188AD02} - System32\Tasks\{75924CED-E37F-454E-83A7-E68F9ED175C1} => C:\Windows\system32\pcalua.exe -a G:\.\Setup.exe -d G:\ -c AUTORUN=1 Task: {DAAB9442-83F9-4B78-8284-7DF90A834060} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {EA2A10A6-79F2-4385-8C8F-22190E2D1048} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe [2016-02-18] (Hewlett-Packard) Task: {F4921E79-0823-44E9-93A6-0B475AF75A6A} - System32\Tasks\HPCeeScheduleForRudi => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\HPCeeScheduleForRUDI-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\HPCeeScheduleForRudi.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Verknüpfungen & WMI ======================== (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2013-07-21 20:20 - 2011-04-25 12:24 - 000034304 _____ () C:\Windows\System32\ssj1mlm.dll 2012-03-13 20:46 - 2017-03-28 11:18 - 000638128 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe 2012-03-13 20:46 - 2017-03-28 11:18 - 000989872 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe 2011-03-04 11:43 - 2011-03-04 11:43 - 000079872 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Services.dll 2011-03-04 11:44 - 2011-03-04 11:44 - 000073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2017-03-28 11:18 - 2017-03-28 11:18 - 000275456 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgMobileBroadband7.dll 2014-01-12 21:20 - 2007-04-19 09:33 - 000035584 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\uPiApi.dll 2014-01-12 21:20 - 2007-04-19 09:39 - 000436992 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\fpxlib.dll 2014-01-12 21:20 - 2007-04-19 09:29 - 000273216 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\magengin.dll 2014-01-12 21:20 - 2007-04-19 09:29 - 000187136 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\kgl.dll 2009-07-13 22:03 - 2009-07-14 02:15 - 000364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Temp:905844AA [123] AlternateDataStreams: C:\ProgramData\Temp:F23153EE [316] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\samsungsetup.com -> hxxp://www.samsungsetup.com ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2009-06-10 22:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{D9AD44F7-1DFE-410E-B0FB-82B5A0CE82A7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{AB8FE59C-23B6-483C-AEBA-1DF54E48DA13}] => (Allow) LPort=2869 FirewallRules: [{539FF5B6-5F05-478D-8269-9BBE0D206530}] => (Allow) LPort=1900 FirewallRules: [{D7CA6EE1-06CE-4DAE-B758-3DFE14C345FE}] => (Allow) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TotalMedia.exe FirewallRules: [{9ED8155D-61E8-4366-B0DD-457B5188C09B}] => (Allow) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TotalMedia.exe FirewallRules: [{F59A8F2A-74AE-455A-92DF-B2DEEB078239}] => (Allow) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TotalMedia.exe FirewallRules: [{96E5E0EE-55A8-45DB-BD75-AAC90A5B45D1}] => (Allow) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TotalMedia.exe FirewallRules: [{3515664A-DC6A-4443-BF52-DDAAC30CAFE0}] => (Allow) C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\USBSetup.exe ==================== Wiederherstellungspunkte ========================= 01-01-2011 03:05:52 Geplanter Prüfpunkt ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/01/2011 04:04:18 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Error: (12/31/2010 11:02:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist. Systemfehler: ============= CodeIntegrity: =================================== Date: 2012-10-13 13:23:53.000 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Rudi\AppData\Local\Temp\ListOpenedFileDrv_64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-10-13 13:23:52.906 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Rudi\AppData\Local\Temp\ListOpenedFileDrv_64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-10-13 13:23:47.649 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Rudi\AppData\Local\Temp\ListOpenedFileDrv_64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-10-13 13:23:47.571 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Rudi\AppData\Local\Temp\ListOpenedFileDrv_64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-10-13 13:23:18.839 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Rudi\AppData\Local\Temp\ListOpenedFileDrv_64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-10-13 13:23:18.761 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Rudi\AppData\Local\Temp\ListOpenedFileDrv_64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-10-13 13:22:42.083 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Rudi\AppData\Local\Temp\ListOpenedFileDrv_64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-10-13 13:22:41.989 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Rudi\AppData\Local\Temp\ListOpenedFileDrv_64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: AMD E-240 Processor Prozentuale Nutzung des RAM: 37% Installierter physikalischer RAM: 3690.91 MB Verfügbarer physikalischer RAM: 2303.52 MB Summe virtueller Speicher: 7380 MB Verfügbarer virtueller Speicher: 5446.53 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:217.64 GB) (Free:156.55 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive d: (RECOVERY) (Fixed) (Total:14.95 GB) (Free:1.85 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)] Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32 ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: DA9A0C0E) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=217.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== Ende von Addition.txt ============================ |
19.09.2017, 11:14 | #4 |
| Frst1Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 17-09-2017 01 durchgeführt von Rudi (Administrator) auf RUDI-HP (01-01-2011 04:53:59) Gestartet von C:\Users\Rudi\Documents Geladene Profile: Rudi (Verfügbare Profile: Rudi) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: IE) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (Advanced Micro Devices) C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sonix) C:\Windows\vsnp2uvc.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6602856 2011-01-11] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-21] (Synaptics Incorporated) HKLM\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe [662016 2009-08-12] (Sonix) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [919032 2011-01-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [tsnp2uvc] => C:\Program Files (x86)\Common Files\SNP2UVC\tsnp2uvc.exe [249856 2012-05-04] (Sonix Technology Co., Ltd.) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [97512 2017-06-08] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\Run: [jICc7n9BYxBTRVw] => C:\Users\Rudi\AppData\Roaming\wsf3CmCT.exe HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: G - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {259dbd5c-0af1-11e1-a5de-68a3c4d1c179} - H:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {259dbd6a-0af1-11e1-a5de-68a3c4d1c179} - H:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {49be8cdd-0a9b-11e6-ac1b-001e101fe70e} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {49be8cf4-0a9b-11e6-ac1b-001e101fe70e} - I:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {59830c6f-7426-11e2-860a-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {8d84e8c3-a7bc-11e5-b629-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {941e22fb-0baf-11e6-a331-68a3c4d1c179} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {a582d1be-6e04-11e1-a1ac-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {a582d1ed-6e04-11e1-a1ac-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {a7f078b1-01bf-11e2-8346-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {a8a4e724-5a34-11e1-b6d3-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {d2644492-3c42-11e4-94eb-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {de238638-a76d-11e5-941e-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {eb065f82-6bd9-11e4-8deb-68a3c4d1c179} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {f7a549b0-0a51-11e6-b6a0-001e101faa49} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {f7a549bb-0a51-11e6-b6a0-001e101faa49} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {f7a549c7-0a51-11e6-b6a0-001e101faa49} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {f7a549da-0a51-11e6-b6a0-001e101faa49} - G:\.\Setup.exe AUTORUN=1 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launcher.lnk [2012-03-13] ShortcutTarget: Launcher.lnk -> C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk [2014-01-12] ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 1000 J110 series.lnk [2011-01-01] ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 1000 J110 series.lnk -> C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{11C79F3D-A2B6-4D0D-83FC-40AC6DE02E73}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{1DF2F6FF-4DBF-4503-901A-8A2AF11234A7}: [NameServer] 212.23.115.132 212.23.115.148 Tcpip\..\Interfaces\{53C50116-1412-438A-B596-75C78F0FBBA1}: [NameServer] 212.23.115.148 212.23.115.132 Tcpip\..\Interfaces\{662DEAA7-E456-40C8-B329-C9C9583C068B}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{C3A6E741-61B3-4216-BD2F-56DF34EF4B04}: [NameServer] 212.23.115.148 212.23.115.132 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://web.de/ HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM-x32 -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> Keine Datei BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-02] (Oracle Corporation) BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-06] (Atheros Commnucations) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-02] (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard) Toolbar: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab FireFox: ======== FF ProfilePath: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\xrow3d6a.default [2016-09-20] FF NetworkProxy: Mozilla\Firefox\Profiles\xrow3d6a.default -> type", 0 FF SelectedSearchEngine: Mozilla\Firefox\Profiles\xrow3d6a.default -> MyPlayCity Search FF Keyword.URL: Mozilla\Firefox\Profiles\xrow3d6a.default -> hxxp://home.myplaycity.com/results.php?category=web&s= FF Homepage: Mozilla\Firefox\Profiles\xrow3d6a.default -> hxxp://home.myplaycity.com/ FF Extension: (MyPlayCity Toolbar) - C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\xrow3d6a.default\Extensions\{A9897564-CA29-4CAE-8A26-453035570837} [2012-04-09] [ist nicht signiert] FF SearchPlugin: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\xrow3d6a.default\searchplugins\myplaycity-search.xml [2012-01-31] FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-02] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-02] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S4 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [638128 2017-03-28] () R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [354304 2011-03-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] R2 AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [194496 2010-06-17] (Advanced Micro Devices) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1128432 2011-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [490968 2011-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [490968 2011-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1525240 2011-01-01] (Avira Operations GmbH & Co. KG) S3 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-06] (Atheros) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [356256 2017-06-08] (Avira Operations GmbH & Co. KG) S3 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1817088 2010-12-28] (Realsil Microelectronics Inc.) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S4 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-02-25] (Xobni Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [64504 2017-06-21] (Avira Operations GmbH & Co. KG) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [194912 2011-01-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [151128 2011-01-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-02-25] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2017-02-25] (Avira Operations GmbH & Co. KG) S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2012-03-13] (Huawei Technologies Co., Ltd.) S3 ewusbnet; C:\Windows\SysWOW64\DRIVERS\ewusbnet.sys [256000 2012-03-13] (Huawei Technologies Co., Ltd.) S3 ew_hwusbdev; C:\Windows\SysWOW64\DRIVERS\ew_hwusbdev.sys [117248 2012-03-13] (Huawei Technologies Co., Ltd.) S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [121600 2012-03-13] (Huawei Technologies Co., Ltd.) S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [113280 2014-01-12] (ITE ) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3568128 2012-06-27] () S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-26 10:19 - 2017-06-26 10:19 - 000001096 _____ C:\Users\Public\Desktop\Avira Connect.lnk 2017-06-23 12:35 - 2017-09-16 20:16 - 000003180 _____ C:\Windows\System32\Tasks\HPCeeScheduleForRudi 2017-06-23 12:34 - 1817-09-17 10:22 - 000000328 _____ C:\Windows\Tasks\HPCeeScheduleForRudi.job 2017-06-21 06:02 - 2017-06-21 05:58 - 000064504 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avdevprot.sys 2017-06-17 10:03 - 2017-05-14 21:19 - 025738752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-06-17 10:03 - 2017-05-14 20:11 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-06-17 10:03 - 2017-04-27 23:50 - 003550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2017-06-17 10:03 - 2017-04-12 14:05 - 004296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 002317824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-06-17 10:02 - 2017-06-02 09:11 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-06-17 10:02 - 2017-06-02 09:11 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-06-17 10:02 - 2017-06-02 09:10 - 000733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-06-17 10:02 - 2017-06-02 09:10 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-06-17 10:02 - 2017-06-02 09:09 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2017-06-17 10:02 - 2017-06-02 08:58 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-06-17 10:02 - 2017-06-02 08:58 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2017-06-17 10:02 - 2017-06-02 08:57 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2017-06-17 10:02 - 2017-06-02 08:57 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2017-06-17 10:02 - 2017-05-21 05:28 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-06-17 10:02 - 2017-05-21 05:28 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-06-17 10:02 - 2017-05-21 05:24 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-06-17 10:02 - 2017-05-21 05:24 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-06-17 10:02 - 2017-05-21 05:06 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-06-17 10:02 - 2017-05-16 19:19 - 000394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-06-17 10:02 - 2017-05-16 18:35 - 000346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-06-17 10:02 - 2017-05-14 21:26 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-06-17 10:02 - 2017-05-14 21:24 - 002899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-06-17 10:02 - 2017-05-14 21:17 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-06-17 10:02 - 2017-05-14 21:12 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-06-17 10:02 - 2017-05-14 21:10 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-06-17 10:02 - 2017-05-14 21:01 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-06-17 10:02 - 2017-05-14 20:55 - 005975040 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-06-17 10:02 - 2017-05-14 20:36 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-06-17 10:02 - 2017-05-14 20:23 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-06-17 10:02 - 2017-05-14 20:22 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-06-17 10:02 - 2017-05-14 20:19 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-06-17 10:02 - 2017-05-14 20:18 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-06-17 10:02 - 2017-05-14 20:17 - 002132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-06-17 10:02 - 2017-05-14 20:16 - 002290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-06-17 10:02 - 2017-05-14 20:10 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-06-17 10:02 - 2017-05-14 19:54 - 015252992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-06-17 10:02 - 2017-05-14 19:52 - 003240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-06-17 10:02 - 2017-05-14 19:44 - 004549120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-06-17 10:02 - 2017-05-14 19:40 - 000693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-06-17 10:02 - 2017-05-14 19:39 - 002057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-06-17 10:02 - 2017-05-14 19:38 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-06-17 10:02 - 2017-05-14 19:37 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-06-17 10:02 - 2017-05-14 19:30 - 013664768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-06-17 10:02 - 2017-05-14 19:15 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-06-17 10:02 - 2017-05-14 19:11 - 001314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-06-17 10:02 - 2017-05-12 19:27 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-06-17 10:02 - 2017-05-12 19:26 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-06-17 10:02 - 2017-05-12 19:26 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-06-17 10:02 - 2017-05-12 19:26 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2017-06-17 10:02 - 2017-05-12 19:24 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-06-17 10:02 - 2017-05-12 19:22 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-06-17 10:02 - 2017-05-12 19:22 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-06-17 10:02 - 2017-05-12 19:07 - 004001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-06-17 10:02 - 2017-05-12 19:07 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-06-17 10:02 - 2017-05-12 19:07 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2017-06-17 10:02 - 2017-05-12 19:04 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-06-17 10:02 - 2017-05-12 19:03 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-06-17 10:02 - 2017-05-12 19:03 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-06-17 10:02 - 2017-05-12 18:52 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-06-17 10:02 - 2017-05-12 16:58 - 001648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-06-17 10:02 - 2017-05-10 16:33 - 000091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe 2017-06-17 10:02 - 2017-05-10 16:29 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-06-17 10:02 - 2017-05-10 16:29 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2017-06-17 10:02 - 2017-05-10 16:16 - 000091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe 2017-06-17 10:02 - 2017-05-10 16:14 - 002651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-06-17 10:02 - 2017-05-10 16:12 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-06-17 10:02 - 2017-05-10 15:52 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2017-06-17 10:02 - 2017-05-09 16:30 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-06-17 10:02 - 2017-05-09 16:29 - 000970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2017-06-17 10:02 - 2017-05-09 16:11 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-06-17 10:02 - 2017-05-07 16:33 - 000094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2017-06-17 10:02 - 2017-03-30 16:03 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe 2017-06-17 10:02 - 2017-03-30 15:58 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe 2017-06-17 10:01 - 2017-05-21 05:24 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-06-17 10:01 - 2017-05-21 04:55 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-06-17 10:01 - 2017-05-21 04:48 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-06-17 10:01 - 2017-05-21 04:48 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-06-17 10:01 - 2017-05-21 04:48 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-06-17 10:01 - 2017-05-21 04:47 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-06-17 10:01 - 2017-05-21 04:46 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-06-17 10:01 - 2017-05-21 04:42 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-06-17 10:01 - 2017-05-14 21:46 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-06-17 10:01 - 2017-05-14 21:46 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-06-17 10:01 - 2017-05-14 21:28 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-06-17 10:01 - 2017-05-14 21:27 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-06-17 10:01 - 2017-05-14 21:27 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-06-17 10:01 - 2017-05-14 21:27 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-06-17 10:01 - 2017-05-14 21:16 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-06-17 10:01 - 2017-05-14 21:10 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-06-17 10:01 - 2017-05-14 21:10 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-06-17 10:01 - 2017-05-14 21:10 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-06-17 10:01 - 2017-05-14 20:57 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-06-17 10:01 - 2017-05-14 20:48 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-06-17 10:01 - 2017-05-14 20:47 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-06-17 10:01 - 2017-05-14 20:46 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-06-17 10:01 - 2017-05-14 20:42 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-06-17 10:01 - 2017-05-14 20:41 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-06-17 10:01 - 2017-05-14 20:38 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-06-17 10:01 - 2017-05-14 20:37 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-06-17 10:01 - 2017-05-14 20:23 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-06-17 10:01 - 2017-05-14 20:22 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-06-17 10:01 - 2017-05-14 20:22 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-06-17 10:01 - 2017-05-14 20:21 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-06-17 10:01 - 2017-05-14 20:20 - 000725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-06-17 10:01 - 2017-05-14 20:15 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-06-17 10:01 - 2017-05-14 20:14 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-06-17 10:01 - 2017-05-14 20:12 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-06-17 10:01 - 2017-05-14 20:11 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-06-17 10:01 - 2017-05-14 20:10 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-06-17 10:01 - 2017-05-14 20:02 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-06-17 10:01 - 2017-05-14 19:57 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2017-06-17 10:01 - 2017-05-14 19:57 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-06-17 10:01 - 2017-05-14 19:56 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-06-17 10:01 - 2017-05-14 19:53 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-06-17 10:01 - 2017-05-14 19:52 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-06-17 10:01 - 2017-05-14 19:50 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-06-17 10:01 - 2017-05-14 19:49 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-06-17 10:01 - 2017-05-14 19:42 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-06-17 10:01 - 2017-05-14 19:27 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-06-17 10:01 - 2017-05-14 19:11 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 18:55 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-06-17 10:01 - 2017-05-12 18:54 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-06-17 10:01 - 2017-05-12 18:54 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-06-17 10:01 - 2017-05-12 18:51 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-06-17 10:01 - 2017-05-12 18:50 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-06-17 10:01 - 2017-05-12 18:46 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-06-17 10:01 - 2017-05-12 18:43 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2017-06-17 10:01 - 2017-05-12 18:41 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-06-17 10:01 - 2017-05-12 18:41 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-06-17 10:01 - 2017-05-12 18:41 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-06-17 10:01 - 2017-05-12 18:41 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-06-17 10:01 - 2017-05-12 18:40 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 18:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 18:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 18:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 17:25 - 001251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-06-17 10:01 - 2017-05-12 16:58 - 001180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-06-17 10:01 - 2017-05-10 16:29 - 003165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-06-17 10:01 - 2017-05-10 16:29 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-06-17 10:01 - 2017-05-10 16:29 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-06-17 10:01 - 2017-05-10 16:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-06-17 10:01 - 2017-05-10 16:13 - 000709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-06-17 10:01 - 2017-05-10 16:13 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-06-17 10:01 - 2017-05-10 16:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-06-17 10:01 - 2017-05-10 16:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-06-17 10:01 - 2017-05-10 16:13 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-06-17 10:01 - 2017-05-10 16:13 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2017-06-17 10:01 - 2017-05-10 16:12 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2017-06-17 10:01 - 2017-05-10 16:12 - 000174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-06-17 10:01 - 2017-05-10 16:00 - 000573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-06-17 10:01 - 2017-05-10 16:00 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-06-17 10:01 - 2017-05-10 16:00 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-06-17 10:01 - 2017-05-10 16:00 - 000030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-06-17 10:01 - 2017-05-07 16:29 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2017-05-12 14:26 - 2017-04-21 16:34 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2017-05-12 14:26 - 2017-04-21 16:15 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 000876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll 2017-05-12 14:26 - 2017-04-17 16:12 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2017-05-12 14:26 - 2017-04-17 16:12 - 000581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2017-05-12 14:26 - 2017-04-17 16:12 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll 2017-05-12 14:26 - 2017-04-17 15:54 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll 2017-05-12 14:26 - 2017-04-12 16:32 - 001483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2017-05-12 14:26 - 2017-04-12 16:32 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2017-05-12 14:26 - 2017-04-12 16:32 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2017-05-12 14:26 - 2017-04-12 16:32 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2017-05-12 14:26 - 2017-04-12 16:26 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2017-05-12 14:26 - 2017-04-12 16:25 - 001176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2017-05-12 14:26 - 2017-04-12 16:25 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2017-05-12 14:26 - 2017-04-12 16:25 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2017-05-12 14:26 - 2017-04-07 16:34 - 000986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-05-12 14:26 - 2017-04-07 16:34 - 000265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2017-05-12 14:26 - 2017-04-07 16:30 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2017-05-12 14:26 - 2017-04-05 15:55 - 000460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-05-12 14:26 - 2017-04-05 15:55 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-05-12 14:26 - 2017-04-05 15:55 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-05-12 14:26 - 2017-04-04 16:34 - 001895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2017-05-12 14:26 - 2017-04-04 16:34 - 000377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2017-05-12 14:26 - 2017-04-04 16:34 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2017-05-12 14:26 - 2017-04-04 15:53 - 000496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2017-05-12 14:26 - 2017-03-10 17:32 - 001389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll 2017-05-12 14:26 - 2017-03-10 17:32 - 000300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll 2017-05-12 14:26 - 2017-03-10 17:20 - 001508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll 2017-05-12 14:26 - 2017-03-10 17:20 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll 2017-05-12 14:26 - 2017-03-10 16:57 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe 2017-05-12 14:26 - 2017-03-10 16:55 - 000205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2017-05-12 14:26 - 2017-03-10 16:55 - 000195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys 2017-05-12 14:25 - 2017-03-09 17:34 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-05-12 14:25 - 2017-03-09 17:19 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-05-09 10:43 - 2017-05-09 10:43 - 000099871 _____ C:\Users\Rudi\Documents\0002075041_Jahressteuerbescheinigung_und_Erträgnisaufstellung_983904725922209000.pdf 2017-04-29 09:35 - 2017-03-04 02:27 - 001574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-04-29 09:35 - 2017-03-04 02:14 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-04-29 09:35 - 2017-02-09 17:32 - 000769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-04-29 09:34 - 2017-03-07 17:30 - 000085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2017-04-29 09:34 - 2017-03-07 17:17 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2017-04-29 09:34 - 2017-03-04 02:27 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll 2017-04-29 09:34 - 2017-03-04 02:14 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll 2017-04-29 09:34 - 2017-02-09 17:32 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-04-29 09:34 - 2017-02-09 17:14 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-03-28 11:38 - 2017-03-28 11:53 - 000000000 ____D C:\Users\Rudi\Documents\Hanse Merkur Erstattungen 2017-03-26 19:33 - 2017-03-26 19:33 - 000028344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll 2017-03-26 19:33 - 2017-03-26 19:33 - 000019104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110_clr0400.dll 2017-03-26 19:33 - 2017-03-26 19:33 - 000019104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100_clr0400.dll 2017-03-26 19:33 - 2017-03-26 19:33 - 000019104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110_clr0400.dll 2017-03-26 19:29 - 2017-03-26 19:29 - 000030400 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll 2017-03-26 19:29 - 2017-03-26 19:29 - 000019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcr110_clr0400.dll 2017-03-26 19:29 - 2017-03-26 19:29 - 000019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll 2017-03-26 19:29 - 2017-03-26 19:29 - 000019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcp110_clr0400.dll 2017-03-16 16:44 - 2017-02-09 17:32 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-03-16 16:44 - 2017-02-09 17:31 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-03-16 16:44 - 2017-02-09 17:31 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-03-16 16:44 - 2017-02-09 17:14 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-03-16 16:44 - 2017-02-09 17:14 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-03-16 16:44 - 2017-02-09 16:51 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-03-16 16:44 - 2017-01-13 19:00 - 000976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-03-16 16:44 - 2017-01-13 19:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-03-16 16:44 - 2017-01-13 18:45 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-03-16 16:44 - 2017-01-13 18:45 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-03-16 16:44 - 2017-01-11 19:01 - 001887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-03-16 16:44 - 2017-01-11 19:01 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-03-16 16:44 - 2017-01-11 18:43 - 001241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-03-16 16:43 - 2017-01-11 18:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-03-16 16:39 - 2017-02-23 00:42 - 000084712 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-03-16 16:39 - 2017-02-23 00:37 - 001285632 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-03-16 16:39 - 2017-02-18 15:05 - 001609216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-03-16 16:39 - 2017-02-18 15:05 - 000646656 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000556544 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000335360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000293376 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000233984 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000133632 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-03-11 18:54 - 2017-03-11 18:54 - 000067513 _____ C:\Users\Rudi\Documents\Buchungsanfrage_R780398-A139608-2595.pdf 2017-03-11 18:37 - 2017-03-11 18:37 - 000063231 _____ C:\Users\Rudi\Documents\Bösehof Buchung.pdf 2017-03-09 17:13 - 2017-03-09 17:13 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\java 2017-03-09 17:01 - 2017-03-09 17:01 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Servicecenter 2017-03-09 17:01 - 2017-03-09 17:01 - 000000000 ____D C:\Users\Rudi\.swt 2017-03-02 14:31 - 2017-03-02 15:17 - 000000000 ____D C:\Users\Rudi\Documents\Sicherung S5 2017-02-25 18:36 - 2017-02-25 18:36 - 000000000 ____D C:\Users\Rudi\AppData\Local\{6754908E-CC15-4E62-B8CF-E68246AB0A88} 2017-02-25 15:13 - 2017-02-25 15:13 - 000000000 ____D C:\Users\Rudi\Documents\Bluetooth Folder 2017-02-24 14:51 - 2017-05-12 14:44 - 000000000 ____D C:\Users\Rudi\Documents\Schriftverkehr 2017-02-24 14:40 - 2017-02-24 14:40 - 000000000 ____D C:\Users\Rudi\AppData\Local\{C1635CC3-3158-49EE-9574-7D69C2771953} 2017-02-24 14:30 - 2017-03-02 13:24 - 000000000 ____D C:\Users\Rudi\Documents\Dana WWK 2017-02-17 15:16 - 2017-02-17 15:16 - 000000000 ____D C:\Users\Rudi\AppData\Local\{3803325C-C691-48DD-971B-81FE562ED737} 2017-02-14 14:11 - 2017-02-14 14:11 - 000002055 _____ C:\Users\Public\Desktop\WISO steuer Sparbuch 2017.lnk 2017-02-14 14:09 - 2017-02-14 14:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO steuer Sparbuch 2017 2017-01-18 12:21 - 2017-01-24 17:12 - 000000000 ____D C:\Users\Rudi\Documents\International Service Check 2016-12-19 11:39 - 2016-12-19 11:39 - 000001202 _____ C:\Users\Rudi\Desktop\Avira Antivirus starten.lnk 2016-12-14 11:54 - 2016-11-21 19:12 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll 2016-12-14 11:54 - 2016-11-20 17:19 - 000084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll 2016-12-14 11:54 - 2016-11-20 15:07 - 000467392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2016-12-14 11:54 - 2016-11-17 17:41 - 000370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2016-12-14 11:54 - 2016-11-10 17:32 - 001009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2016-12-14 11:54 - 2016-11-10 17:19 - 000833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2016-12-14 11:54 - 2016-11-09 17:41 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2016-12-14 11:54 - 2016-11-09 17:33 - 003244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2016-12-14 11:54 - 2016-11-09 17:33 - 001941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2016-12-14 11:54 - 2016-11-09 17:33 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2016-12-14 11:54 - 2016-11-09 17:33 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2016-12-14 11:54 - 2016-11-09 17:33 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2016-12-14 11:54 - 2016-11-09 17:17 - 002365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2016-12-14 11:54 - 2016-11-09 17:17 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2016-12-14 11:54 - 2016-11-09 17:17 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2016-12-14 11:54 - 2016-11-09 17:17 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2016-12-14 11:54 - 2016-11-09 17:02 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2016-12-14 11:54 - 2016-11-09 16:55 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2016-12-14 11:54 - 2016-10-11 16:32 - 000069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll 2016-12-14 11:54 - 2016-10-11 16:18 - 000069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2016-12-14 11:54 - 2016-10-11 15:55 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe 2016-12-14 11:54 - 2016-10-11 14:18 - 000419648 _____ C:\Windows\SysWOW64\locale.nls 2016-12-14 11:54 - 2016-10-11 14:17 - 000419648 _____ C:\Windows\system32\locale.nls 2016-12-14 11:54 - 2016-10-08 14:06 - 000633296 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2016-12-09 12:45 - 2017-06-29 14:31 - 000000000 ____D C:\Users\Rudi\Documents\Knappschaft 2016-12-02 13:02 - 2017-03-26 17:52 - 000000000 ____D C:\Users\Rudi\Documents\BG ETEM 2016-11-22 15:59 - 2017-03-22 14:16 - 000196096 _____ C:\Users\Rudi\Documents\ZH1.axe 2016-11-17 16:57 - 2017-06-26 11:41 - 000196096 _____ C:\Users\Rudi\Documents\ZH.axe 2016-11-14 16:12 - 2016-11-14 16:12 - 000000000 ____D C:\Users\Rudi\AppData\Local\{2AAB1E71-4CEF-4544-99A0-06284543290B} 2016-11-12 13:19 - 1817-09-17 11:41 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Ability5 2016-11-12 13:17 - 2016-11-12 13:17 - 000000000 ____D C:\Users\Rudi\Documents\DbgLogs 2016-11-12 13:14 - 2012-09-04 13:41 - 006617528 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\system32\cdintf450_64.dll 2016-11-12 13:14 - 2012-09-04 13:41 - 004897720 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\SysWOW64\cdintf450.dll 2016-11-12 13:13 - 2016-11-12 13:13 - 000000958 _____ C:\Users\Public\Desktop\Ability Presentation.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000953 _____ C:\Users\Public\Desktop\Ability Spreadsheet.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000946 _____ C:\Users\Public\Desktop\Ability Write.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000946 _____ C:\Users\Public\Desktop\Ability Photopaint.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000941 _____ C:\Users\Public\Desktop\Ability Database.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ability Office 6 2016-11-12 13:13 - 2016-11-12 13:13 - 000000000 ____D C:\Program Files (x86)\Ability Office 6 2016-11-10 12:05 - 2017-06-29 14:33 - 000687104 ___SH C:\Users\Rudi\Documents\Thumbs.db 2016-11-09 12:18 - 2016-10-11 16:31 - 001148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME 2016-11-09 12:18 - 2016-10-11 16:31 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2016-11-09 12:18 - 2016-10-11 16:31 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2016-11-09 12:18 - 2016-10-11 16:31 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll 2016-11-09 12:18 - 2016-10-11 16:31 - 000176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 001027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME 2016-11-09 12:18 - 2016-10-11 16:18 - 000829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2016-11-09 12:18 - 2016-10-11 16:18 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2016-11-09 12:18 - 2016-10-11 16:18 - 000430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll 2016-11-09 12:18 - 2016-10-11 16:18 - 000126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime 2016-11-09 12:18 - 2016-10-11 14:33 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2016-11-09 12:18 - 2016-10-11 14:06 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2016-11-09 12:18 - 2016-10-07 16:32 - 003649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll 2016-11-09 12:18 - 2016-10-07 16:12 - 002291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll 2016-11-09 12:18 - 2016-10-05 15:54 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2016-11-09 12:18 - 2016-09-15 15:56 - 000041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2016-11-09 12:17 - 2016-08-22 17:19 - 001386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2016-10-25 16:50 - 2016-10-25 16:50 - 000000000 ____D C:\Users\Rudi\AppData\Local\{ED68FA0C-EEBE-423A-AA74-CFC26BE7537C} 2016-10-25 16:32 - 2017-02-04 13:08 - 000000000 ____D C:\Users\Rudi\Documents\MysteryPanel 2016-10-24 16:35 - 2017-02-10 17:15 - 000000000 ____D C:\Users\Rudi\Documents\ebay Kleinanzeigen 2016-10-24 09:15 - 2017-02-04 13:09 - 000000000 ____D C:\Users\Rudi\Documents\NEXT Skopos 2016-10-17 11:24 - 2017-02-04 13:09 - 000000000 ____D C:\Users\Rudi\Documents\Performance 2016-10-15 14:59 - 2017-02-25 15:07 - 000000000 ____D C:\Users\Rudi\Documents\Steuer 2016-10-15 11:02 - 2016-10-15 14:34 - 000000000 ____D C:\Users\Rudi\Documents\Rente 2016-10-15 10:37 - 2017-06-21 05:58 - 000034128 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avusbflt.sys 2016-10-12 09:41 - 2016-08-12 18:02 - 014632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2016-10-12 09:41 - 2016-08-12 17:47 - 011410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2016-10-12 09:41 - 2016-08-12 17:26 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2016-10-12 09:41 - 2016-08-06 16:31 - 002023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2016-10-12 09:41 - 2016-08-06 16:15 - 001178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2016-10-12 09:41 - 2016-06-14 18:16 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2016-10-12 09:41 - 2016-06-14 18:16 - 001202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2016-10-12 09:41 - 2016-06-14 18:16 - 000842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2016-10-12 09:41 - 2016-06-14 18:16 - 000782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2016-10-12 09:41 - 2016-06-14 16:21 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2016-10-12 09:41 - 2016-06-14 16:21 - 000988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2016-10-12 09:41 - 2016-06-14 16:21 - 000744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2016-10-12 09:41 - 2016-06-14 16:21 - 000617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2016-10-12 09:40 - 2016-09-12 22:08 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll 2016-10-12 09:40 - 2016-09-12 21:49 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll 2016-10-12 09:40 - 2016-09-08 21:34 - 000263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2016-10-12 09:40 - 2016-09-08 21:34 - 000208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2016-10-12 09:40 - 2016-09-08 21:34 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2016-10-12 09:40 - 2016-09-08 21:34 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2016-10-12 09:40 - 2016-09-08 15:55 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2016-10-12 09:40 - 2016-09-08 15:55 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys 2016-10-12 09:40 - 2016-08-12 18:02 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2016-10-12 09:40 - 2016-08-12 18:02 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2016-10-12 09:40 - 2016-08-12 18:02 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2016-10-12 09:40 - 2016-08-12 18:02 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2016-10-12 09:40 - 2016-08-12 17:47 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2016-10-12 09:40 - 2016-08-12 17:31 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2016-10-12 09:40 - 2016-08-12 17:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2016-10-12 09:40 - 2016-08-12 17:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2016-10-12 09:40 - 2016-08-06 16:31 - 000347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2016-10-12 09:40 - 2016-08-06 16:31 - 000310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2016-10-12 09:40 - 2016-08-06 16:31 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2016-10-12 09:40 - 2016-08-06 16:31 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll 2016-10-12 09:40 - 2016-08-06 16:15 - 000249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2016-10-12 09:40 - 2016-08-06 16:15 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2016-10-12 09:40 - 2016-08-06 16:15 - 000146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2016-10-12 09:40 - 2016-08-06 16:01 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2016-10-12 09:40 - 2016-08-06 16:01 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe 2016-10-12 09:40 - 2016-08-06 15:53 - 000199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2016-10-12 09:40 - 2016-08-06 15:53 - 000012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe 2016-10-12 09:40 - 2016-08-06 15:53 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2016-10-12 09:40 - 2016-06-14 18:11 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2016-10-12 09:40 - 2016-06-14 16:21 - 001005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2016-10-12 09:40 - 2016-06-14 16:15 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2016-10-12 09:40 - 2016-06-14 16:15 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2016-10-12 09:40 - 2016-06-14 16:15 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2016-10-12 09:40 - 2016-06-14 16:05 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2016-10-12 09:40 - 2016-06-14 16:05 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2016-10-12 09:40 - 2016-06-14 16:00 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2016-10-12 09:40 - 2016-06-14 16:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2016-10-12 09:39 - 2016-08-06 16:31 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll 2016-10-12 09:39 - 2016-08-06 16:15 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll 2016-10-12 09:39 - 2016-06-14 18:16 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2016-10-12 09:39 - 2016-06-14 16:21 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2016-10-12 09:32 - 2016-07-22 15:58 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2016-10-12 09:32 - 2016-07-22 15:51 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2016-10-12 09:26 - 2016-08-16 21:40 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2016-10-12 09:25 - 2016-08-29 16:04 - 003229696 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2016-10-12 09:25 - 2016-08-29 15:55 - 002972672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2016-10-11 16:20 - 2017-03-08 15:58 - 000000000 ____D C:\Users\Rudi\Documents\MSM 2016-10-08 10:59 - 2017-03-12 14:46 - 000000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini 2016-10-08 10:59 - 2016-10-08 10:59 - 000000000 ____D C:\Users\Public\Documents\Atheros 2016-10-07 19:20 - 2016-10-07 19:20 - 000000000 ____D C:\Users\Rudi\AppData\Local\{C62911B6-2249-4E28-B35B-BD9C097F8B3A} 2016-10-07 18:52 - 2016-10-07 18:52 - 000000000 ____D C:\Users\Rudi\AppData\Local\{52BFEE37-115B-45C3-B61A-62741FFC7137} 2016-10-07 13:15 - 2011-05-30 13:42 - 000255488 _____ C:\Windows\system32\xvidvfw.dll 2016-10-07 13:15 - 2011-05-30 13:42 - 000240640 _____ C:\Windows\SysWOW64\xvidvfw.dll 2016-10-07 13:15 - 2011-05-23 07:46 - 000645632 _____ C:\Windows\SysWOW64\xvidcore.dll 2016-10-07 13:15 - 2011-05-23 07:45 - 000696832 _____ C:\Windows\system32\xvidcore.dll 2016-10-06 11:55 - 2017-06-11 10:49 - 000000000 ____D C:\Users\Rudi\Documents\Youcam 2016-10-05 16:29 - 2016-10-05 16:29 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Sun 2016-10-05 16:29 - 2016-10-05 16:29 - 000000000 ____D C:\Users\Rudi\.oracle_jre_usage 2016-10-02 10:38 - 1817-09-17 11:22 - 000197120 _____ C:\Users\Rudi\Documents\Dinklage bis Bippen.axe 2016-09-25 14:39 - 2016-09-25 14:39 - 000000234 _____ C:\Users\Rudi\Desktop\WEB.DE - E-Mail-Adresse kostenlos, FreeMail, De-Mail & Nachrichten.url 2016-09-24 16:00 - 2016-07-07 16:08 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2016-09-24 15:18 - 2016-05-12 16:18 - 000090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll 2016-09-14 14:22 - 2016-09-14 14:22 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\TuneUp Software 2016-09-14 14:08 - 2016-09-23 09:44 - 000000000 ____D C:\ProgramData\TuneUp Software 2016-09-14 09:09 - 2016-09-14 09:09 - 000000000 ____D C:\Users\Rudi\DxReport 2016-09-14 09:01 - 2016-09-14 09:01 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\LaunchPad 2016-09-05 05:47 - 2016-09-05 05:47 - 000165504 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudmdm.sys 2016-09-05 05:47 - 2016-09-05 05:47 - 000131712 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudbus.sys 2016-08-26 09:54 - 2016-08-26 09:54 - 000000000 ____D C:\Users\Rudi\AppData\Local\{450F5E8A-ABCD-48FA-9BE8-1BAE77A879B3} 2016-08-24 10:36 - 2016-08-24 10:36 - 000000000 ____D C:\Users\Rudi\AppData\Local\{7258F52A-C1F9-4672-AF5B-B26BF766D3D8} 2016-08-04 13:11 - 2016-08-04 13:11 - 000000000 ____D C:\Users\Rudi\AppData\Local\{42470E0F-B917-4A0A-B3D0-F2EA3CA55F6B} 2016-07-30 08:36 - 2011-01-01 04:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2016-07-26 12:41 - 2016-07-26 12:41 - 000001272 _____ C:\Users\Rudi\Desktop\Snipping Tool.lnk 2016-07-21 17:38 - 2016-07-21 17:39 - 000000000 ___HD C:\Windows\AxInstSV 2016-07-14 13:34 - 2016-07-14 13:34 - 000002272 _____ C:\Users\Public\Desktop\HP Deskjet 1000 J110 series.lnk 2016-07-14 13:34 - 2016-07-14 13:34 - 000001194 _____ C:\Users\Public\Desktop\Shop für Zubehör - HP Deskjet 1000 J110 series.lnk 2016-07-14 13:30 - 2016-07-14 13:30 - 000000000 ____D C:\Program Files\HP 2016-07-13 20:55 - 2016-06-26 01:27 - 000344576 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2016-07-13 20:55 - 2016-06-26 01:27 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2016-07-13 20:55 - 2016-06-26 01:27 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2016-07-13 20:55 - 2016-06-25 20:53 - 000297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll 2016-07-13 20:55 - 2016-06-25 20:53 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe 2016-07-13 20:55 - 2016-06-25 20:53 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe 2016-07-13 20:55 - 2016-06-25 20:41 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe 2016-07-13 12:39 - 2016-07-13 12:39 - 004775224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140u.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 004705072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000440128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000400192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcamp140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000267592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vccorlib140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000244032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\concrt140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000138560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcomp140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000095552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm140u.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000095032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000083792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcruntime140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000075584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140fra.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000075584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140deu.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000074560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140esn.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000073536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140ita.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000071488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140rus.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000065856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140enu.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000055104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140jpn.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000054080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140kor.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000046912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140cht.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000046912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140chs.dll 2016-07-01 17:27 - 2016-07-01 17:27 - 000000000 ____D C:\ProgramData\MetaQuotes 2016-07-01 17:06 - 2016-07-03 14:43 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\MetaQuotes 2016-06-29 18:00 - 2016-07-21 18:52 - 000000000 __SHD C:\Users\Rudi\Documents\cache 2016-06-29 18:00 - 2016-06-29 18:00 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\webex 2016-06-29 17:59 - 2016-07-21 18:05 - 000000000 _____ C:\ProgramData\WebEx 2016-06-17 19:51 - 2016-05-12 14:05 - 000297984 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2016-06-17 19:51 - 2016-05-12 14:04 - 000249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2016-06-17 19:49 - 2016-05-12 18:15 - 000105472 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll 2016-06-17 19:49 - 2016-05-12 18:14 - 000794624 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll 2016-06-17 19:49 - 2016-05-12 18:14 - 000502272 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL 2016-06-17 19:49 - 2016-05-12 18:14 - 000373760 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll 2016-06-17 19:49 - 2016-05-12 18:14 - 000096256 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll 2016-06-17 19:49 - 2016-05-12 18:14 - 000075776 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll 2016-06-17 19:49 - 2016-05-12 16:18 - 000274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll 2016-06-17 19:49 - 2016-05-12 16:18 - 000079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll 2016-06-17 19:49 - 2016-05-12 16:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll 2016-06-17 19:49 - 2016-05-12 16:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll 2016-06-17 19:49 - 2016-05-11 18:02 - 000483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll 2016-06-17 19:49 - 2016-05-11 16:19 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll 2016-06-17 18:31 - 2016-05-11 18:02 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2016-06-17 18:31 - 2016-05-11 18:02 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2016-06-17 18:31 - 2016-05-11 18:02 - 000296448 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll 2016-06-17 18:31 - 2016-05-11 16:19 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2016-06-17 18:31 - 2016-05-11 16:19 - 000231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2016-06-17 18:31 - 2016-05-11 16:19 - 000206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll 2016-06-17 18:31 - 2016-05-11 16:11 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe 2016-06-17 18:31 - 2016-05-11 16:01 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe 2016-06-17 18:31 - 2016-05-11 15:58 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2016-06-17 18:27 - 2016-03-09 20:00 - 000396800 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2016-06-17 18:27 - 2016-03-09 19:40 - 000316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2016-05-12 21:38 - 2016-04-14 14:49 - 000603648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2016-05-12 21:38 - 2016-04-14 14:21 - 000647680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2016-05-12 21:34 - 2016-03-09 19:54 - 000275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2016-05-12 21:34 - 2016-03-09 19:34 - 000216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2016-05-12 21:12 - 2016-04-09 05:20 - 001230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2016-05-12 21:12 - 2016-04-09 04:52 - 001424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2016-04-24 20:05 - 2016-04-24 20:05 - 000003054 _____ C:\Windows\System32\Tasks\{C1DBE46F-1E15-4A65-9A75-42E1DF8ADE50} 2016-04-24 20:04 - 2016-04-24 20:04 - 000003058 _____ C:\Windows\System32\Tasks\{75924CED-E37F-454E-83A7-E68F9ED175C1} 2016-04-20 14:36 - 2016-04-20 14:36 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Temp 2016-04-15 12:25 - 2016-03-16 19:50 - 000156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-04-15 12:25 - 2016-03-16 19:28 - 000176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-04-15 12:25 - 2016-03-16 19:28 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-04-15 12:25 - 2015-06-03 21:17 - 000546656 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2016-04-15 12:24 - 2016-01-21 01:51 - 000073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2016-04-14 12:49 - 2016-02-05 19:56 - 000020480 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll 2016-04-14 12:49 - 2016-02-05 19:54 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll 2016-04-14 12:49 - 2016-02-05 18:33 - 000015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll 2016-04-14 12:49 - 2015-06-03 21:21 - 000451080 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll 2016-03-17 19:15 - 1999-01-20 05:01 - 000210032 _____ C:\Windows\SysWOW64\DBCLIENT.DLL 2016-03-17 19:14 - 2016-04-14 11:46 - 000000000 ____D C:\Program Files (x86)\IN MEDIA KG - CSV-Editor 2016-03-17 18:59 - 2016-03-17 18:59 - 000000000 ____D C:\ProgramData\PC1Data 2016-03-10 21:09 - 2016-01-11 20:11 - 001684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2016-03-10 21:08 - 2016-02-09 10:55 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll 2016-03-10 21:06 - 2016-02-03 19:07 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2016-03-10 20:53 - 2016-02-05 02:19 - 000381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2016-03-10 20:53 - 2016-02-04 19:41 - 000296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll 2016-02-24 16:58 - 2016-02-24 16:58 - 000000000 ____D C:\Users\Rudi\AppData\Local\{B791B576-2C0B-4068-BC8C-34DDE1246DA6} 2016-02-24 16:21 - 2016-02-24 16:21 - 000000000 ____D C:\Users\Rudi\Tracing 2016-02-11 08:21 - 2016-01-22 07:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2016-02-11 08:21 - 2016-01-22 07:18 - 000723968 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2016-02-11 08:21 - 2016-01-22 07:04 - 000642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2016-02-11 08:21 - 2016-01-22 07:04 - 000535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2016-01-15 17:33 - 2015-11-14 00:09 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll 2016-01-15 17:33 - 2015-11-14 00:09 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll 2016-01-15 17:33 - 2015-11-14 00:08 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe 2016-01-15 17:33 - 2015-11-13 23:50 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll 2016-01-15 17:33 - 2015-11-13 23:50 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll 2016-01-15 17:33 - 2015-11-13 23:49 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe 2016-01-15 17:32 - 2015-12-08 22:54 - 001620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 001568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll 2016-01-15 17:32 - 2015-12-08 22:54 - 000739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL 2016-01-15 17:32 - 2015-12-08 22:53 - 000970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll 2016-01-15 17:32 - 2015-12-08 22:53 - 000829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL 2016-01-15 17:32 - 2015-12-08 22:53 - 000153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll 2016-01-15 17:32 - 2015-12-08 20:07 - 001232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2016-01-15 17:32 - 2015-12-08 20:07 - 001010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2016-01-15 17:32 - 2015-12-08 20:07 - 000978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 000666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 000642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 000189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL 2016-01-15 17:31 - 2015-12-08 22:54 - 002285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2016-01-15 17:31 - 2015-12-08 22:54 - 001325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL 2016-01-15 17:31 - 2015-12-08 22:54 - 000358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL 2016-01-15 17:31 - 2015-12-08 22:54 - 000154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2016-01-15 17:31 - 2015-12-08 22:53 - 000415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll 2016-01-15 17:31 - 2015-12-08 22:53 - 000193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax 2016-01-15 17:31 - 2015-12-08 22:53 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll 2016-01-15 17:31 - 2015-12-08 22:53 - 000053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll 2016-01-15 17:31 - 2015-12-08 22:53 - 000004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 002777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 001393152 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll 2016-01-15 17:31 - 2015-12-08 20:06 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax 2016-01-15 17:31 - 2015-12-08 19:54 - 000116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2016-01-15 17:31 - 2015-12-08 19:12 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2016-01-15 17:31 - 2015-12-08 19:11 - 000005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys 2015-12-21 10:41 - 2016-10-10 17:14 - 000921624 _____ C:\snp2uvc-001.raw 2015-12-21 10:36 - 2015-12-21 10:36 - 000000828 _____ C:\Users\Public\Desktop\AMCap.lnk 2015-12-21 10:36 - 2015-12-21 10:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Video Device 2015-12-21 10:36 - 2012-05-25 11:36 - 000376832 _____ (Sonix Technology Co., Ltd.) C:\Windows\system32\vsnp2uvc.dll 2015-12-21 10:36 - 2012-05-25 11:33 - 000306688 _____ (Sonix Technology Co., Ltd.) C:\Windows\SysWOW64\vsnp2uvc.dll 2015-12-21 10:36 - 2009-08-13 20:33 - 000239616 _____ ( ) C:\Windows\SysWOW64\rsnp2uvc.dll 2015-12-21 10:36 - 2009-08-13 20:33 - 000238080 _____ ( ) C:\Windows\system32\rsnp2uvc.dll 2015-12-21 10:36 - 2009-08-12 15:06 - 000662016 _____ (Sonix) C:\Windows\vsnp2uvc.exe 2015-12-21 10:36 - 2009-07-21 12:08 - 000013021 _____ C:\Windows\snp2uvc.src 2015-12-21 10:36 - 2009-02-16 18:33 - 000306176 _____ ( ) C:\Windows\system32\csnp2uvc.dll 2015-12-21 10:36 - 2006-05-19 11:39 - 000015497 _____ C:\Windows\snp2uvc.ini 2015-12-21 10:26 - 2012-06-27 15:29 - 003568128 _____ () C:\Windows\system32\Drivers\snp2uvc.sys 2015-12-21 10:26 - 2011-08-21 10:46 - 000035584 _____ C:\Windows\system32\Drivers\sncduvc.sys 2015-12-09 22:20 - 2015-11-05 20:05 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll 2015-12-09 22:20 - 2015-11-05 20:02 - 000014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll 2015-12-09 22:20 - 2015-11-05 10:53 - 000146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-12-09 21:31 - 2015-10-09 00:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL 2015-12-09 21:31 - 2015-10-09 00:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll 2015-12-09 21:31 - 2015-10-09 00:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL 2015-12-09 21:31 - 2015-10-09 00:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL 2015-12-09 21:31 - 2015-10-09 00:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll 2015-12-09 21:31 - 2015-10-09 00:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL 2015-12-09 21:30 - 2015-11-03 20:04 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll 2015-12-09 21:30 - 2015-11-03 19:55 - 000179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll 2015-12-09 21:04 - 2015-11-11 19:53 - 001735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-12-09 21:03 - 2015-11-11 19:53 - 000525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2015-12-09 21:03 - 2015-11-11 19:39 - 001242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll 2015-12-09 21:03 - 2015-11-11 19:39 - 000487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll 2015-11-26 10:18 - 2015-11-26 10:18 - 000002055 _____ C:\Users\Public\Desktop\WISO steuer Sparbuch 2016.lnk 2015-11-26 10:18 - 2015-11-26 10:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO steuer Sparbuch 2016 2015-11-15 23:11 - 2015-10-29 18:50 - 000342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-11-15 23:11 - 2015-10-29 18:50 - 000072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-11-15 23:11 - 2015-10-29 18:50 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-11-15 23:11 - 2015-10-29 18:50 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-11-15 23:11 - 2015-10-29 18:50 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-11-15 23:11 - 2015-10-29 18:49 - 000295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-11-15 23:11 - 2015-10-29 18:49 - 000020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-11-15 21:51 - 2015-10-13 05:57 - 000950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-11-09 16:43 - 2015-11-09 16:43 - 000000000 ____D C:\Users\Rudi\mimviewer 2015-11-06 16:59 - 2015-11-06 16:59 - 000001277 _____ C:\Users\Rudi\Desktop\CyberLink YouCam.lnk 2015-11-01 11:18 - 2015-11-01 11:18 - 000002998 _____ C:\Windows\System32\Tasks\{B8475E7F-7DC6-4E2A-9211-0988C160EF29} 2015-11-01 11:18 - 2015-11-01 11:18 - 000002998 _____ C:\Windows\System32\Tasks\{B18FA98A-E82C-4A91-8381-F27EE8F93E80} 2015-11-01 11:18 - 2015-11-01 11:18 - 000002998 _____ C:\Windows\System32\Tasks\{86259AB4-CAA0-43BB-B56E-53709CCA447D} 2015-11-01 11:18 - 2015-11-01 11:18 - 000002998 _____ C:\Windows\System32\Tasks\{1D96B393-3B3C-4731-8BBE-C2A5818DD354} 2015-11-01 11:16 - 2015-11-01 11:16 - 000002998 _____ C:\Windows\System32\Tasks\{42894C95-CACE-48E5-8FA9-03180ABC6D82} 2015-10-27 10:35 - 2016-09-11 15:38 - 000007620 _____ C:\Users\Rudi\AppData\Local\Resmon.ResmonCfg 2015-10-22 10:09 - 2015-10-22 10:09 - 000993632 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll 2015-10-22 10:09 - 2015-10-22 10:09 - 000987848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll 2015-10-22 10:08 - 2015-10-22 10:08 - 000690016 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll 2015-10-22 10:08 - 2015-10-22 10:08 - 000484552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll 2015-09-14 11:56 - 2015-09-14 11:56 - 000000000 ____D C:\Users\Rudi\AppData\Local\CEF 2015-09-10 16:59 - 2015-09-10 16:59 - 000000000 ____D C:\Users\Rudi\Phone Browser 2015-09-10 16:59 - 2015-09-10 16:59 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\PC Suite 2015-09-10 16:57 - 2015-09-10 17:13 - 000000000 ____D C:\Program Files (x86)\Nokia 2015-09-09 08:17 - 2015-07-23 01:02 - 000879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-09-09 08:16 - 2015-07-22 18:53 - 000635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-09-09 08:12 - 2015-08-05 18:56 - 001110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2015-09-09 08:10 - 2015-07-09 18:58 - 001632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-09-09 08:10 - 2015-07-09 18:58 - 000082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll 2015-09-09 08:10 - 2015-07-09 18:42 - 001372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2015-09-09 08:10 - 2015-07-09 18:42 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll 2015-09-09 08:03 - 2015-08-27 19:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2015-09-09 08:03 - 2015-08-27 19:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2015-09-09 08:03 - 2015-08-27 18:58 - 001391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2015-09-09 08:03 - 2015-08-27 18:51 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2015-09-07 18:12 - 2017-05-04 16:24 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-09-07 18:10 - 2017-04-11 17:16 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-09-07 18:10 - 2015-09-07 18:10 - 000002007 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk Geändert von cosinus (19.09.2017 um 12:53 Uhr) Grund: code tags |
19.09.2017, 11:29 | #5 |
| Zertifikatfehler, NavigationCode:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 17-09-2017 01 durchgeführt von Rudi (Administrator) auf RUDI-HP (01-01-2011 04:53:59) Gestartet von C:\Users\Rudi\Documents Geladene Profile: Rudi (Verfügbare Profile: Rudi) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: IE) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (Advanced Micro Devices) C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sonix) C:\Windows\vsnp2uvc.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6602856 2011-01-11] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-21] (Synaptics Incorporated) HKLM\...\Run: [snp2uvc] => C:\Windows\vsnp2uvc.exe [662016 2009-08-12] (Sonix) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [919032 2011-01-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [tsnp2uvc] => C:\Program Files (x86)\Common Files\SNP2UVC\tsnp2uvc.exe [249856 2012-05-04] (Sonix Technology Co., Ltd.) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [97512 2017-06-08] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\Run: [jICc7n9BYxBTRVw] => C:\Users\Rudi\AppData\Roaming\wsf3CmCT.exe HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: G - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {259dbd5c-0af1-11e1-a5de-68a3c4d1c179} - H:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {259dbd6a-0af1-11e1-a5de-68a3c4d1c179} - H:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {49be8cdd-0a9b-11e6-ac1b-001e101fe70e} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {49be8cf4-0a9b-11e6-ac1b-001e101fe70e} - I:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {59830c6f-7426-11e2-860a-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {8d84e8c3-a7bc-11e5-b629-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {941e22fb-0baf-11e6-a331-68a3c4d1c179} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {a582d1be-6e04-11e1-a1ac-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {a582d1ed-6e04-11e1-a1ac-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {a7f078b1-01bf-11e2-8346-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {a8a4e724-5a34-11e1-b6d3-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {d2644492-3c42-11e4-94eb-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {de238638-a76d-11e5-941e-68a3c4d1c179} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {eb065f82-6bd9-11e4-8deb-68a3c4d1c179} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {f7a549b0-0a51-11e6-b6a0-001e101faa49} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {f7a549bb-0a51-11e6-b6a0-001e101faa49} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {f7a549c7-0a51-11e6-b6a0-001e101faa49} - G:\.\Setup.exe AUTORUN=1 HKU\S-1-5-21-3229228620-787667599-3763351482-1001\...\MountPoints2: {f7a549da-0a51-11e6-b6a0-001e101faa49} - G:\.\Setup.exe AUTORUN=1 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Launcher.lnk [2012-03-13] ShortcutTarget: Launcher.lnk -> C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk [2014-01-12] ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 1000 J110 series.lnk [2011-01-01] ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 1000 J110 series.lnk -> C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{11C79F3D-A2B6-4D0D-83FC-40AC6DE02E73}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{1DF2F6FF-4DBF-4503-901A-8A2AF11234A7}: [NameServer] 212.23.115.132 212.23.115.148 Tcpip\..\Interfaces\{53C50116-1412-438A-B596-75C78F0FBBA1}: [NameServer] 212.23.115.148 212.23.115.132 Tcpip\..\Interfaces\{662DEAA7-E456-40C8-B329-C9C9583C068B}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{C3A6E741-61B3-4216-BD2F-56DF34EF4B04}: [NameServer] 212.23.115.148 212.23.115.132 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://web.de/ HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://safesearch.avira.com/#web/result?source=art&q= SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM-x32 -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> Keine Datei BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-02] (Oracle Corporation) BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-06] (Atheros Commnucations) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-02] (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard) Toolbar: HKU\S-1-5-21-3229228620-787667599-3763351482-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab FireFox: ======== FF ProfilePath: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\xrow3d6a.default [2016-09-20] FF NetworkProxy: Mozilla\Firefox\Profiles\xrow3d6a.default -> type", 0 FF SelectedSearchEngine: Mozilla\Firefox\Profiles\xrow3d6a.default -> MyPlayCity Search FF Keyword.URL: Mozilla\Firefox\Profiles\xrow3d6a.default -> hxxp://home.myplaycity.com/results.php?category=web&s= FF Homepage: Mozilla\Firefox\Profiles\xrow3d6a.default -> hxxp://home.myplaycity.com/ FF Extension: (MyPlayCity Toolbar) - C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\xrow3d6a.default\Extensions\{A9897564-CA29-4CAE-8A26-453035570837} [2012-04-09] [ist nicht signiert] FF SearchPlugin: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\xrow3d6a.default\searchplugins\myplaycity-search.xml [2012-01-31] FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-02] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-02] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S4 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [638128 2017-03-28] () R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [354304 2011-03-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] R2 AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [194496 2010-06-17] (Advanced Micro Devices) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1128432 2011-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [490968 2011-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [490968 2011-01-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1525240 2011-01-01] (Avira Operations GmbH & Co. KG) S3 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-06] (Atheros) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [356256 2017-06-08] (Avira Operations GmbH & Co. KG) S3 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1817088 2010-12-28] (Realsil Microelectronics Inc.) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S4 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-02-25] (Xobni Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [64504 2017-06-21] (Avira Operations GmbH & Co. KG) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [194912 2011-01-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [151128 2011-01-01] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [35328 2017-02-25] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2017-02-25] (Avira Operations GmbH & Co. KG) S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2012-03-13] (Huawei Technologies Co., Ltd.) S3 ewusbnet; C:\Windows\SysWOW64\DRIVERS\ewusbnet.sys [256000 2012-03-13] (Huawei Technologies Co., Ltd.) S3 ew_hwusbdev; C:\Windows\SysWOW64\DRIVERS\ew_hwusbdev.sys [117248 2012-03-13] (Huawei Technologies Co., Ltd.) S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [121600 2012-03-13] (Huawei Technologies Co., Ltd.) S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [113280 2014-01-12] (ITE ) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3568128 2012-06-27] () S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-26 10:19 - 2017-06-26 10:19 - 000001096 _____ C:\Users\Public\Desktop\Avira Connect.lnk 2017-06-23 12:35 - 2017-09-16 20:16 - 000003180 _____ C:\Windows\System32\Tasks\HPCeeScheduleForRudi 2017-06-23 12:34 - 1817-09-17 10:22 - 000000328 _____ C:\Windows\Tasks\HPCeeScheduleForRudi.job 2017-06-21 06:02 - 2017-06-21 05:58 - 000064504 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avdevprot.sys 2017-06-17 10:03 - 2017-05-14 21:19 - 025738752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-06-17 10:03 - 2017-05-14 20:11 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-06-17 10:03 - 2017-04-27 23:50 - 003550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2017-06-17 10:03 - 2017-04-12 14:05 - 004296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 002317824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-06-17 10:02 - 2017-06-02 09:28 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-06-17 10:02 - 2017-06-02 09:11 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-06-17 10:02 - 2017-06-02 09:11 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-06-17 10:02 - 2017-06-02 09:10 - 000733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-06-17 10:02 - 2017-06-02 09:10 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-06-17 10:02 - 2017-06-02 09:09 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2017-06-17 10:02 - 2017-06-02 09:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2017-06-17 10:02 - 2017-06-02 08:58 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-06-17 10:02 - 2017-06-02 08:58 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2017-06-17 10:02 - 2017-06-02 08:57 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2017-06-17 10:02 - 2017-06-02 08:57 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2017-06-17 10:02 - 2017-05-21 05:28 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-06-17 10:02 - 2017-05-21 05:28 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-06-17 10:02 - 2017-05-21 05:24 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-06-17 10:02 - 2017-05-21 05:24 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-06-17 10:02 - 2017-05-21 05:06 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-06-17 10:02 - 2017-05-16 19:19 - 000394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-06-17 10:02 - 2017-05-16 18:35 - 000346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-06-17 10:02 - 2017-05-14 21:26 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-06-17 10:02 - 2017-05-14 21:24 - 002899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-06-17 10:02 - 2017-05-14 21:17 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-06-17 10:02 - 2017-05-14 21:12 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-06-17 10:02 - 2017-05-14 21:10 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-06-17 10:02 - 2017-05-14 21:01 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-06-17 10:02 - 2017-05-14 20:55 - 005975040 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-06-17 10:02 - 2017-05-14 20:36 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-06-17 10:02 - 2017-05-14 20:23 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-06-17 10:02 - 2017-05-14 20:22 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-06-17 10:02 - 2017-05-14 20:19 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-06-17 10:02 - 2017-05-14 20:18 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-06-17 10:02 - 2017-05-14 20:17 - 002132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-06-17 10:02 - 2017-05-14 20:16 - 002290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-06-17 10:02 - 2017-05-14 20:10 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-06-17 10:02 - 2017-05-14 19:54 - 015252992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-06-17 10:02 - 2017-05-14 19:52 - 003240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-06-17 10:02 - 2017-05-14 19:44 - 004549120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-06-17 10:02 - 2017-05-14 19:40 - 000693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-06-17 10:02 - 2017-05-14 19:39 - 002057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-06-17 10:02 - 2017-05-14 19:38 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-06-17 10:02 - 2017-05-14 19:37 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-06-17 10:02 - 2017-05-14 19:30 - 013664768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-06-17 10:02 - 2017-05-14 19:15 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-06-17 10:02 - 2017-05-14 19:11 - 001314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-06-17 10:02 - 2017-05-12 19:27 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-06-17 10:02 - 2017-05-12 19:26 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-06-17 10:02 - 2017-05-12 19:26 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-06-17 10:02 - 2017-05-12 19:26 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2017-06-17 10:02 - 2017-05-12 19:24 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-06-17 10:02 - 2017-05-12 19:22 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-06-17 10:02 - 2017-05-12 19:22 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-06-17 10:02 - 2017-05-12 19:07 - 004001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-06-17 10:02 - 2017-05-12 19:07 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-06-17 10:02 - 2017-05-12 19:07 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2017-06-17 10:02 - 2017-05-12 19:04 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-06-17 10:02 - 2017-05-12 19:03 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-06-17 10:02 - 2017-05-12 19:03 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-06-17 10:02 - 2017-05-12 18:52 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-06-17 10:02 - 2017-05-12 16:58 - 001648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-06-17 10:02 - 2017-05-10 16:33 - 000091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe 2017-06-17 10:02 - 2017-05-10 16:29 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-06-17 10:02 - 2017-05-10 16:29 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2017-06-17 10:02 - 2017-05-10 16:16 - 000091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe 2017-06-17 10:02 - 2017-05-10 16:14 - 002651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-06-17 10:02 - 2017-05-10 16:12 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-06-17 10:02 - 2017-05-10 15:52 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2017-06-17 10:02 - 2017-05-09 16:30 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-06-17 10:02 - 2017-05-09 16:29 - 000970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2017-06-17 10:02 - 2017-05-09 16:11 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2017-06-17 10:02 - 2017-05-07 16:33 - 000094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2017-06-17 10:02 - 2017-03-30 16:03 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe 2017-06-17 10:02 - 2017-03-30 15:58 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe 2017-06-17 10:01 - 2017-05-21 05:24 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-06-17 10:01 - 2017-05-21 05:24 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-06-17 10:01 - 2017-05-21 05:06 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-06-17 10:01 - 2017-05-21 04:55 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-06-17 10:01 - 2017-05-21 04:48 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-06-17 10:01 - 2017-05-21 04:48 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-06-17 10:01 - 2017-05-21 04:48 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-06-17 10:01 - 2017-05-21 04:47 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-06-17 10:01 - 2017-05-21 04:46 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-06-17 10:01 - 2017-05-21 04:42 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-06-17 10:01 - 2017-05-14 21:46 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-06-17 10:01 - 2017-05-14 21:46 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-06-17 10:01 - 2017-05-14 21:28 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-06-17 10:01 - 2017-05-14 21:27 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-06-17 10:01 - 2017-05-14 21:27 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-06-17 10:01 - 2017-05-14 21:27 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-06-17 10:01 - 2017-05-14 21:16 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-06-17 10:01 - 2017-05-14 21:10 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-06-17 10:01 - 2017-05-14 21:10 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-06-17 10:01 - 2017-05-14 21:10 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-06-17 10:01 - 2017-05-14 20:57 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-06-17 10:01 - 2017-05-14 20:48 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-06-17 10:01 - 2017-05-14 20:47 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-06-17 10:01 - 2017-05-14 20:46 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-06-17 10:01 - 2017-05-14 20:42 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-06-17 10:01 - 2017-05-14 20:41 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-06-17 10:01 - 2017-05-14 20:38 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-06-17 10:01 - 2017-05-14 20:37 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-06-17 10:01 - 2017-05-14 20:23 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-06-17 10:01 - 2017-05-14 20:22 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-06-17 10:01 - 2017-05-14 20:22 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-06-17 10:01 - 2017-05-14 20:21 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-06-17 10:01 - 2017-05-14 20:20 - 000725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-06-17 10:01 - 2017-05-14 20:15 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-06-17 10:01 - 2017-05-14 20:14 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-06-17 10:01 - 2017-05-14 20:12 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-06-17 10:01 - 2017-05-14 20:11 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-06-17 10:01 - 2017-05-14 20:10 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-06-17 10:01 - 2017-05-14 20:02 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-06-17 10:01 - 2017-05-14 19:57 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2017-06-17 10:01 - 2017-05-14 19:57 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-06-17 10:01 - 2017-05-14 19:56 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-06-17 10:01 - 2017-05-14 19:53 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-06-17 10:01 - 2017-05-14 19:52 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-06-17 10:01 - 2017-05-14 19:50 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-06-17 10:01 - 2017-05-14 19:49 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-06-17 10:01 - 2017-05-14 19:42 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-06-17 10:01 - 2017-05-14 19:27 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-06-17 10:01 - 2017-05-14 19:11 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 19:03 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 18:55 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-06-17 10:01 - 2017-05-12 18:54 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-06-17 10:01 - 2017-05-12 18:54 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-06-17 10:01 - 2017-05-12 18:51 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-06-17 10:01 - 2017-05-12 18:50 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-06-17 10:01 - 2017-05-12 18:46 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-06-17 10:01 - 2017-05-12 18:43 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2017-06-17 10:01 - 2017-05-12 18:41 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-06-17 10:01 - 2017-05-12 18:41 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-06-17 10:01 - 2017-05-12 18:41 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-06-17 10:01 - 2017-05-12 18:41 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-06-17 10:01 - 2017-05-12 18:40 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 18:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 18:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 18:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-06-17 10:01 - 2017-05-12 17:25 - 001251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-06-17 10:01 - 2017-05-12 16:58 - 001180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-06-17 10:01 - 2017-05-10 16:29 - 003165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2017-06-17 10:01 - 2017-05-10 16:29 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2017-06-17 10:01 - 2017-05-10 16:29 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2017-06-17 10:01 - 2017-05-10 16:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2017-06-17 10:01 - 2017-05-10 16:13 - 000709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-06-17 10:01 - 2017-05-10 16:13 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2017-06-17 10:01 - 2017-05-10 16:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2017-06-17 10:01 - 2017-05-10 16:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2017-06-17 10:01 - 2017-05-10 16:13 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2017-06-17 10:01 - 2017-05-10 16:13 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2017-06-17 10:01 - 2017-05-10 16:12 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2017-06-17 10:01 - 2017-05-10 16:12 - 000174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2017-06-17 10:01 - 2017-05-10 16:00 - 000573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-06-17 10:01 - 2017-05-10 16:00 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2017-06-17 10:01 - 2017-05-10 16:00 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2017-06-17 10:01 - 2017-05-10 16:00 - 000030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2017-06-17 10:01 - 2017-05-07 16:29 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2017-05-12 14:26 - 2017-04-21 16:34 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2017-05-12 14:26 - 2017-04-21 16:15 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 000876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll 2017-05-12 14:26 - 2017-04-17 16:37 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll 2017-05-12 14:26 - 2017-04-17 16:12 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2017-05-12 14:26 - 2017-04-17 16:12 - 000581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2017-05-12 14:26 - 2017-04-17 16:12 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll 2017-05-12 14:26 - 2017-04-17 15:54 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll 2017-05-12 14:26 - 2017-04-12 16:32 - 001483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2017-05-12 14:26 - 2017-04-12 16:32 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2017-05-12 14:26 - 2017-04-12 16:32 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2017-05-12 14:26 - 2017-04-12 16:32 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2017-05-12 14:26 - 2017-04-12 16:26 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2017-05-12 14:26 - 2017-04-12 16:25 - 001176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2017-05-12 14:26 - 2017-04-12 16:25 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2017-05-12 14:26 - 2017-04-12 16:25 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2017-05-12 14:26 - 2017-04-07 16:34 - 000986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-05-12 14:26 - 2017-04-07 16:34 - 000265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2017-05-12 14:26 - 2017-04-07 16:30 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2017-05-12 14:26 - 2017-04-05 15:55 - 000460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-05-12 14:26 - 2017-04-05 15:55 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-05-12 14:26 - 2017-04-05 15:55 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-05-12 14:26 - 2017-04-04 16:34 - 001895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2017-05-12 14:26 - 2017-04-04 16:34 - 000377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2017-05-12 14:26 - 2017-04-04 16:34 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2017-05-12 14:26 - 2017-04-04 15:53 - 000496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2017-05-12 14:26 - 2017-03-10 17:32 - 001389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll 2017-05-12 14:26 - 2017-03-10 17:32 - 000300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll 2017-05-12 14:26 - 2017-03-10 17:20 - 001508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll 2017-05-12 14:26 - 2017-03-10 17:20 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll 2017-05-12 14:26 - 2017-03-10 16:57 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe 2017-05-12 14:26 - 2017-03-10 16:55 - 000205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2017-05-12 14:26 - 2017-03-10 16:55 - 000195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys 2017-05-12 14:25 - 2017-03-09 17:34 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-05-12 14:25 - 2017-03-09 17:19 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-05-09 10:43 - 2017-05-09 10:43 - 000099871 _____ C:\Users\Rudi\Documents\0002075041_Jahressteuerbescheinigung_und_Erträgnisaufstellung_983904725922209000.pdf 2017-04-29 09:35 - 2017-03-04 02:27 - 001574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2017-04-29 09:35 - 2017-03-04 02:14 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2017-04-29 09:35 - 2017-02-09 17:32 - 000769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:36 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-04-29 09:35 - 2017-01-18 16:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-04-29 09:34 - 2017-03-07 17:30 - 000085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2017-04-29 09:34 - 2017-03-07 17:17 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2017-04-29 09:34 - 2017-03-04 02:27 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll 2017-04-29 09:34 - 2017-03-04 02:14 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll 2017-04-29 09:34 - 2017-02-09 17:32 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2017-04-29 09:34 - 2017-02-09 17:14 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-04-29 09:34 - 2017-01-18 16:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-03-28 11:38 - 2017-03-28 11:53 - 000000000 ____D C:\Users\Rudi\Documents\Hanse Merkur Erstattungen 2017-03-26 19:33 - 2017-03-26 19:33 - 000028344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll 2017-03-26 19:33 - 2017-03-26 19:33 - 000019104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110_clr0400.dll 2017-03-26 19:33 - 2017-03-26 19:33 - 000019104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100_clr0400.dll 2017-03-26 19:33 - 2017-03-26 19:33 - 000019104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110_clr0400.dll 2017-03-26 19:29 - 2017-03-26 19:29 - 000030400 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll 2017-03-26 19:29 - 2017-03-26 19:29 - 000019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcr110_clr0400.dll 2017-03-26 19:29 - 2017-03-26 19:29 - 000019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll 2017-03-26 19:29 - 2017-03-26 19:29 - 000019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcp110_clr0400.dll 2017-03-16 16:44 - 2017-02-09 17:32 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll 2017-03-16 16:44 - 2017-02-09 17:31 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2017-03-16 16:44 - 2017-02-09 17:31 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll 2017-03-16 16:44 - 2017-02-09 17:14 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2017-03-16 16:44 - 2017-02-09 17:14 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll 2017-03-16 16:44 - 2017-02-09 16:51 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll 2017-03-16 16:44 - 2017-01-13 19:00 - 000976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-03-16 16:44 - 2017-01-13 19:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll 2017-03-16 16:44 - 2017-01-13 18:45 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-03-16 16:44 - 2017-01-13 18:45 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll 2017-03-16 16:44 - 2017-01-11 19:01 - 001887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2017-03-16 16:44 - 2017-01-11 19:01 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2017-03-16 16:44 - 2017-01-11 18:43 - 001241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2017-03-16 16:43 - 2017-01-11 18:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2017-03-16 16:39 - 2017-02-23 00:42 - 000084712 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-03-16 16:39 - 2017-02-23 00:37 - 001285632 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-03-16 16:39 - 2017-02-18 15:05 - 001609216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-03-16 16:39 - 2017-02-18 15:05 - 000646656 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000556544 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000335360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000293376 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000233984 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-03-16 16:39 - 2016-12-31 16:36 - 000133632 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-03-11 18:54 - 2017-03-11 18:54 - 000067513 _____ C:\Users\Rudi\Documents\Buchungsanfrage_R780398-A139608-2595.pdf 2017-03-11 18:37 - 2017-03-11 18:37 - 000063231 _____ C:\Users\Rudi\Documents\Bösehof Buchung.pdf 2017-03-09 17:13 - 2017-03-09 17:13 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\java 2017-03-09 17:01 - 2017-03-09 17:01 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Servicecenter 2017-03-09 17:01 - 2017-03-09 17:01 - 000000000 ____D C:\Users\Rudi\.swt 2017-03-02 14:31 - 2017-03-02 15:17 - 000000000 ____D C:\Users\Rudi\Documents\Sicherung S5 2017-02-25 18:36 - 2017-02-25 18:36 - 000000000 ____D C:\Users\Rudi\AppData\Local\{6754908E-CC15-4E62-B8CF-E68246AB0A88} 2017-02-25 15:13 - 2017-02-25 15:13 - 000000000 ____D C:\Users\Rudi\Documents\Bluetooth Folder 2017-02-24 14:51 - 2017-05-12 14:44 - 000000000 ____D C:\Users\Rudi\Documents\Schriftverkehr 2017-02-24 14:40 - 2017-02-24 14:40 - 000000000 ____D C:\Users\Rudi\AppData\Local\{C1635CC3-3158-49EE-9574-7D69C2771953} 2017-02-24 14:30 - 2017-03-02 13:24 - 000000000 ____D C:\Users\Rudi\Documents\Dana WWK 2017-02-17 15:16 - 2017-02-17 15:16 - 000000000 ____D C:\Users\Rudi\AppData\Local\{3803325C-C691-48DD-971B-81FE562ED737} 2017-02-14 14:11 - 2017-02-14 14:11 - 000002055 _____ C:\Users\Public\Desktop\WISO steuer Sparbuch 2017.lnk 2017-02-14 14:09 - 2017-02-14 14:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO steuer Sparbuch 2017 2017-01-18 12:21 - 2017-01-24 17:12 - 000000000 ____D C:\Users\Rudi\Documents\International Service Check 2016-12-19 11:39 - 2016-12-19 11:39 - 000001202 _____ C:\Users\Rudi\Desktop\Avira Antivirus starten.lnk 2016-12-14 11:54 - 2016-11-21 19:12 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll 2016-12-14 11:54 - 2016-11-20 17:19 - 000084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll 2016-12-14 11:54 - 2016-11-20 15:07 - 000467392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2016-12-14 11:54 - 2016-11-17 17:41 - 000370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2016-12-14 11:54 - 2016-11-10 17:32 - 001009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2016-12-14 11:54 - 2016-11-10 17:19 - 000833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2016-12-14 11:54 - 2016-11-09 17:41 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2016-12-14 11:54 - 2016-11-09 17:33 - 003244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2016-12-14 11:54 - 2016-11-09 17:33 - 001941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2016-12-14 11:54 - 2016-11-09 17:33 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2016-12-14 11:54 - 2016-11-09 17:33 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2016-12-14 11:54 - 2016-11-09 17:33 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2016-12-14 11:54 - 2016-11-09 17:17 - 002365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2016-12-14 11:54 - 2016-11-09 17:17 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2016-12-14 11:54 - 2016-11-09 17:17 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2016-12-14 11:54 - 2016-11-09 17:17 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2016-12-14 11:54 - 2016-11-09 17:02 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2016-12-14 11:54 - 2016-11-09 16:55 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2016-12-14 11:54 - 2016-10-11 16:32 - 000069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll 2016-12-14 11:54 - 2016-10-11 16:18 - 000069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2016-12-14 11:54 - 2016-10-11 15:55 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe 2016-12-14 11:54 - 2016-10-11 14:18 - 000419648 _____ C:\Windows\SysWOW64\locale.nls 2016-12-14 11:54 - 2016-10-11 14:17 - 000419648 _____ C:\Windows\system32\locale.nls 2016-12-14 11:54 - 2016-10-08 14:06 - 000633296 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2016-12-09 12:45 - 2017-06-29 14:31 - 000000000 ____D C:\Users\Rudi\Documents\Knappschaft 2016-12-02 13:02 - 2017-03-26 17:52 - 000000000 ____D C:\Users\Rudi\Documents\BG ETEM 2016-11-22 15:59 - 2017-03-22 14:16 - 000196096 _____ C:\Users\Rudi\Documents\ZH1.axe 2016-11-17 16:57 - 2017-06-26 11:41 - 000196096 _____ C:\Users\Rudi\Documents\ZH.axe 2016-11-14 16:12 - 2016-11-14 16:12 - 000000000 ____D C:\Users\Rudi\AppData\Local\{2AAB1E71-4CEF-4544-99A0-06284543290B} 2016-11-12 13:19 - 1817-09-17 11:41 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Ability5 2016-11-12 13:17 - 2016-11-12 13:17 - 000000000 ____D C:\Users\Rudi\Documents\DbgLogs 2016-11-12 13:14 - 2012-09-04 13:41 - 006617528 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\system32\cdintf450_64.dll 2016-11-12 13:14 - 2012-09-04 13:41 - 004897720 _____ (Amyuni Technologies hxxp://www.amyuni.com) C:\Windows\SysWOW64\cdintf450.dll 2016-11-12 13:13 - 2016-11-12 13:13 - 000000958 _____ C:\Users\Public\Desktop\Ability Presentation.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000953 _____ C:\Users\Public\Desktop\Ability Spreadsheet.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000946 _____ C:\Users\Public\Desktop\Ability Write.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000946 _____ C:\Users\Public\Desktop\Ability Photopaint.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000941 _____ C:\Users\Public\Desktop\Ability Database.lnk 2016-11-12 13:13 - 2016-11-12 13:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ability Office 6 2016-11-12 13:13 - 2016-11-12 13:13 - 000000000 ____D C:\Program Files (x86)\Ability Office 6 2016-11-10 12:05 - 2017-06-29 14:33 - 000687104 ___SH C:\Users\Rudi\Documents\Thumbs.db 2016-11-09 12:18 - 2016-10-11 16:31 - 001148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME 2016-11-09 12:18 - 2016-10-11 16:31 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2016-11-09 12:18 - 2016-10-11 16:31 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2016-11-09 12:18 - 2016-10-11 16:31 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll 2016-11-09 12:18 - 2016-10-11 16:31 - 000176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime 2016-11-09 12:18 - 2016-10-11 16:31 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 001027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME 2016-11-09 12:18 - 2016-10-11 16:18 - 000829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2016-11-09 12:18 - 2016-10-11 16:18 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2016-11-09 12:18 - 2016-10-11 16:18 - 000430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll 2016-11-09 12:18 - 2016-10-11 16:18 - 000126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime 2016-11-09 12:18 - 2016-10-11 16:18 - 000090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime 2016-11-09 12:18 - 2016-10-11 14:33 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2016-11-09 12:18 - 2016-10-11 14:06 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2016-11-09 12:18 - 2016-10-07 16:32 - 003649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll 2016-11-09 12:18 - 2016-10-07 16:12 - 002291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll 2016-11-09 12:18 - 2016-10-05 15:54 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2016-11-09 12:18 - 2016-09-15 15:56 - 000041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2016-11-09 12:17 - 2016-08-22 17:19 - 001386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2016-10-25 16:50 - 2016-10-25 16:50 - 000000000 ____D C:\Users\Rudi\AppData\Local\{ED68FA0C-EEBE-423A-AA74-CFC26BE7537C} 2016-10-25 16:32 - 2017-02-04 13:08 - 000000000 ____D C:\Users\Rudi\Documents\MysteryPanel 2016-10-24 16:35 - 2017-02-10 17:15 - 000000000 ____D C:\Users\Rudi\Documents\ebay Kleinanzeigen 2016-10-24 09:15 - 2017-02-04 13:09 - 000000000 ____D C:\Users\Rudi\Documents\NEXT Skopos 2016-10-17 11:24 - 2017-02-04 13:09 - 000000000 ____D C:\Users\Rudi\Documents\Performance 2016-10-15 14:59 - 2017-02-25 15:07 - 000000000 ____D C:\Users\Rudi\Documents\Steuer 2016-10-15 11:02 - 2016-10-15 14:34 - 000000000 ____D C:\Users\Rudi\Documents\Rente 2016-10-15 10:37 - 2017-06-21 05:58 - 000034128 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avusbflt.sys 2016-10-12 09:41 - 2016-08-12 18:02 - 014632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2016-10-12 09:41 - 2016-08-12 17:47 - 011410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2016-10-12 09:41 - 2016-08-12 17:26 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2016-10-12 09:41 - 2016-08-06 16:31 - 002023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2016-10-12 09:41 - 2016-08-06 16:15 - 001178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2016-10-12 09:41 - 2016-06-14 18:16 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2016-10-12 09:41 - 2016-06-14 18:16 - 001202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2016-10-12 09:41 - 2016-06-14 18:16 - 000842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2016-10-12 09:41 - 2016-06-14 18:16 - 000782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2016-10-12 09:41 - 2016-06-14 16:21 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2016-10-12 09:41 - 2016-06-14 16:21 - 000988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2016-10-12 09:41 - 2016-06-14 16:21 - 000744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2016-10-12 09:41 - 2016-06-14 16:21 - 000617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2016-10-12 09:40 - 2016-09-12 22:08 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll 2016-10-12 09:40 - 2016-09-12 21:49 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll 2016-10-12 09:40 - 2016-09-08 21:34 - 000263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2016-10-12 09:40 - 2016-09-08 21:34 - 000208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2016-10-12 09:40 - 2016-09-08 21:34 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2016-10-12 09:40 - 2016-09-08 21:34 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2016-10-12 09:40 - 2016-09-08 15:55 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2016-10-12 09:40 - 2016-09-08 15:55 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys 2016-10-12 09:40 - 2016-08-12 18:02 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2016-10-12 09:40 - 2016-08-12 18:02 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2016-10-12 09:40 - 2016-08-12 18:02 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2016-10-12 09:40 - 2016-08-12 18:02 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2016-10-12 09:40 - 2016-08-12 17:47 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2016-10-12 09:40 - 2016-08-12 17:31 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2016-10-12 09:40 - 2016-08-12 17:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2016-10-12 09:40 - 2016-08-12 17:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2016-10-12 09:40 - 2016-08-06 16:31 - 000347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2016-10-12 09:40 - 2016-08-06 16:31 - 000310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2016-10-12 09:40 - 2016-08-06 16:31 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2016-10-12 09:40 - 2016-08-06 16:31 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll 2016-10-12 09:40 - 2016-08-06 16:15 - 000249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2016-10-12 09:40 - 2016-08-06 16:15 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2016-10-12 09:40 - 2016-08-06 16:15 - 000146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2016-10-12 09:40 - 2016-08-06 16:01 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2016-10-12 09:40 - 2016-08-06 16:01 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe 2016-10-12 09:40 - 2016-08-06 15:53 - 000199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2016-10-12 09:40 - 2016-08-06 15:53 - 000012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe 2016-10-12 09:40 - 2016-08-06 15:53 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2016-10-12 09:40 - 2016-06-14 18:16 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2016-10-12 09:40 - 2016-06-14 18:11 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2016-10-12 09:40 - 2016-06-14 16:21 - 001005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2016-10-12 09:40 - 2016-06-14 16:21 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2016-10-12 09:40 - 2016-06-14 16:15 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2016-10-12 09:40 - 2016-06-14 16:15 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2016-10-12 09:40 - 2016-06-14 16:15 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2016-10-12 09:40 - 2016-06-14 16:05 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2016-10-12 09:40 - 2016-06-14 16:05 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2016-10-12 09:40 - 2016-06-14 16:00 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2016-10-12 09:40 - 2016-06-14 16:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2016-10-12 09:39 - 2016-08-06 16:31 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll 2016-10-12 09:39 - 2016-08-06 16:15 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll 2016-10-12 09:39 - 2016-06-14 18:16 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2016-10-12 09:39 - 2016-06-14 16:21 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2016-10-12 09:32 - 2016-07-22 15:58 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2016-10-12 09:32 - 2016-07-22 15:51 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2016-10-12 09:26 - 2016-08-16 21:40 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2016-10-12 09:26 - 2016-08-16 21:40 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2016-10-12 09:25 - 2016-08-29 16:04 - 003229696 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2016-10-12 09:25 - 2016-08-29 15:55 - 002972672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2016-10-11 16:20 - 2017-03-08 15:58 - 000000000 ____D C:\Users\Rudi\Documents\MSM 2016-10-08 10:59 - 2017-03-12 14:46 - 000000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini 2016-10-08 10:59 - 2016-10-08 10:59 - 000000000 ____D C:\Users\Public\Documents\Atheros 2016-10-07 19:20 - 2016-10-07 19:20 - 000000000 ____D C:\Users\Rudi\AppData\Local\{C62911B6-2249-4E28-B35B-BD9C097F8B3A} 2016-10-07 18:52 - 2016-10-07 18:52 - 000000000 ____D C:\Users\Rudi\AppData\Local\{52BFEE37-115B-45C3-B61A-62741FFC7137} 2016-10-07 13:15 - 2011-05-30 13:42 - 000255488 _____ C:\Windows\system32\xvidvfw.dll 2016-10-07 13:15 - 2011-05-30 13:42 - 000240640 _____ C:\Windows\SysWOW64\xvidvfw.dll 2016-10-07 13:15 - 2011-05-23 07:46 - 000645632 _____ C:\Windows\SysWOW64\xvidcore.dll 2016-10-07 13:15 - 2011-05-23 07:45 - 000696832 _____ C:\Windows\system32\xvidcore.dll 2016-10-06 11:55 - 2017-06-11 10:49 - 000000000 ____D C:\Users\Rudi\Documents\Youcam 2016-10-05 16:29 - 2016-10-05 16:29 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Sun 2016-10-05 16:29 - 2016-10-05 16:29 - 000000000 ____D C:\Users\Rudi\.oracle_jre_usage 2016-10-02 10:38 - 1817-09-17 11:22 - 000197120 _____ C:\Users\Rudi\Documents\Dinklage bis Bippen.axe 2016-09-25 14:39 - 2016-09-25 14:39 - 000000234 _____ C:\Users\Rudi\Desktop\WEB.DE - E-Mail-Adresse kostenlos, FreeMail, De-Mail & Nachrichten.url 2016-09-24 16:00 - 2016-07-07 16:08 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2016-09-24 15:18 - 2016-05-12 16:18 - 000090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll 2016-09-14 14:22 - 2016-09-14 14:22 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\TuneUp Software 2016-09-14 14:08 - 2016-09-23 09:44 - 000000000 ____D C:\ProgramData\TuneUp Software 2016-09-14 09:09 - 2016-09-14 09:09 - 000000000 ____D C:\Users\Rudi\DxReport 2016-09-14 09:01 - 2016-09-14 09:01 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\LaunchPad 2016-09-05 05:47 - 2016-09-05 05:47 - 000165504 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudmdm.sys 2016-09-05 05:47 - 2016-09-05 05:47 - 000131712 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudbus.sys 2016-08-26 09:54 - 2016-08-26 09:54 - 000000000 ____D C:\Users\Rudi\AppData\Local\{450F5E8A-ABCD-48FA-9BE8-1BAE77A879B3} 2016-08-24 10:36 - 2016-08-24 10:36 - 000000000 ____D C:\Users\Rudi\AppData\Local\{7258F52A-C1F9-4672-AF5B-B26BF766D3D8} 2016-08-04 13:11 - 2016-08-04 13:11 - 000000000 ____D C:\Users\Rudi\AppData\Local\{42470E0F-B917-4A0A-B3D0-F2EA3CA55F6B} 2016-07-30 08:36 - 2011-01-01 04:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2016-07-26 12:41 - 2016-07-26 12:41 - 000001272 _____ C:\Users\Rudi\Desktop\Snipping Tool.lnk 2016-07-21 17:38 - 2016-07-21 17:39 - 000000000 ___HD C:\Windows\AxInstSV 2016-07-14 13:34 - 2016-07-14 13:34 - 000002272 _____ C:\Users\Public\Desktop\HP Deskjet 1000 J110 series.lnk 2016-07-14 13:34 - 2016-07-14 13:34 - 000001194 _____ C:\Users\Public\Desktop\Shop für Zubehör - HP Deskjet 1000 J110 series.lnk 2016-07-14 13:30 - 2016-07-14 13:30 - 000000000 ____D C:\Program Files\HP 2016-07-13 20:55 - 2016-06-26 01:27 - 000344576 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2016-07-13 20:55 - 2016-06-26 01:27 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2016-07-13 20:55 - 2016-06-26 01:27 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2016-07-13 20:55 - 2016-06-25 20:53 - 000297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll 2016-07-13 20:55 - 2016-06-25 20:53 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe 2016-07-13 20:55 - 2016-06-25 20:53 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe 2016-07-13 20:55 - 2016-06-25 20:41 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe 2016-07-13 12:39 - 2016-07-13 12:39 - 004775224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140u.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 004705072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000440128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000400192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcamp140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000267592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vccorlib140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000244032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\concrt140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000138560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcomp140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000095552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm140u.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000095032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000083792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcruntime140.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000075584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140fra.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000075584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140deu.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000074560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140esn.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000073536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140ita.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000071488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140rus.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000065856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140enu.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000055104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140jpn.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000054080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140kor.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000046912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140cht.dll 2016-07-13 12:39 - 2016-07-13 12:39 - 000046912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc140chs.dll 2016-07-01 17:27 - 2016-07-01 17:27 - 000000000 ____D C:\ProgramData\MetaQuotes 2016-07-01 17:06 - 2016-07-03 14:43 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\MetaQuotes 2016-06-29 18:00 - 2016-07-21 18:52 - 000000000 __SHD C:\Users\Rudi\Documents\cache 2016-06-29 18:00 - 2016-06-29 18:00 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\webex 2016-06-29 17:59 - 2016-07-21 18:05 - 000000000 _____ C:\ProgramData\WebEx 2016-06-17 19:51 - 2016-05-12 14:05 - 000297984 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2016-06-17 19:51 - 2016-05-12 14:04 - 000249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2016-06-17 19:49 - 2016-05-12 18:15 - 000105472 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll 2016-06-17 19:49 - 2016-05-12 18:14 - 000794624 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll 2016-06-17 19:49 - 2016-05-12 18:14 - 000502272 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL 2016-06-17 19:49 - 2016-05-12 18:14 - 000373760 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll 2016-06-17 19:49 - 2016-05-12 18:14 - 000096256 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll 2016-06-17 19:49 - 2016-05-12 18:14 - 000075776 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll 2016-06-17 19:49 - 2016-05-12 16:18 - 000274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll 2016-06-17 19:49 - 2016-05-12 16:18 - 000079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll 2016-06-17 19:49 - 2016-05-12 16:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll 2016-06-17 19:49 - 2016-05-12 16:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll 2016-06-17 19:49 - 2016-05-11 18:02 - 000483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll 2016-06-17 19:49 - 2016-05-11 16:19 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll 2016-06-17 18:31 - 2016-05-11 18:02 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2016-06-17 18:31 - 2016-05-11 18:02 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2016-06-17 18:31 - 2016-05-11 18:02 - 000296448 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll 2016-06-17 18:31 - 2016-05-11 16:19 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2016-06-17 18:31 - 2016-05-11 16:19 - 000231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2016-06-17 18:31 - 2016-05-11 16:19 - 000206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll 2016-06-17 18:31 - 2016-05-11 16:11 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe 2016-06-17 18:31 - 2016-05-11 16:01 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe 2016-06-17 18:31 - 2016-05-11 15:58 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2016-06-17 18:27 - 2016-03-09 20:00 - 000396800 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2016-06-17 18:27 - 2016-03-09 19:40 - 000316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2016-05-12 21:38 - 2016-04-14 14:49 - 000603648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2016-05-12 21:38 - 2016-04-14 14:21 - 000647680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2016-05-12 21:34 - 2016-03-09 19:54 - 000275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2016-05-12 21:34 - 2016-03-09 19:34 - 000216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2016-05-12 21:12 - 2016-04-09 05:20 - 001230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2016-05-12 21:12 - 2016-04-09 04:52 - 001424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2016-04-24 20:05 - 2016-04-24 20:05 - 000003054 _____ C:\Windows\System32\Tasks\{C1DBE46F-1E15-4A65-9A75-42E1DF8ADE50} 2016-04-24 20:04 - 2016-04-24 20:04 - 000003058 _____ C:\Windows\System32\Tasks\{75924CED-E37F-454E-83A7-E68F9ED175C1} 2016-04-20 14:36 - 2016-04-20 14:36 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Temp 2016-04-15 12:25 - 2016-03-16 19:50 - 000156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-04-15 12:25 - 2016-03-16 19:28 - 000176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-04-15 12:25 - 2016-03-16 19:28 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-04-15 12:25 - 2015-06-03 21:17 - 000546656 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2016-04-15 12:24 - 2016-01-21 01:51 - 000073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2016-04-14 12:49 - 2016-02-05 19:56 - 000020480 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll 2016-04-14 12:49 - 2016-02-05 19:54 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll 2016-04-14 12:49 - 2016-02-05 18:33 - 000015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll 2016-04-14 12:49 - 2015-06-03 21:21 - 000451080 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll 2016-03-17 19:15 - 1999-01-20 05:01 - 000210032 _____ C:\Windows\SysWOW64\DBCLIENT.DLL 2016-03-17 19:14 - 2016-04-14 11:46 - 000000000 ____D C:\Program Files (x86)\IN MEDIA KG - CSV-Editor 2016-03-17 18:59 - 2016-03-17 18:59 - 000000000 ____D C:\ProgramData\PC1Data 2016-03-10 21:09 - 2016-01-11 20:11 - 001684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2016-03-10 21:08 - 2016-02-09 10:55 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll 2016-03-10 21:06 - 2016-02-03 19:07 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2016-03-10 20:53 - 2016-02-05 02:19 - 000381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2016-03-10 20:53 - 2016-02-04 19:41 - 000296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll 2016-02-24 16:58 - 2016-02-24 16:58 - 000000000 ____D C:\Users\Rudi\AppData\Local\{B791B576-2C0B-4068-BC8C-34DDE1246DA6} 2016-02-24 16:21 - 2016-02-24 16:21 - 000000000 ____D C:\Users\Rudi\Tracing 2016-02-11 08:21 - 2016-01-22 07:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2016-02-11 08:21 - 2016-01-22 07:18 - 000723968 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2016-02-11 08:21 - 2016-01-22 07:04 - 000642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2016-02-11 08:21 - 2016-01-22 07:04 - 000535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2016-01-15 17:33 - 2015-11-14 00:09 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll 2016-01-15 17:33 - 2015-11-14 00:09 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll 2016-01-15 17:33 - 2015-11-14 00:08 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe 2016-01-15 17:33 - 2015-11-13 23:50 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll 2016-01-15 17:33 - 2015-11-13 23:50 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll 2016-01-15 17:33 - 2015-11-13 23:49 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe 2016-01-15 17:32 - 2015-12-08 22:54 - 001620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 001568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll 2016-01-15 17:32 - 2015-12-08 22:54 - 000739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL 2016-01-15 17:32 - 2015-12-08 22:54 - 000541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL 2016-01-15 17:32 - 2015-12-08 22:53 - 000970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll 2016-01-15 17:32 - 2015-12-08 22:53 - 000829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL 2016-01-15 17:32 - 2015-12-08 22:53 - 000153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll 2016-01-15 17:32 - 2015-12-08 20:07 - 001232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 001026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2016-01-15 17:32 - 2015-12-08 20:07 - 001010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2016-01-15 17:32 - 2015-12-08 20:07 - 000978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 000666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 000642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2016-01-15 17:32 - 2015-12-08 20:07 - 000189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL 2016-01-15 17:31 - 2015-12-08 22:54 - 002285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2016-01-15 17:31 - 2015-12-08 22:54 - 001325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL 2016-01-15 17:31 - 2015-12-08 22:54 - 000358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL 2016-01-15 17:31 - 2015-12-08 22:54 - 000154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2016-01-15 17:31 - 2015-12-08 22:53 - 000415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll 2016-01-15 17:31 - 2015-12-08 22:53 - 000193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax 2016-01-15 17:31 - 2015-12-08 22:53 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL 2016-01-15 17:31 - 2015-12-08 22:53 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll 2016-01-15 17:31 - 2015-12-08 22:53 - 000053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll 2016-01-15 17:31 - 2015-12-08 22:53 - 000004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 002777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 001393152 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL 2016-01-15 17:31 - 2015-12-08 20:07 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll 2016-01-15 17:31 - 2015-12-08 20:07 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll 2016-01-15 17:31 - 2015-12-08 20:06 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax 2016-01-15 17:31 - 2015-12-08 19:54 - 000116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2016-01-15 17:31 - 2015-12-08 19:12 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2016-01-15 17:31 - 2015-12-08 19:11 - 000005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys 2015-12-21 10:41 - 2016-10-10 17:14 - 000921624 _____ C:\snp2uvc-001.raw 2015-12-21 10:36 - 2015-12-21 10:36 - 000000828 _____ C:\Users\Public\Desktop\AMCap.lnk 2015-12-21 10:36 - 2015-12-21 10:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Video Device 2015-12-21 10:36 - 2012-05-25 11:36 - 000376832 _____ (Sonix Technology Co., Ltd.) C:\Windows\system32\vsnp2uvc.dll 2015-12-21 10:36 - 2012-05-25 11:33 - 000306688 _____ (Sonix Technology Co., Ltd.) C:\Windows\SysWOW64\vsnp2uvc.dll 2015-12-21 10:36 - 2009-08-13 20:33 - 000239616 _____ ( ) C:\Windows\SysWOW64\rsnp2uvc.dll 2015-12-21 10:36 - 2009-08-13 20:33 - 000238080 _____ ( ) C:\Windows\system32\rsnp2uvc.dll 2015-12-21 10:36 - 2009-08-12 15:06 - 000662016 _____ (Sonix) C:\Windows\vsnp2uvc.exe 2015-12-21 10:36 - 2009-07-21 12:08 - 000013021 _____ C:\Windows\snp2uvc.src 2015-12-21 10:36 - 2009-02-16 18:33 - 000306176 _____ ( ) C:\Windows\system32\csnp2uvc.dll 2015-12-21 10:36 - 2006-05-19 11:39 - 000015497 _____ C:\Windows\snp2uvc.ini 2015-12-21 10:26 - 2012-06-27 15:29 - 003568128 _____ () C:\Windows\system32\Drivers\snp2uvc.sys 2015-12-21 10:26 - 2011-08-21 10:46 - 000035584 _____ C:\Windows\system32\Drivers\sncduvc.sys 2015-12-09 22:20 - 2015-11-05 20:05 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll 2015-12-09 22:20 - 2015-11-05 20:02 - 000014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll 2015-12-09 22:20 - 2015-11-05 10:53 - 000146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-12-09 21:31 - 2015-10-09 00:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL 2015-12-09 21:31 - 2015-10-09 00:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll 2015-12-09 21:31 - 2015-10-09 00:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL 2015-12-09 21:31 - 2015-10-09 00:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL 2015-12-09 21:31 - 2015-10-09 00:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll 2015-12-09 21:31 - 2015-10-09 00:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL 2015-12-09 21:30 - 2015-11-03 20:04 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll 2015-12-09 21:30 - 2015-11-03 19:55 - 000179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll 2015-12-09 21:04 - 2015-11-11 19:53 - 001735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-12-09 21:03 - 2015-11-11 19:53 - 000525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2015-12-09 21:03 - 2015-11-11 19:39 - 001242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll 2015-12-09 21:03 - 2015-11-11 19:39 - 000487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll 2015-11-26 10:18 - 2015-11-26 10:18 - 000002055 _____ C:\Users\Public\Desktop\WISO steuer Sparbuch 2016.lnk 2015-11-26 10:18 - 2015-11-26 10:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO steuer Sparbuch 2016 2015-11-15 23:11 - 2015-10-29 18:50 - 000342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-11-15 23:11 - 2015-10-29 18:50 - 000072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-11-15 23:11 - 2015-10-29 18:50 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-11-15 23:11 - 2015-10-29 18:50 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-11-15 23:11 - 2015-10-29 18:50 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-11-15 23:11 - 2015-10-29 18:49 - 000295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-11-15 23:11 - 2015-10-29 18:49 - 000020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-11-15 21:51 - 2015-10-13 05:57 - 000950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-11-09 16:43 - 2015-11-09 16:43 - 000000000 ____D C:\Users\Rudi\mimviewer 2015-11-06 16:59 - 2015-11-06 16:59 - 000001277 _____ C:\Users\Rudi\Desktop\CyberLink YouCam.lnk 2015-11-01 11:18 - 2015-11-01 11:18 - 000002998 _____ C:\Windows\System32\Tasks\{B8475E7F-7DC6-4E2A-9211-0988C160EF29} 2015-11-01 11:18 - 2015-11-01 11:18 - 000002998 _____ C:\Windows\System32\Tasks\{B18FA98A-E82C-4A91-8381-F27EE8F93E80} 2015-11-01 11:18 - 2015-11-01 11:18 - 000002998 _____ C:\Windows\System32\Tasks\{86259AB4-CAA0-43BB-B56E-53709CCA447D} 2015-11-01 11:18 - 2015-11-01 11:18 - 000002998 _____ C:\Windows\System32\Tasks\{1D96B393-3B3C-4731-8BBE-C2A5818DD354} 2015-11-01 11:16 - 2015-11-01 11:16 - 000002998 _____ C:\Windows\System32\Tasks\{42894C95-CACE-48E5-8FA9-03180ABC6D82} 2015-10-27 10:35 - 2016-09-11 15:38 - 000007620 _____ C:\Users\Rudi\AppData\Local\Resmon.ResmonCfg 2015-10-22 10:09 - 2015-10-22 10:09 - 000993632 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll 2015-10-22 10:09 - 2015-10-22 10:09 - 000987848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll 2015-10-22 10:08 - 2015-10-22 10:08 - 000690016 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll 2015-10-22 10:08 - 2015-10-22 10:08 - 000484552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll 2015-09-14 11:56 - 2015-09-14 11:56 - 000000000 ____D C:\Users\Rudi\AppData\Local\CEF 2015-09-10 16:59 - 2015-09-10 16:59 - 000000000 ____D C:\Users\Rudi\Phone Browser 2015-09-10 16:59 - 2015-09-10 16:59 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\PC Suite 2015-09-10 16:57 - 2015-09-10 17:13 - 000000000 ____D C:\Program Files (x86)\Nokia 2015-09-09 08:17 - 2015-07-23 01:02 - 000879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-09-09 08:16 - 2015-07-22 18:53 - 000635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-09-09 08:12 - 2015-08-05 18:56 - 001110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2015-09-09 08:10 - 2015-07-09 18:58 - 001632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-09-09 08:10 - 2015-07-09 18:58 - 000082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll 2015-09-09 08:10 - 2015-07-09 18:42 - 001372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2015-09-09 08:10 - 2015-07-09 18:42 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll 2015-09-09 08:03 - 2015-08-27 19:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2015-09-09 08:03 - 2015-08-27 19:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2015-09-09 08:03 - 2015-08-27 18:58 - 001391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2015-09-09 08:03 - 2015-08-27 18:51 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2015-09-07 18:12 - 2017-05-04 16:24 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-09-07 18:10 - 2017-04-11 17:16 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-09-07 18:10 - 2015-09-07 18:10 - 000002007 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-09-07 18:10 - 2015-09-07 18:10 - 000000000 ich hoffe jetzt alles richtig gemacht zu haben. Gruß Rudi |
19.09.2017, 11:32 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Zertifikatfehler, Navigation FRST.txt ist unvollständig
__________________ --> Zertifikatfehler, Navigation |
19.09.2017, 12:43 | #7 |
| Frst2Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 17-09-2017 01 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-09-07 18:10 - 2015-09-07 18:10 - 000002007 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-09-07 18:10 - 2015-09-07 18:10 - 000000000 ____D C:\Program Files (x86)\Adobe 2015-09-07 17:07 - 2015-09-07 17:07 - 002659296 _____ C:\Users\Rudi\Downloads\avira_speedup.exe 2015-08-13 17:29 - 2015-07-15 19:10 - 001743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2015-08-13 17:23 - 2015-07-15 04:19 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll 2015-08-13 08:35 - 2015-07-30 14:13 - 000124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-08-13 08:35 - 2015-07-30 14:13 - 000103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-08-12 14:28 - 2015-07-10 18:51 - 003722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-08-12 14:28 - 2015-07-10 18:51 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2015-08-12 14:28 - 2015-07-10 18:51 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2015-08-12 14:28 - 2015-07-10 18:34 - 003221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2015-08-12 14:28 - 2015-07-10 18:34 - 000036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2015-08-12 14:28 - 2015-07-10 18:33 - 000131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2015-08-12 14:17 - 2015-07-30 19:06 - 002565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2015-08-12 14:17 - 2015-07-30 18:57 - 001987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2015-08-12 14:16 - 2015-07-09 18:57 - 000193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2015-08-12 14:16 - 2015-07-09 18:57 - 000193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe 2015-08-12 14:16 - 2015-07-09 18:42 - 000179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe 2015-08-12 14:12 - 2015-05-09 19:26 - 000493504 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll 2015-07-19 21:01 - 2015-06-02 01:07 - 000254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll 2015-07-19 21:01 - 2015-06-02 00:47 - 000210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll 2015-06-24 22:31 - 2015-06-24 22:31 - 000000000 ____D C:\Users\Rudi\AppData\Local\GWX 2015-06-10 21:16 - 2015-05-25 19:19 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-10 21:16 - 2015-05-25 19:18 - 000404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-10 21:16 - 2015-05-25 19:18 - 000104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-10 21:16 - 2015-05-25 19:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-10 21:16 - 2015-05-25 19:18 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-10 21:16 - 2015-05-25 19:18 - 000019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-10 21:16 - 2015-05-25 19:01 - 000092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2015-06-10 21:16 - 2015-05-25 19:00 - 000364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe 2015-06-10 21:16 - 2015-05-25 19:00 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe 2015-06-10 21:16 - 2015-05-25 19:00 - 000040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe 2015-06-10 21:16 - 2015-05-25 19:00 - 000037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe 2015-06-10 21:16 - 2015-05-25 19:00 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe 2015-06-10 21:10 - 2015-04-24 19:17 - 000633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-10 21:10 - 2015-04-24 18:56 - 000530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2015-06-10 21:00 - 2015-04-11 04:19 - 000069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-06-10 20:59 - 2016-02-24 16:20 - 000000000 ____D C:\Users\Rudi\AppData\Local\Skype 2015-05-26 10:31 - 2015-05-26 10:31 - 000000000 ____D C:\Users\Rudi\AppData\Local\{9796655F-EFD8-4EA2-8080-B5E58C67BB4B} 2015-05-14 20:46 - 2015-04-13 04:28 - 000328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe 2015-05-14 20:42 - 2015-01-29 04:19 - 002543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll 2015-05-14 20:42 - 2015-01-29 04:02 - 002311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll 2015-04-29 08:00 - 2015-04-29 08:00 - 000000000 ____D C:\Users\Rudi\AppData\Local\{2846B882-0C65-4FED-908E-0FFDBBCA5B5E} 2015-04-29 07:59 - 2015-04-29 07:59 - 000000000 ____D C:\Users\Rudi\AppData\Local\{606805A1-86B0-41A5-90B9-775F3A690E90} 2015-04-15 20:19 - 2015-02-25 04:18 - 000754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-15 20:15 - 2015-03-04 05:41 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-15 20:15 - 2015-03-04 05:10 - 000058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2015-03-11 10:35 - 2015-02-03 04:31 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-11 10:35 - 2015-02-03 04:12 - 000171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll 2015-03-11 09:59 - 2015-02-04 04:16 - 000465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-11 09:59 - 2015-02-04 03:54 - 000417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2015-02-11 11:00 - 2015-01-09 04:14 - 000950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll 2015-02-11 11:00 - 2015-01-09 04:14 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll 2015-02-11 11:00 - 2015-01-09 04:14 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll 2015-02-11 11:00 - 2015-01-09 03:48 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll 2015-02-11 10:52 - 2015-01-28 00:36 - 001239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-02-11 10:43 - 2014-12-08 04:09 - 000406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-02-11 10:43 - 2014-12-08 03:46 - 000308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll 2015-01-22 08:27 - 2017-05-02 14:31 - 000097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-01-14 13:14 - 2014-12-19 04:06 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-14 13:14 - 2014-12-11 18:47 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-14 13:14 - 2014-12-06 05:17 - 000303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 13:14 - 2014-12-06 04:50 - 000156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-14 13:14 - 2014-12-06 04:50 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-14 13:13 - 2014-06-28 01:21 - 000457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-01-06 16:27 - 2017-06-26 10:19 - 000000000 ____D C:\ProgramData\Package Cache 2015-01-05 10:44 - 2017-02-14 17:41 - 000000000 ___DC C:\Users\Rudi\AppData\Local\MigWiz 2014-12-22 17:43 - 2016-04-20 16:10 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\PhotoScape 2014-12-22 17:43 - 2014-12-22 17:43 - 000000991 _____ C:\Users\Rudi\Desktop\PhotoScape.lnk 2014-12-22 17:43 - 2014-12-22 17:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape 2014-12-22 17:43 - 2014-12-22 17:43 - 000000000 ____D C:\Program Files (x86)\PhotoScape 2014-12-11 09:50 - 2014-12-11 09:50 - 000000000 ____D C:\Users\Rudi\AppData\Local\{579DC522-D085-4998-9457-3CBAEA8E2884} 2014-12-11 09:37 - 2014-12-11 09:37 - 000000000 ____D C:\Users\Rudi\AppData\Local\{BE2FB535-7F64-4CE2-B5C5-D24212E6B690} 2014-12-11 09:07 - 2014-12-11 09:07 - 000000000 ____D C:\Users\Rudi\AppData\Local\{5305EBDB-6814-429B-BD30-86C68E56A075} 2014-12-11 08:52 - 2014-12-11 08:52 - 000000000 ____D C:\Users\Rudi\AppData\Local\{D0995299-7F6E-4F60-9367-F6A6E5581504} 2014-12-11 07:22 - 2017-03-17 11:51 - 000000000 ____D C:\Windows\system32\appraiser 2014-12-10 09:43 - 2014-12-10 09:43 - 000000000 ____D C:\Users\Rudi\AppData\Local\{2919DC2B-E0FD-4065-9012-6615B48C3425} 2014-12-10 06:21 - 2014-10-30 03:03 - 000165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-10 06:21 - 2014-10-30 02:45 - 000155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2014-12-07 11:39 - 2016-06-29 17:59 - 000000000 ____D C:\Users\Rudi\AppData\LocalLow\Temp 2014-11-26 18:17 - 2014-11-26 18:17 - 000000000 ____D C:\Users\Rudi\AppData\LocalLow\Oracle 2014-11-24 01:12 - 2016-04-20 13:49 - 000000000 __SHD C:\Users\Rudi\AppData\LocalLow\EmieUserList 2014-11-24 01:12 - 2016-04-20 13:49 - 000000000 __SHD C:\Users\Rudi\AppData\LocalLow\EmieSiteList 2014-11-24 01:12 - 2016-04-20 13:49 - 000000000 __SHD C:\Users\Rudi\AppData\LocalLow\EmieBrowserModeList 2014-11-24 00:29 - 2014-11-11 04:08 - 000241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-24 00:29 - 2014-11-11 03:44 - 000186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-17 08:39 - 2015-06-11 18:51 - 000000000 __SHD C:\Users\Rudi\AppData\Local\EmieBrowserModeList 2014-11-14 13:27 - 2014-10-14 03:13 - 000683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-14 11:09 - 2014-10-25 02:57 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-14 11:09 - 2014-10-25 02:32 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-20 07:15 - 2014-06-18 23:23 - 001943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-20 07:15 - 2014-06-18 23:23 - 001131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-10-20 07:15 - 2014-06-18 23:23 - 000156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2014-10-20 07:15 - 2014-06-18 23:23 - 000156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-20 07:15 - 2014-06-18 23:23 - 000081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2014-10-20 07:15 - 2014-06-18 23:23 - 000073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-20 07:07 - 2014-07-17 03:07 - 001118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-20 07:07 - 2014-07-17 03:07 - 000235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-20 07:07 - 2014-07-17 02:40 - 000157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll 2014-10-20 07:07 - 2014-07-17 02:39 - 001051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-10-20 07:07 - 2014-07-17 02:21 - 000212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-20 07:06 - 2014-07-17 03:07 - 000455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-20 07:06 - 2014-07-17 03:07 - 000150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-20 07:06 - 2014-07-17 02:21 - 000039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-20 00:49 - 2014-07-09 03:03 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-10-20 00:49 - 2014-07-09 03:03 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-10-20 00:49 - 2014-07-09 03:03 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-10-20 00:49 - 2014-07-09 03:03 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-10-20 00:49 - 2014-07-09 03:03 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-10-20 00:49 - 2014-07-09 02:31 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-10-20 00:49 - 2014-07-09 02:31 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-10-20 00:49 - 2014-07-09 02:31 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-10-20 00:49 - 2014-07-09 02:31 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-10-20 00:49 - 2014-07-09 02:31 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-10-20 00:45 - 2014-09-04 06:23 - 000424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-20 00:45 - 2014-09-04 06:04 - 000372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2014-09-12 07:46 - 2014-09-12 07:46 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Oracle 2014-09-12 07:44 - 2017-05-02 14:34 - 000000000 ____D C:\ProgramData\Oracle 2014-09-12 07:43 - 2017-05-02 14:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-09-12 07:43 - 2015-01-22 08:23 - 000272296 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-09-11 17:36 - 2014-08-01 12:53 - 001031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-09-11 17:36 - 2014-08-01 12:35 - 000793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-08-17 19:34 - 2014-06-30 23:24 - 000008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-17 19:34 - 2014-06-30 23:14 - 000008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-17 19:34 - 2014-06-06 07:16 - 000035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-17 19:34 - 2014-06-06 07:12 - 000035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-17 19:34 - 2014-03-09 22:48 - 001389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-17 19:34 - 2014-03-09 22:48 - 000171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-17 19:34 - 2014-03-09 22:47 - 000619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-17 19:34 - 2014-03-09 22:47 - 000099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-07-25 09:29 - 2014-07-25 09:29 - 000000000 ____D C:\Users\Rudi\AppData\Local\{2F73EFBA-A2D8-4417-814C-65C07F6AC923} 2014-07-25 09:23 - 2014-07-25 09:23 - 000000000 ____D C:\Users\Rudi\AppData\Local\{0F8A34DC-4A8B-44E7-B7EF-631BE12CDEC7} 2014-07-25 08:51 - 2014-07-25 08:51 - 000000000 ____D C:\Users\Rudi\AppData\Local\{B35265CB-0654-4C45-8811-86D20A392B40} 2014-07-25 08:42 - 2014-07-25 08:42 - 000000000 ____D C:\Users\Rudi\AppData\Local\{930B3B9B-A57B-4162-9F1C-12EC7FAAE0BE} 2014-07-25 08:40 - 2014-07-25 08:40 - 000000000 ____D C:\Users\Rudi\AppData\Local\{96B7A543-4D5E-4E26-A89D-73652A79EDFC} 2014-07-25 08:27 - 2014-07-25 08:27 - 000000000 ____D C:\Users\Rudi\AppData\Local\{DC9A9976-A577-4324-8F00-6DEF082B0F88} 2014-07-10 07:30 - 2014-06-18 03:18 - 000692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-10 07:30 - 2014-06-18 02:51 - 000646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-06-05 11:27 - 2014-06-05 11:27 - 000000000 ___RD C:\Users\Rudi\AppData\Roaming\Brother 2014-06-05 10:22 - 2014-06-05 10:22 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Buhl Data Service 2014-06-05 10:22 - 2014-06-05 10:22 - 000000000 ____D C:\Users\Rudi\AppData\Local\Buhl Data Service 2014-06-02 12:23 - 2017-03-13 15:46 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Buhl 2014-05-19 12:21 - 2016-10-15 14:55 - 000000783 _____ C:\Windows\wiso.ini 2014-05-19 12:20 - 2017-02-14 14:11 - 000000000 ____D C:\Users\Rudi\AppData\Local\Buhl 2014-05-19 12:14 - 2017-02-14 14:02 - 000000000 ____D C:\Program Files (x86)\WISO 2014-05-19 12:12 - 2017-02-14 14:14 - 000000000 ____D C:\ProgramData\Buhl Data Service GmbH 2014-05-19 11:42 - 2017-02-12 15:51 - 000000469 _____ C:\Windows\BRWMARK.INI 2014-05-19 11:42 - 2014-05-19 11:42 - 000000034 _____ C:\Windows\SysWOW64\BD2030.DAT 2014-05-14 22:49 - 2014-03-04 10:44 - 000722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 22:49 - 2014-03-04 10:44 - 000039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 22:49 - 2014-03-04 10:43 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 22:49 - 2014-03-04 10:43 - 000056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 22:49 - 2014-03-04 10:43 - 000053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 22:49 - 2014-03-04 10:43 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 22:49 - 2014-03-04 10:43 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 22:49 - 2014-03-04 10:17 - 000538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 22:49 - 2014-03-04 10:17 - 000051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 22:49 - 2014-03-04 10:17 - 000049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 22:49 - 2014-03-04 10:17 - 000048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 22:49 - 2014-03-04 10:17 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 22:49 - 2014-03-04 10:17 - 000036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 22:49 - 2014-03-04 10:17 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-07 07:52 - 2017-03-17 11:51 - 000000000 ___SD C:\Windows\system32\CompatTel 2014-04-24 09:21 - 2014-04-24 09:21 - 000000000 ____D C:\Users\Rudi\AppData\Local\{EAAF76D3-E4F0-4A06-A62C-1E453F2E91B3} 2014-04-22 18:19 - 2014-04-22 18:20 - 000000000 ____D C:\Users\Rudi\AppData\Local\{D146E770-6382-4A5F-97DB-3D8E9770661F} 2014-04-22 17:04 - 2014-04-22 17:04 - 000000000 ____D C:\Users\Rudi\AppData\Local\{4E969717-2096-4749-A6C4-16FFDC3F19A6} 2014-04-22 08:18 - 2014-04-22 08:18 - 000000000 ____D C:\Users\Rudi\AppData\Local\{6B070201-BFD2-40FD-B7ED-1637ADEA9C4A} 2014-04-22 08:04 - 2014-04-22 08:04 - 000000000 ____D C:\Users\Rudi\AppData\Local\{F4214A6A-18B5-4963-80B2-8680D891BFC9} 2014-04-22 08:01 - 2014-04-22 08:01 - 000000000 ____D C:\Users\Rudi\AppData\Local\{23FC134B-1ACD-4878-9CA7-06BBD5D21B51} 2014-04-22 07:56 - 2014-04-22 07:56 - 000000000 ____D C:\Users\Rudi\AppData\Local\{22CDE6C8-8F62-4C4C-93DB-78C3F393F480} 2014-04-22 07:49 - 2014-04-22 07:49 - 000000000 ____D C:\Users\Rudi\AppData\Local\{6921E53E-0898-4B4C-A07F-F29C3607E500} 2014-04-22 07:48 - 2014-04-22 07:48 - 000000000 ____D C:\Users\Rudi\AppData\Local\{12C52CCC-E87E-4A54-B1D3-9123C6416850} 2014-04-18 08:19 - 2015-06-11 18:51 - 000000000 __SHD C:\Users\Rudi\AppData\Local\EmieUserList 2014-04-18 08:19 - 2015-06-11 18:51 - 000000000 __SHD C:\Users\Rudi\AppData\Local\EmieSiteList 2014-04-10 18:41 - 2014-02-04 03:35 - 000274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 18:41 - 2014-02-04 03:35 - 000190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 18:41 - 2014-02-04 03:35 - 000027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 18:41 - 2014-02-04 03:28 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 18:41 - 2014-02-04 03:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-02 16:20 - 2014-04-02 16:20 - 000000000 ____D C:\Users\Rudi\AppData\Local\{D5145900-15AC-4F97-B413-E569BF70F4EB} 2014-04-02 16:19 - 2014-04-02 16:19 - 000000000 ____D C:\Users\Rudi\AppData\Local\{585E575F-E7F8-4E09-8560-56151CE4D760} 2014-04-02 16:17 - 2014-04-02 16:17 - 000000000 ____D C:\Users\Rudi\AppData\Local\{8EAB2585-0786-464C-9157-88AE6D34796A} 2014-03-12 07:59 - 2014-01-29 03:32 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-12 07:59 - 2014-01-29 03:06 - 000381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-12 07:58 - 2014-01-28 03:32 - 000228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-03 10:49 - 2014-03-03 10:49 - 000000000 ____D C:\Users\Rudi\AppData\Local\{2C54501D-D63A-4FD8-A713-424D6033FA10} 2014-03-03 10:46 - 2014-03-03 10:46 - 000000000 ____D C:\Users\Rudi\AppData\Local\{EDB1A5A4-295E-4074-9395-4A4B09678660} 2014-03-03 10:31 - 2014-03-03 10:31 - 000000000 ____D C:\Users\Rudi\AppData\Local\{C94D3025-2314-41CE-8989-BE04D9F3B24E} 2014-02-12 09:03 - 2013-12-04 03:27 - 000488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 09:03 - 2013-12-04 03:27 - 000485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 09:03 - 2013-12-04 03:27 - 000123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 09:03 - 2013-12-04 03:27 - 000123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 09:03 - 2013-12-04 03:26 - 000528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 09:03 - 2013-12-04 03:16 - 000658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 09:03 - 2013-12-04 03:16 - 000626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 09:03 - 2013-12-04 03:16 - 000553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 09:03 - 2013-12-04 03:16 - 000552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 09:03 - 2013-12-04 03:03 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 09:03 - 2013-12-04 03:03 - 000423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 09:03 - 2013-12-04 03:03 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 09:03 - 2013-12-04 03:03 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 09:03 - 2013-12-04 03:02 - 000390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 09:03 - 2013-12-04 02:54 - 000594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 09:03 - 2013-12-04 02:54 - 000572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 09:03 - 2013-12-04 02:54 - 000510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 09:03 - 2013-12-04 02:54 - 000508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 09:02 - 2013-11-26 09:16 - 003419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 09:02 - 2013-11-22 23:48 - 003928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-01-12 21:22 - 2014-01-12 21:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Connect 2014-01-12 21:21 - 2014-01-12 21:21 - 000001961 _____ C:\Users\Public\Desktop\TotalMedia 3.5.lnk 2014-01-12 21:21 - 2014-01-12 21:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft TotalMedia 3.5 2014-01-12 21:20 - 2014-01-12 21:20 - 000000000 ____D C:\Program Files (x86)\ArcSoft 2014-01-12 21:20 - 2005-04-27 16:36 - 000245408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unicows.dll 2014-01-06 13:29 - 2003-03-18 22:14 - 000499712 ____R (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2014-01-06 13:29 - 2003-02-21 04:42 - 000348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2013-12-12 18:15 - 2013-10-30 03:32 - 000335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-12 18:15 - 2013-10-30 03:19 - 000301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-12 18:15 - 2013-10-19 03:18 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 18:15 - 2013-10-19 02:36 - 000159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-12 18:15 - 2013-10-12 03:32 - 000150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 18:15 - 2013-10-12 03:31 - 000202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 18:15 - 2013-10-12 03:04 - 000121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-12 18:15 - 2013-10-12 03:03 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-12 18:15 - 2013-10-12 02:33 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 18:15 - 2013-10-12 02:33 - 000156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-12 18:15 - 2013-10-12 02:15 - 000141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-12 18:15 - 2013-10-12 02:15 - 000126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-11-29 08:59 - 2013-10-14 18:00 - 000028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-29 08:47 - 2013-11-29 08:47 - 000942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-29 08:47 - 2013-11-29 08:47 - 000616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-29 08:47 - 2013-11-29 08:47 - 000247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-29 08:47 - 2013-11-29 08:47 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-29 08:47 - 2013-11-29 08:47 - 000012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-13 23:02 - 2013-10-12 03:30 - 000830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 23:02 - 2013-10-12 03:29 - 000859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 23:02 - 2013-10-12 03:29 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 23:02 - 2013-10-12 03:03 - 000656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 23:02 - 2013-10-12 03:01 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 23:02 - 2013-10-04 03:28 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 23:02 - 2013-10-04 03:25 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 23:02 - 2013-10-04 02:58 - 000152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 23:02 - 2013-10-04 02:56 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-10-10 20:32 - 2013-07-12 11:41 - 000185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-10 20:32 - 2013-07-12 11:41 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-10 20:32 - 2013-07-12 11:40 - 000109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-10 20:32 - 2013-07-03 05:40 - 000042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-10 20:32 - 2013-07-03 05:05 - 000076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-10 20:32 - 2013-07-03 05:05 - 000032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-10 20:32 - 2013-06-25 23:55 - 000785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-05 02:38 - 2013-10-05 02:38 - 004449952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120u.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 004424344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000970912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000455328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000339616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcamp120.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000247984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vccorlib120.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000119456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcomp120.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000083104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm120u.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000083104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm120.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000074920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120fra.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000074920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120deu.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000073896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120esn.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000072872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120ita.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000070824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120rus.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000065192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120enu.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000053928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120jpn.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000053416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120kor.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000046248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120cht.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000046248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc120chs.dll 2013-09-25 19:14 - 2013-09-25 19:14 - 097858179 _____ C:\Windows\SysWOW64\䌔崢E 2013-09-24 12:47 - 2013-09-24 12:47 - 097531747 _____ C:\Windows\SysWOW64\稪Á 2013-09-12 18:23 - 2015-02-04 09:18 - 000000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2013-09-12 18:16 - 2013-09-12 18:16 - 000002145 _____ C:\Users\Public\Desktop\HP Support Assistant.lnk 2013-09-12 18:16 - 2013-09-12 18:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support 2013-09-12 18:12 - 2016-09-14 15:54 - 000000000 ____D C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF} 2013-09-12 17:12 - 2013-08-05 03:25 - 000155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-12 17:12 - 2013-07-26 03:24 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-12 17:12 - 2013-07-26 02:55 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-08-19 09:04 - 2013-08-19 09:04 - 000000000 ____D C:\Users\Rudi\AppData\Local\{CE0EB4D7-D0BE-42DD-AABA-E45C966FA1D1} 2013-07-28 10:19 - 2013-07-28 10:19 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Visan 2013-07-27 15:31 - 2013-07-27 15:31 - 000000000 _____ C:\ProgramData\awifocoq.dat 2013-07-27 15:21 - 2013-07-27 15:21 - 000000162 _____ C:\ProgramData\wavav0bdtzbtb43b.reg 2013-07-27 15:21 - 2013-07-27 15:21 - 000000067 _____ C:\ProgramData\wavav0bdtzbtb43b.bat 2013-07-27 14:55 - 2013-07-27 14:55 - 000000000 ____D C:\Users\Rudi\AppData\Local\{43890D96-840D-45D0-9063-A50DFB3C14E7} 2013-07-27 14:35 - 2013-07-28 10:19 - 000000000 ____D C:\ProgramData\Visan 2013-07-27 14:35 - 2013-07-27 14:35 - 000000000 ____D C:\Users\Rudi\AppData\LocalLow\Hewlett-Packard 2013-07-27 14:34 - 2016-09-14 15:54 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\HpUpdate 2013-07-27 14:32 - 2016-07-14 13:31 - 000000000 ____D C:\Program Files (x86)\HP 2013-07-27 14:32 - 2013-07-27 14:32 - 000000000 ____D C:\ProgramData\HP 2013-07-27 14:30 - 2013-07-27 14:30 - 000000057 _____ C:\ProgramData\Ament.ini 2013-07-27 14:27 - 2013-07-27 14:35 - 000000000 ____D C:\Users\Rudi\AppData\Local\HP 2013-07-21 20:23 - 2013-07-28 10:45 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Samsung 2013-07-21 20:22 - 2013-07-28 10:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers 2013-07-21 20:21 - 2013-07-28 10:45 - 000000000 ____D C:\ProgramData\Samsung 2013-07-21 20:20 - 2011-04-25 12:24 - 000034304 _____ () C:\Windows\system32\ssj1mlm.dll 2013-07-21 20:20 - 2011-02-09 11:17 - 000151552 _____ (SS) C:\Windows\system32\ssj1mci.exe 2013-07-21 20:20 - 2011-02-09 11:17 - 000089600 _____ (SS) C:\Windows\system32\ssj1mci.dll 2013-07-21 20:20 - 2011-02-09 11:17 - 000000359 _____ C:\Windows\system32\ssj1mlm.smt 2013-07-18 10:18 - 2015-09-23 11:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\So Many 2013-07-18 09:27 - 2017-06-14 08:37 - 000000000 ____D C:\Windows\system32\MRT 2013-07-01 18:17 - 2013-07-01 18:18 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Nikon 2013-07-01 18:11 - 2014-11-18 07:25 - 000000000 ____H C:\ProgramData\PKP_DLdw.DAT 2013-07-01 18:11 - 2014-11-18 07:25 - 000000000 _____ C:\Users\Rudi\AppData\Roaming\Image Manipulation 2013-07-01 18:09 - 2014-11-18 07:15 - 000000000 ____D C:\Program Files (x86)\Nikon 2013-07-01 18:08 - 2014-11-18 07:15 - 000000000 ____H C:\ProgramData\PKP_DLdu.DAT 2013-07-01 18:08 - 2014-11-18 07:15 - 000000000 _____ C:\Users\Rudi\AppData\Roaming\Icons 2013-07-01 18:08 - 2013-07-01 18:11 - 000000000 ____D C:\ProgramData\Ultima_T15 2013-07-01 18:08 - 2013-07-01 18:11 - 000000000 ____D C:\ProgramData\EnterNHelp 2013-07-01 18:03 - 2013-07-01 18:03 - 000003032 _____ C:\Windows\System32\Tasks\{47336EC5-94B1-4769-AFED-39EDEF2A6709} 2013-06-25 18:45 - 2017-09-16 18:41 - 000004366 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-06-25 18:45 - 2017-09-16 18:40 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-25 18:45 - 2017-09-16 18:40 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-25 17:24 - 2013-06-25 17:24 - 000000000 ____D C:\ProgramData\PDFC 2013-06-21 07:28 - 2013-06-21 07:29 - 000000004 _____ C:\Users\Rudi\AppData\Roaming\skype.ini 2013-06-17 06:47 - 2013-06-17 06:47 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-06-12 19:46 - 2013-04-26 00:30 - 001505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-12 19:46 - 2013-03-31 23:52 - 001887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-06-12 12:59 - 2013-05-10 06:49 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-06-12 12:59 - 2013-05-10 04:20 - 000024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-12 12:52 - 2013-05-13 06:50 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-06-12 12:52 - 2013-05-13 04:43 - 001192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-06-12 12:52 - 2013-05-13 04:08 - 000903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 12:52 - 2013-05-13 04:08 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-05-17 07:35 - 2013-03-19 06:53 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-05-17 07:34 - 2013-04-01 07:03 - 000078680 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_AuthenticAMD.dll 2013-05-05 21:51 - 2013-05-05 21:51 - 000000000 ____D C:\Program Files (x86)\QuickTime 2013-05-02 10:36 - 2017-02-25 12:56 - 000078600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-05-01 23:41 - 2015-09-08 07:08 - 000000000 ____D C:\Users\Rudi\AppData\Local\Adobe 2013-05-01 23:41 - 2013-05-01 23:41 - 000000000 ____D C:\Users\Rudi\AppData\LocalLow\Adobe 2013-04-10 14:53 - 2013-01-24 07:01 - 000223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-03-28 11:43 - 2017-02-25 12:56 - 000035328 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-03-28 11:43 - 2011-01-01 03:58 - 000194912 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-03-28 11:43 - 2011-01-01 03:58 - 000151128 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-03-26 12:39 - 2013-02-12 05:12 - 000019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-02-28 06:12 - 2013-01-13 22:17 - 000009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 22:17 - 000002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 22:16 - 000010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 22:12 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-02-28 06:12 - 2013-01-13 22:11 - 000005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-02-28 06:12 - 2013-01-13 22:11 - 000005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 22:11 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 22:11 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 22:11 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:35 - 000010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:35 - 000009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:35 - 000002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:31 - 000005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:31 - 000005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:31 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:31 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:31 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-02-28 06:12 - 2013-01-13 21:20 - 000293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-02-28 06:12 - 2013-01-13 21:09 - 000249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-02-28 06:12 - 2013-01-13 21:08 - 000220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-02-28 06:12 - 2013-01-13 20:53 - 000207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-02-28 06:12 - 2013-01-13 20:49 - 000363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-02-28 06:12 - 2013-01-13 20:48 - 000161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-02-28 06:12 - 2013-01-13 20:46 - 001080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-02-28 06:12 - 2013-01-13 20:38 - 000333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-02-28 06:12 - 2013-01-13 20:38 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-02-28 06:12 - 2013-01-13 20:25 - 000245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-02-28 06:12 - 2013-01-13 20:20 - 001238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-02-28 06:12 - 2013-01-13 20:20 - 000194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-02-28 06:12 - 2013-01-13 19:34 - 000364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-02-28 06:12 - 2013-01-13 19:09 - 000522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-02-28 06:12 - 2013-01-13 18:26 - 001158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-02-28 06:12 - 2013-01-13 18:05 - 001682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-01-29 01:03 - 2011-01-01 13:49 - 000000000 ____D C:\Windows\Minidump 2013-01-19 15:17 - 2015-04-01 08:39 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Avira 2013-01-19 15:10 - 2016-07-30 08:37 - 000000000 ____D C:\ProgramData\Avira 2013-01-19 15:10 - 2016-07-30 08:37 - 000000000 ____D C:\Program Files (x86)\Avira 2013-01-19 14:30 - 2015-01-29 10:55 - 000000000 ____D C:\found.000 2013-01-08 22:50 - 2012-12-07 14:20 - 000441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2013-01-08 22:50 - 2012-12-07 14:15 - 002746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2013-01-08 22:50 - 2012-12-07 13:26 - 000308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2013-01-08 22:50 - 2012-12-07 13:20 - 002576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2013-01-08 22:50 - 2012-12-07 12:20 - 000045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2013-01-08 22:50 - 2012-12-07 12:20 - 000044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2013-01-08 22:50 - 2012-12-07 12:20 - 000043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2013-01-08 22:50 - 2012-12-07 12:20 - 000030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2013-01-08 22:50 - 2012-12-07 12:20 - 000023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2013-01-08 22:50 - 2012-12-07 12:20 - 000020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2013-01-08 22:50 - 2012-12-07 12:20 - 000020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2013-01-08 22:50 - 2012-12-07 12:19 - 000055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2013-01-08 22:50 - 2012-12-07 12:19 - 000051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2013-01-08 22:50 - 2012-12-07 12:19 - 000046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2013-01-08 22:50 - 2012-12-07 12:19 - 000040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2013-01-08 22:50 - 2012-12-07 12:19 - 000021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2013-01-08 22:50 - 2012-12-07 12:19 - 000020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2013-01-08 22:50 - 2012-12-07 12:19 - 000015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2013-01-08 22:50 - 2012-12-07 11:46 - 000015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2013-01-08 22:46 - 2012-11-23 04:13 - 000068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2012-12-13 09:42 - 2012-12-13 09:55 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\SoftGrid Client 2012-12-13 09:42 - 2012-12-13 09:42 - 000000000 ____D C:\Users\Rudi\AppData\Local\SoftGrid Client 2012-12-13 09:41 - 2017-05-12 15:23 - 001623944 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2012-12-13 09:41 - 2012-12-13 09:41 - 000000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2012-12-13 09:40 - 2012-12-13 09:43 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\TP 2012-12-12 21:04 - 2012-11-02 06:59 - 000478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2012-12-12 21:04 - 2012-11-02 06:11 - 000376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2012-12-04 13:15 - 2017-06-16 12:11 - 000003216 _____ C:\Windows\System32\Tasks\HPCeeScheduleForRUDI-HP$ 2012-12-04 13:15 - 2017-06-16 12:11 - 000000340 _____ C:\Windows\Tasks\HPCeeScheduleForRUDI-HP$.job 2012-11-30 10:26 - 2012-12-04 06:07 - 000000000 ____D C:\Program Files\Google 2012-11-30 10:25 - 2013-06-25 17:55 - 000000000 ____D C:\Program Files (x86)\Google 2012-11-30 10:25 - 2012-12-03 18:42 - 000000000 ____D C:\Users\Rudi\AppData\Local\Google 2012-11-30 10:21 - 2015-09-07 18:09 - 000000000 ____D C:\ProgramData\Adobe 2012-11-15 21:48 - 2012-07-26 05:55 - 000054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2012-11-15 21:48 - 2012-07-26 03:36 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2012-11-15 21:48 - 2012-06-02 15:35 - 000000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2012-11-15 21:31 - 2012-07-26 04:08 - 000744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2012-11-15 21:31 - 2012-07-26 04:08 - 000229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2012-11-15 21:31 - 2012-07-26 04:08 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2012-11-15 21:31 - 2012-07-26 04:08 - 000084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2012-11-15 21:31 - 2012-07-26 04:08 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2012-11-15 21:31 - 2012-07-26 03:26 - 000198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2012-11-15 21:31 - 2012-07-26 03:26 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2012-11-15 21:31 - 2012-06-02 15:57 - 000000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2012-11-15 21:29 - 2012-10-09 19:17 - 000226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2012-11-15 21:29 - 2012-10-09 19:17 - 000055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2012-11-15 21:29 - 2012-10-09 18:40 - 000193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2012-11-15 21:29 - 2012-10-09 18:40 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2012-11-15 21:29 - 2012-10-03 18:44 - 000246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2012-11-15 21:29 - 2012-10-03 18:44 - 000216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2012-11-15 21:29 - 2012-10-03 18:44 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2012-11-15 21:29 - 2012-10-03 18:44 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2012-11-15 21:29 - 2012-10-03 18:42 - 000569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2012-11-15 21:29 - 2012-10-03 17:42 - 000175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2012-11-15 21:29 - 2012-10-03 17:42 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2012-11-15 21:22 - 2012-09-25 23:47 - 000078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll 2012-11-15 21:22 - 2012-09-25 23:46 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2012-11-09 08:36 - 2009-07-14 05:55 - 000001230 _____ C:\Users\Rudi\Desktop\Calculator.lnk 2012-11-06 00:20 - 2012-11-06 00:20 - 000875472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110.dll 2012-11-06 00:20 - 2012-11-06 00:20 - 000535008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110.dll 2012-11-06 00:20 - 2012-11-06 00:20 - 000252400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vccorlib110.dll 2012-10-24 10:42 - 2012-10-24 10:42 - 000000360 _____ C:\Users\Rudi\Desktop\Mahjong.lnk 2012-10-14 11:10 - 2012-10-14 11:10 - 000001118 _____ C:\Users\Public\Desktop\GS Münz-Verwaltung 3D.lnk 2012-10-14 11:10 - 2012-10-14 11:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GS Münz-Verwaltung 3D 2012-10-13 15:14 - 2012-10-13 15:14 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Malwarebytes 2012-10-13 15:14 - 2012-10-13 15:14 - 000000000 ____D C:\ProgramData\Malwarebytes 2012-10-13 12:12 - 2012-10-13 12:12 - 000000000 ____D C:\Users\Rudi\AppData\Local\CrashRpt 2012-10-02 23:42 - 2012-10-02 23:42 - 002873744 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpinkins8811.exe 2012-10-02 23:42 - 2012-10-02 23:42 - 000332176 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpinksts8811LM.dll 2012-10-02 23:42 - 2012-10-02 23:42 - 000270224 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpinkcoi8811.dll 2012-09-26 09:06 - 2012-08-21 22:01 - 000245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2012-09-18 09:52 - 2012-09-18 09:52 - 000000000 ____D C:\Users\Rudi\AppData\Local\{36546064-8B8A-4375-9584-80E5C1944E6B} 2012-09-12 21:40 - 2012-07-04 21:26 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2012-08-16 21:11 - 2012-07-06 21:07 - 000552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2012-08-16 20:49 - 2012-07-04 23:16 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2012-08-16 20:49 - 2012-07-04 23:13 - 000136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2012-08-16 20:49 - 2012-07-04 23:13 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2012-08-16 20:49 - 2012-07-04 22:16 - 000057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2012-08-16 20:49 - 2012-07-04 22:14 - 000041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2012-08-16 20:49 - 2012-02-11 07:36 - 000559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2012-08-16 20:49 - 2012-02-11 07:36 - 000067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2012-08-09 08:51 - 2012-08-09 08:51 - 000000000 ____D C:\Users\Rudi\AppData\Local\{E9FBF3D6-01A1-412B-B30E-2E662DC88F41} 2012-08-09 08:31 - 2012-08-09 08:31 - 000000000 ____D C:\Users\Rudi\AppData\Local\{6EEE6A8A-776F-4EDB-B96B-382F4E8E3D9F} 2012-08-09 08:31 - 2012-08-09 08:31 - 000000000 ____D C:\Users\Rudi\AppData\Local\{434596E4-B537-483B-8F27-A22A4838CC98} 2012-08-09 08:30 - 2016-11-14 16:23 - 000000000 ____D C:\Users\Rudi\AppData\Local\Windows Live 2012-08-09 08:30 - 2012-08-09 08:30 - 000000000 ____D C:\Users\Rudi\AppData\Local\{439C28F6-7641-42B9-9021-3CE1AE13E879} 2012-07-11 08:35 - 2012-07-11 08:35 - 000003532 _____ C:\Windows\System32\Tasks\CreateChoiceProcessTask 2012-07-11 08:16 - 2010-02-23 09:16 - 000294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe 2012-06-24 11:37 - 2012-06-24 11:37 - 000003334 _____ C:\Windows\System32\Tasks\{10A56367-DD8B-4A3F-997E-741937A033D0} 2012-06-24 11:13 - 2012-06-24 11:13 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_silabser_01009.Wdf 2012-06-24 11:06 - 2012-06-24 11:06 - 000000000 ____D C:\Program Files (x86)\Silabs 2012-06-24 11:05 - 2012-06-24 11:05 - 000000000 ____D C:\SiLabs 2012-06-24 11:05 - 2011-10-14 15:13 - 001721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoinstaller01009.dll 2012-06-24 11:05 - 2011-10-14 15:13 - 000071168 _____ (Silicon Laboratories) C:\Windows\system32\Drivers\silabser.sys 2012-06-24 11:05 - 2011-10-14 15:13 - 000027336 _____ (Silicon Laboratories) C:\Windows\system32\Drivers\silabenm.sys 2012-06-12 21:31 - 2012-04-26 06:41 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2012-06-12 21:31 - 2012-04-26 06:34 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2012-05-13 12:11 - 2016-09-14 15:54 - 000000000 __HDC C:\ProgramData\{907549E1-1111-4EA2-9A82-21C7D9BBB851} 2012-05-13 11:43 - 2012-05-13 11:43 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\GS Münz-Verwaltung 3 2012-05-13 11:42 - 2012-05-13 11:42 - 000000000 ____D C:\Users\Rudi\AppData\Local\FileMaker 2012-05-13 11:41 - 2012-10-14 11:10 - 000000000 ____D C:\Program Files (x86)\GS Münz-Verwaltung 3D 2012-05-13 08:56 - 2012-03-17 08:58 - 000075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2012-04-21 14:16 - 2017-09-16 18:39 - 000000000 ____D C:\Windows\system32\Macromed 2012-04-18 20:39 - 2006-03-06 05:36 - 000000440 ____R C:\Windows\system\CmiInst.Ini 2012-04-18 20:39 - 2005-12-07 09:20 - 000258048 ____R (C-Media Corporation) C:\Windows\CmiUSB2Uninstall.exe 2012-04-18 20:39 - 2005-10-19 03:26 - 000004952 ____R C:\Windows\Cmudau.ini 2012-04-18 20:38 - 2012-04-18 20:38 - 000003028 _____ C:\Windows\System32\Tasks\{763FF240-EEDA-4A2C-A2D0-8619FFE41BCB} 2012-04-12 19:48 - 2012-03-01 07:46 - 000023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2012-04-12 19:48 - 2012-03-01 07:28 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2012-04-12 19:48 - 2012-03-01 06:29 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll 2012-04-03 20:25 - 2012-04-03 20:25 - 000000000 ____D C:\Users\Rudi\Recorded TV 2012-04-01 01:32 - 2012-04-01 01:32 - 000000000 ____D C:\Users\Rudi\Documents\ArcSoft ToGo 2012-04-01 01:31 - 2015-10-21 07:28 - 000000000 ____D C:\Program Files (x86)\IR 2012-04-01 01:31 - 2014-05-31 08:06 - 000000000 ____D C:\ProgramData\ArcSoft 2012-04-01 01:31 - 2012-04-01 01:36 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\ArcSoft 2012-04-01 01:31 - 2012-04-01 01:31 - 000000000 ____D C:\Users\Rudi\AppData\Local\ArcSoft 2012-04-01 01:31 - 2006-11-14 11:31 - 000022784 _____ (Arcsoft, Inc.) C:\Windows\SysWOW64\Drivers\afc.sys 2012-04-01 01:16 - 2012-04-01 01:15 - 000073728 _____ (ITE) C:\Windows\SysWOW64\AF15BDAEX.dll 2012-04-01 01:16 - 2012-04-01 01:15 - 000073728 _____ (ITE) C:\Windows\system32\AF15BDAEX.dll 2012-04-01 01:16 - 2011-11-16 05:08 - 000000350 ____R C:\Windows\system32\AF15IRTBL.bin 2012-03-25 20:12 - 2012-03-25 20:12 - 000001250 _____ C:\Users\Rudi\Desktop\On-Screen Keyboard.lnk 2012-03-21 18:36 - 2013-03-13 11:32 - 000001854 _____ C:\Users\Rudi\AppData\Roaming\GhostObjGAFix.xml 2012-03-18 21:03 - 2009-01-14 18:55 - 000092672 _____ (Prolific Technology Inc.) C:\Windows\system32\Drivers\ser2pl64.sys 2012-03-18 21:02 - 2012-03-18 21:02 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\WinRAR 2012-03-18 21:02 - 2012-03-18 21:02 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2012-03-18 21:02 - 2012-03-18 21:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2012-03-18 21:01 - 2012-03-18 21:02 - 000000000 ____D C:\Program Files (x86)\WinRAR 2012-03-18 20:59 - 2012-03-18 20:59 - 000000000 ____D C:\Users\Rudi\AppData\Local\WinZip 2012-03-14 19:40 - 2012-03-13 20:46 - 000363008 _____ (Huawei Technologies Co., Ltd.) C:\Windows\SysWOW64\hwgpssensor.dll 2012-03-14 19:40 - 2012-03-13 20:46 - 000363008 _____ (Huawei Technologies Co., Ltd.) C:\Windows\SysWOW64\Drivers\hwgpssensor.dll 2012-03-13 20:46 - 2017-04-17 11:40 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\ALDITALKVerbindungsassistent 2012-03-13 20:46 - 2017-03-28 11:20 - 000000000 ____D C:\Program Files (x86)\ALDITALKVerbindungsassistent 2012-03-13 20:46 - 2012-03-13 20:46 - 000256000 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbnet.sys 2012-03-13 20:46 - 2012-03-13 20:46 - 000121600 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2012-03-13 20:46 - 2012-03-13 20:46 - 000117248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys 2012-03-13 20:46 - 2012-03-13 20:46 - 000002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\ALDI TALK Verbindungsassistent.lnk 2012-03-13 20:46 - 2012-03-13 20:46 - 000002193 _____ C:\Users\Public\Desktop\ALDI TALK Verbindungsassistent.lnk 2012-03-13 20:46 - 2012-03-13 20:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ALDI TALK Verbindungsassistent 2012-03-13 20:41 - 2012-02-17 07:38 - 001031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2012-03-13 20:41 - 2012-02-17 06:34 - 000826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2012-03-13 20:41 - 2012-02-17 05:57 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2012-02-20 22:05 - 2017-05-02 14:33 - 000000000 ____D C:\Program Files (x86)\Java 2012-02-20 20:39 - 2017-06-14 08:26 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2012-02-19 11:23 - 2016-02-24 18:06 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Skype 2012-02-19 11:20 - 2012-02-19 11:20 - 000944264 _____ (Skype Technologies S.A.) C:\Users\Rudi\Downloads\SkypeSetup.exe 2012-02-18 15:55 - 2015-12-21 10:38 - 000000000 ____D C:\ProgramData\CyberLink 2012-02-18 15:54 - 2012-02-18 15:54 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\CyberLink 2012-02-18 15:54 - 2012-02-18 15:54 - 000000000 ____D C:\Users\Rudi\AppData\Local\CyberLink 2012-02-18 15:54 - 2012-02-18 15:54 - 000000000 ____D C:\Users\Public\CyberLink 2012-02-18 13:46 - 2012-01-04 11:44 - 000509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2012-02-18 13:46 - 2012-01-04 09:58 - 000442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2012-02-18 13:46 - 2011-12-30 07:26 - 000515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl 2012-02-18 13:46 - 2011-12-30 06:27 - 000478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl 2012-02-18 13:46 - 2011-12-16 09:46 - 000634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2012-02-18 13:46 - 2011-12-16 08:52 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll 2012-02-18 12:54 - 2012-03-13 20:46 - 000999936 _____ (DiBcom SA) C:\Windows\SysWOW64\Drivers\mod7700.sys 2012-02-18 12:54 - 2012-03-13 20:46 - 000256000 _____ (Huawei Technologies Co., Ltd.) C:\Windows\SysWOW64\Drivers\ewusbnet.sys 2012-02-18 12:54 - 2012-03-13 20:46 - 000121600 _____ (Huawei Technologies Co., Ltd.) C:\Windows\SysWOW64\Drivers\ewusbmdm.sys 2012-02-18 12:54 - 2012-03-13 20:46 - 000117248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\SysWOW64\Drivers\ew_hwusbdev.sys 2012-02-18 12:54 - 2012-03-13 20:46 - 000032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\SysWOW64\Drivers\ewdcsc.sys 2012-02-18 12:54 - 2012-03-13 20:46 - 000013952 _____ (Huawei Technologies Co., Ltd.) C:\Windows\SysWOW64\Drivers\ew_usbenumfilter.sys 2012-02-18 12:09 - 2012-02-18 12:09 - 000000000 ____D C:\Users\Rudi\AppData\Local\{C8E02B93-1613-47BD-965E-D0972D4506DB} 2012-02-18 12:03 - 2012-02-18 12:03 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2012-02-18 11:50 - 2016-09-23 09:24 - 000003704 _____ C:\Windows\System32\Tasks\Registration 2011-11-06 11:40 - 2011-08-17 06:26 - 000613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2011-11-06 11:40 - 2011-08-17 06:25 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2011-11-06 11:40 - 2011-08-17 05:24 - 000465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll 2011-11-06 11:40 - 2011-08-17 05:19 - 000075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax 2011-11-06 11:38 - 2011-08-27 06:37 - 000331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2011-11-06 11:38 - 2011-08-27 05:26 - 000233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll 2011-10-07 13:45 - 2011-10-07 13:45 - 000000136 _____ C:\Users\Rudi\Desktop\Solitär - Verknüpfung.lnk 2011-10-06 07:40 - 2011-10-06 07:40 - 000000000 ____D C:\Users\Rudi\AppData\Local\{672294EC-6FEB-4A93-97C1-C103D9603420} 2011-10-04 23:23 - 2016-06-17 11:38 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\dvdcss 2011-10-04 22:55 - 2011-10-04 22:55 - 000000000 ____D C:\Users\Rudi\AppData\Local\{8750A028-5F5C-4847-939C-5913EBCF3E99} 2011-10-04 22:55 - 2011-10-04 22:55 - 000000000 ____D C:\Users\Rudi\AppData\Local\{0438DC80-9E09-4119-BC4D-6C86E5586651} 2011-10-04 14:05 - 2017-02-25 18:34 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\vlc 2011-10-04 14:04 - 2015-10-01 06:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2011-10-04 14:04 - 2011-10-04 14:04 - 000001066 _____ C:\Users\Public\Desktop\VLC media player.lnk 2011-10-04 14:04 - 2011-10-04 14:04 - 000000000 ____D C:\Program Files (x86)\VideoLAN 2011-09-28 14:54 - 2011-09-28 14:54 - 000002743 _____ C:\Users\Rudi\Desktop\Microsoft AutoRoute 2007.lnk 2011-09-28 14:22 - 2011-09-28 14:22 - 000000000 ____D C:\Program Files (x86)\ScanSoft 2011-09-28 14:19 - 2011-09-28 14:19 - 000002743 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft AutoRoute 2007.lnk 2011-09-28 14:16 - 2011-09-28 14:17 - 000000000 ____D C:\Program Files (x86)\Microsoft AutoRoute 2007 2011-09-28 13:46 - 2011-09-28 13:46 - 000000000 ____D C:\Users\Rudi\AppData\Local\Apps\2.0 2011-09-28 13:22 - 2011-09-28 13:22 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Mozilla 2011-09-28 13:22 - 2011-09-28 13:22 - 000000000 ____D C:\Users\Rudi\AppData\Local\Mozilla 2011-09-28 13:02 - 2011-04-28 04:54 - 000080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS 2011-09-28 13:02 - 2011-03-11 07:41 - 000410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys 2011-09-28 13:02 - 2011-03-11 07:41 - 000166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys 2011-09-28 13:02 - 2011-03-11 07:41 - 000148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys 2011-09-28 13:02 - 2011-03-11 07:41 - 000107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys 2011-09-28 13:02 - 2011-03-11 07:41 - 000027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys 2011-09-28 13:02 - 2011-03-11 07:33 - 002565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2011-09-28 13:02 - 2011-03-11 07:30 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe 2011-09-28 13:02 - 2011-03-11 06:33 - 001699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2011-09-28 13:02 - 2011-03-11 06:31 - 000074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe 2011-09-27 18:56 - 2011-09-27 18:56 - 000025616 _____ (franson.biz) C:\Windows\system32\Drivers\bizVSerialNT.sys 2011-09-27 18:54 - 2011-09-27 18:54 - 000000000 ____D C:\Windows\Downloaded Installations 2011-09-27 18:21 - 2012-04-17 07:29 - 000002767 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft AutoRoute 2006.lnk 2011-09-27 17:59 - 2012-04-17 07:18 - 000000000 ____D C:\Program Files (x86)\Microsoft AutoRoute 2011-09-27 16:11 - 2011-06-16 06:49 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll 2011-09-27 16:11 - 2011-06-16 05:33 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll 2011-09-27 16:11 - 2011-06-15 11:02 - 000212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll 2011-09-27 16:11 - 2011-06-15 11:02 - 000163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2011-09-27 16:11 - 2011-06-15 11:02 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll 2011-09-27 16:11 - 2011-06-15 11:02 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll 2011-09-27 16:11 - 2011-06-15 09:55 - 000319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll 2011-09-27 16:11 - 2011-06-15 09:55 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll 2011-09-27 16:11 - 2011-06-15 09:55 - 000122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll 2011-09-27 16:11 - 2011-06-15 09:55 - 000086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll 2011-09-27 16:11 - 2011-06-15 09:55 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll 2011-09-27 16:11 - 2011-03-11 07:34 - 001395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2011-09-27 16:11 - 2011-03-11 07:34 - 001359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2011-09-27 16:11 - 2011-03-11 06:33 - 001164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2011-09-27 16:11 - 2011-03-11 06:33 - 001137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2011-09-27 16:11 - 2011-03-03 07:24 - 000357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2011-09-27 16:11 - 2011-03-03 07:24 - 000183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2011-09-27 16:11 - 2011-03-03 07:21 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2011-09-27 16:11 - 2011-03-03 06:38 - 000270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2011-09-27 16:11 - 2011-03-03 06:36 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2011-09-27 16:11 - 2011-02-05 18:10 - 000020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2011-09-27 16:11 - 2011-02-05 18:10 - 000019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2011-09-27 16:11 - 2011-02-05 18:10 - 000017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2011-09-27 16:10 - 2011-05-24 12:42 - 000404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2011-09-27 16:10 - 2011-05-24 11:40 - 000064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll 2011-09-27 16:10 - 2011-05-24 11:40 - 000044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll 2011-09-27 16:10 - 2011-05-24 11:39 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll 2011-09-27 16:10 - 2011-05-24 11:37 - 000252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe 2011-09-27 16:09 - 2011-02-18 11:51 - 000031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe 2011-09-27 16:09 - 2011-02-18 06:39 - 000031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe 2011-09-27 16:09 - 2011-02-12 12:34 - 000267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2011-09-26 21:23 - 2015-09-08 07:09 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Adobe 2011-09-26 21:23 - 2011-09-26 21:23 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Macromedia 2011-09-26 20:45 - 2011-09-26 20:45 - 000000000 ____D C:\Users\Rudi\AppData\Local\{5DD0F9E8-A83D-419F-B1B7-2F45C04E58C7} 2011-09-26 20:40 - 2011-09-26 20:40 - 000000000 ____D C:\Users\Rudi\AppData\Local\{034FDFE8-27D7-4943-9B21-B98B9CB146FB} 2011-09-26 19:18 - 2012-04-04 13:29 - 000000000 ____D C:\Users\Rudi\AppData\Local\Microsoft Games 2011-09-26 18:18 - 2011-09-26 18:18 - 000000000 ____D C:\Users\Rudi\AppData\LocalLow\Sun 2011-09-26 17:30 - 2011-01-01 07:00 - 000000000 ____D C:\Users\Rudi\AppData\Local\ElevatedDiagnostics 2011-09-26 15:09 - 1817-09-17 11:27 - 000000000 ____D C:\Users\Rudi\AppData\Local\CrashDumps 2011-09-26 14:51 - 2011-09-26 14:51 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\ATI 2011-09-26 14:51 - 2011-09-26 14:51 - 000000000 ____D C:\Users\Rudi\AppData\Local\ATI 2011-09-26 14:51 - 2011-09-26 14:51 - 000000000 ____D C:\Users\Rudi\AppData\Local\AMD 2011-09-26 14:50 - 2013-06-25 13:02 - 000000000 ____D C:\Users\Rudi\AppData\Local\PDFC 2011-09-26 14:50 - 2011-09-26 14:50 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Synaptics 2011-09-26 14:50 - 2011-09-26 14:50 - 000000000 ____D C:\Users\Rudi\AppData\Local\BMExplorer 2011-09-26 14:49 - 2017-02-02 10:45 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\hpqlog 2011-09-26 14:49 - 2013-11-29 09:41 - 000001421 _____ C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2011-09-26 14:48 - 2011-09-26 14:48 - 000000000 ____D C:\Users\Rudi\AppData\Local\RemEngine 2011-09-26 14:47 - 2015-09-23 10:59 - 000059544 _____ C:\Users\Rudi\AppData\Local\GDIPFONTCACHEV1.DAT 2011-09-26 14:42 - 2016-04-20 16:03 - 000000000 ____D C:\Users\Rudi\AppData\Local\Hewlett-Packard 2011-09-26 14:42 - 2013-09-12 18:01 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Hewlett-Packard 2011-09-26 14:42 - 2011-09-26 14:42 - 000000000 ____D C:\Users\Rudi\AppData\Local\Hewlett-Packard_Company 2011-09-26 14:42 - 2011-05-10 08:49 - 000002353 _____ C:\Users\Default\Desktop\eBay.lnk 2011-09-26 14:42 - 2011-05-10 08:49 - 000002353 _____ C:\Users\Default User\Desktop\eBay.lnk 2011-09-26 14:40 - 2017-05-13 11:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2011-09-26 14:40 - 2017-05-13 11:22 - 000000000 ____D C:\Program Files (x86)\WinZip 2011-09-26 14:40 - 2013-07-27 15:09 - 000000000 ____D C:\Users\Rudi\AppData\Local\VirtualStore 2011-09-26 14:40 - 2011-09-26 14:40 - 000000000 ____D C:\ProgramData\WinZip 2011-09-26 14:39 - 2011-09-26 14:39 - 000000020 ___SH C:\Users\Rudi\ntuser.ini 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Vorlagen 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Startmenü 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Netzwerkumgebung 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Lokale Einstellungen 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Eigene Dateien 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Druckumgebung 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Documents\Eigene Videos 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Documents\Eigene Musik 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Documents\Eigene Bilder 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\AppData\Local\Verlauf 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\AppData\Local\Anwendungsdaten 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Rudi\Anwendungsdaten 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Videos 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Musik 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Public\Documents\Eigene Bilder 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Vorlagen 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Startmenü 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Netzwerkumgebung 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Lokale Einstellungen 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Eigene Dateien 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Druckumgebung 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Videos 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Musik 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Documents\Eigene Bilder 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default\Anwendungsdaten 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Videos 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Musik 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Programme 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\ProgramData\Vorlagen 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\ProgramData\Startmenü 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\ProgramData\Favoriten 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\ProgramData\Dokumente 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\ProgramData\Anwendungsdaten 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Program Files\Gemeinsame Dateien 2011-09-26 14:39 - 2011-09-26 14:39 - 000000000 _SHDL C:\Dokumente und Einstellungen 2011-09-26 14:39 - 2011-06-09 01:33 - 000000000 ____D C:\Users\Rudi\AppData\Roaming\Media Center Programs 2011-09-26 14:39 - 2011-01-01 03:51 - 000000000 ____D C:\Users\Rudi 2011-06-11 00:58 - 2011-06-11 00:58 - 004422992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100u.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 004397384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000773968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000421200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000138056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl100.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000081744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm100u.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000081744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm100.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000064336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100fra.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000064336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100deu.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000063824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100esn.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000062288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100ita.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000060752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100rus.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000055120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100enu.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000051024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcomp100.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000043856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100jpn.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000043344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100kor.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000036176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100cht.dll 2011-06-11 00:58 - 2011-06-11 00:58 - 000036176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100chs.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 005601616 _____ (Microsoft Corporation) C:\Windows\system32\mfc100u.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 005574984 _____ (Microsoft Corporation) C:\Windows\system32\mfc100.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000829264 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000608080 _____ (Microsoft Corporation) C:\Windows\system32\msvcp100.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000158536 _____ (Microsoft Corporation) C:\Windows\system32\atl100.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000093008 _____ (Microsoft Corporation) C:\Windows\system32\mfcm100u.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000093008 _____ (Microsoft Corporation) C:\Windows\system32\mfcm100.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000064336 _____ (Microsoft Corporation) C:\Windows\system32\mfc100fra.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000064336 _____ (Microsoft Corporation) C:\Windows\system32\mfc100deu.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000063824 _____ (Microsoft Corporation) C:\Windows\system32\mfc100esn.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000062288 _____ (Microsoft Corporation) C:\Windows\system32\mfc100ita.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000060752 _____ (Microsoft Corporation) C:\Windows\system32\mfc100rus.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000057168 _____ (Microsoft Corporation) C:\Windows\system32\vcomp100.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000055120 _____ (Microsoft Corporation) C:\Windows\system32\mfc100enu.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000043856 _____ (Microsoft Corporation) C:\Windows\system32\mfc100jpn.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000043344 _____ (Microsoft Corporation) C:\Windows\system32\mfc100kor.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000036176 _____ (Microsoft Corporation) C:\Windows\system32\mfc100cht.dll 2011-06-11 00:15 - 2011-06-11 00:15 - 000036176 _____ (Microsoft Corporation) C:\Windows\system32\mfc100chs.dll 2011-06-09 01:34 - 2009-06-10 21:30 - 000048265 _____ C:\Windows\HomePremium.xml 2011-06-09 01:33 - 2012-11-26 19:35 - 000000000 ___RD C:\Users\Public\Recorded TV 2011-06-09 01:33 - 2011-06-09 01:33 - 000000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs 2011-06-09 01:33 - 2011-06-09 01:33 - 000000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs 2011-06-08 16:23 - 2011-06-08 16:23 - 000000000 ____D C:\ProgramData\ATI 2011-06-08 16:09 - 2011-09-28 12:57 - 000000000 ____D C:\ProgramData\Norton 2011-06-08 16:08 - 2011-06-08 16:08 - 000000000 ____D C:\ProgramData\NortonInstaller 2011-06-08 16:07 - 2011-06-08 16:07 - 000003148 _____ C:\Windows\System32\Tasks\MirageAgent 2011-06-08 16:07 - 2011-06-08 16:07 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam 2011-06-08 16:05 - 2011-06-08 16:05 - 000000000 ____D C:\Program Files (x86)\CyberLink 2011-06-08 16:03 - 2017-02-25 15:38 - 000000000 ____D C:\ProgramData\Temp 2011-06-08 16:03 - 2011-06-08 16:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Energy Star 2011-06-08 15:59 - 2011-06-08 15:59 - 000000000 _____ C:\Windows\ativpsrm.bin 2011-06-08 15:55 - 2015-09-23 11:19 - 000000000 ____D C:\Windows\Hewlett-Packard 2011-06-08 15:54 - 2011-06-08 15:54 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_btath_hcrp_01009.Wdf 2011-06-08 15:50 - 2011-06-08 15:51 - 000000000 ____D C:\Program Files (x86)\Bluetooth Suite 2011-06-08 15:48 - 2011-06-08 15:48 - 000000000 ____D C:\Windows\system32\nn-NO 2011-06-08 15:48 - 2011-06-08 15:48 - 000000000 ____D C:\Windows\Options 2011-06-08 15:48 - 2011-06-08 15:48 - 000000000 ____D C:\Program Files (x86)\Cisco 2011-06-08 15:48 - 2011-06-08 15:48 - 000000000 ____D C:\Program Files (x86)\Atheros 2011-06-08 15:48 - 2011-02-16 12:55 - 000443040 _____ (Atheros) C:\Windows\system32\athihvs.dll 2011-06-08 15:48 - 2011-02-16 12:55 - 000063648 _____ (Atheros) C:\Windows\system32\athihvui.dll 2011-06-08 15:48 - 2011-02-10 14:50 - 002717696 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2011-06-08 15:47 - 2015-09-23 12:02 - 000000000 ____D C:\ProgramData\Atheros 2011-06-08 15:47 - 2011-06-08 15:47 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2011-06-08 15:47 - 2011-06-08 15:47 - 000000000 ____D C:\Program Files\Synaptics 2011-06-08 15:46 - 2011-06-08 15:46 - 000000000 ____D C:\Windows\SysWOW64\sda 2011-06-08 15:46 - 2011-02-15 20:37 - 009888360 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsPStorIcon.dll 2011-06-08 15:46 - 2011-02-15 20:37 - 000335464 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsPStor.sys 2011-06-08 15:45 - 2011-06-08 15:45 - 000000000 ____D C:\Windows\SysWOW64\RTCOM 2011-06-08 15:45 - 2011-06-08 15:45 - 000000000 ____D C:\Program Files\Realtek 2011-06-08 15:45 - 2011-03-05 08:16 - 000436840 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2011-06-08 15:45 - 2011-03-05 08:16 - 000107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2011-06-08 15:45 - 2011-03-05 08:16 - 000074272 _____ C:\Windows\system32\RtNicProp64.dll 2011-06-08 15:44 - 2011-06-08 15:46 - 000000000 ____D C:\Program Files (x86)\Realtek 2011-06-08 15:44 - 2011-06-08 15:45 - 000000000 ___HD C:\Program Files (x86)\Temp 2011-06-08 15:44 - 2011-06-08 15:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center 2011-06-08 15:44 - 2011-06-08 15:44 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies 2011-06-08 15:44 - 2011-01-12 05:49 - 002358376 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2011-06-08 15:44 - 2011-01-12 02:56 - 002709224 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2011-06-08 15:44 - 2011-01-12 00:26 - 002838120 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2011-06-08 15:44 - 2011-01-05 04:25 - 000083560 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInst64.dll 2011-06-08 15:44 - 2010-11-29 13:50 - 000044672 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\usbfilter.sys 2011-06-08 15:44 - 2010-11-24 03:45 - 001247848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2011-06-08 15:44 - 2010-11-22 20:39 - 000626792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2011-06-08 15:44 - 2010-11-08 16:31 - 000375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2011-06-08 15:44 - 2010-11-08 16:31 - 000310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2011-06-08 15:44 - 2010-11-08 16:31 - 000310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2011-06-08 15:44 - 2010-11-08 16:31 - 000204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2011-06-08 15:44 - 2010-11-08 16:31 - 000101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2011-06-08 15:44 - 2010-11-08 16:31 - 000078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2011-06-08 15:44 - 2010-11-04 03:31 - 001146984 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2011-06-08 15:44 - 2010-11-04 03:31 - 000332392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2011-06-08 15:44 - 2010-11-04 03:30 - 000149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2011-06-08 15:44 - 2010-10-28 19:46 - 001251944 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2011-06-08 15:44 - 2010-07-23 01:37 - 000200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2011-06-08 15:44 - 2010-01-11 20:36 - 000000176 _____ C:\Windows\system32\Drivers\RTHDAEQ0.dat 2011-06-08 15:44 - 2010-01-07 23:37 - 000000712 _____ C:\Windows\system32\Drivers\RTEQEX0.dat 2011-06-08 15:44 - 2009-11-24 18:55 - 000518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2011-06-08 15:44 - 2009-11-24 18:55 - 000155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2011-06-08 15:44 - 2009-11-18 03:12 - 000108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2011-06-08 15:43 - 2011-06-08 15:43 - 000000000 ____D C:\ProgramData\AMD 2011-06-08 15:43 - 2011-06-08 15:43 - 000000000 ____D C:\Program Files\ATI Technologies 2011-06-08 15:43 - 2010-02-18 08:18 - 000046136 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdiox64.sys 2011-06-08 15:42 - 2015-09-23 12:02 - 000000000 ____D C:\Program Files (x86)\ATI Technologies 2011-06-08 15:42 - 2011-06-08 15:42 - 000000000 ____D C:\Program Files\ATI 2011-06-08 15:41 - 2011-06-08 15:41 - 000000000 __RSH C:\Windows\SysWOW64\Drivers\103C_HP_bNB_635 Notebook PC_Y5336AN_0U_Q5CB1220S82_E648535-044_4A_I3577_SHP_V24.22_BF.24_T110421_W73-1_L407_M1643_J250_7AMD_8F10_91.50_#110608_N_(LH417EA#ABD)_XMOBILE_CN10_Z_20585100000204C10002620100_G10029803.MRK 2011-06-08 15:41 - 2011-06-08 15:41 - 000000000 __RSH C:\Windows\system32\Drivers\103C_HP_bNB_635 Notebook PC_Y5336AN_0U_Q5CB1220S82_E648535-044_4A_I3577_SHP_V24.22_BF.24_T110421_W73-1_L407_M1643_J250_7AMD_8F10_91.50_#110608_N_(LH417EA#ABD)_XMOBILE_CN10_Z_20585100000204C10002620100_G10029803.MRK 2011-06-08 15:39 - 2011-06-08 15:39 - 000001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2011-06-08 15:38 - 2011-06-08 15:38 - 000001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2011-05-10 18:18 - 2011-05-10 18:18 - 000180736 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll 2011-05-10 18:18 - 2011-05-10 18:18 - 000148992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll 2011-05-10 18:18 - 2011-05-10 18:18 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTAM.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAL.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINDEV.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBEN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTAM.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINORI.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINMAR.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINMAL.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINKAN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINHIN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINDEV.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBEN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTEL.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINPUN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINORI.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAR.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINKAN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINHIN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINGUJ.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINEN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBE2.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBE1.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINASA.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTEL.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINPUN.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINGUJ.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBE2.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBE1.DLL 2011-05-10 18:18 - 2011-05-10 18:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINASA.DLL 2011-05-10 18:16 - 2011-05-10 18:16 - 001118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll 2011-05-10 18:16 - 2011-05-10 18:16 - 000850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll 2011-05-10 18:16 - 2011-05-10 18:16 - 000259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax 2011-05-10 18:16 - 2011-05-10 18:16 - 000199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax 2011-05-10 18:14 - 2011-05-10 18:14 - 000295922 _____ C:\Windows\system32\perfi007.dat 2011-05-10 18:14 - 2011-05-10 18:14 - 000038104 _____ C:\Windows\system32\perfd007.dat 2011-05-10 18:14 - 2011-05-10 18:14 - 000000000 ____D C:\Windows\SysWOW64\XPSViewer 2011-05-10 18:14 - 2011-05-10 18:14 - 000000000 ____D C:\Windows\SysWOW64\de 2011-05-10 18:14 - 2011-05-10 18:14 - 000000000 ____D C:\Windows\SysWOW64\0407 2011-05-10 18:14 - 2011-05-10 18:14 - 000000000 ____D C:\Windows\system32\de 2011-05-10 18:14 - 2011-05-10 18:14 - 000000000 ____D C:\Windows\system32\0407 2011-05-10 18:14 - 2011-01-01 04:08 - 000714474 _____ C:\Windows\system32\perfh007.dat 2011-05-10 18:14 - 2011-01-01 04:08 - 000154526 _____ C:\Windows\system32\perfc007.dat 2011-05-10 18:08 - 2011-05-10 18:08 - 000000012 _____ C:\Windows\CSUP.txt 2011-05-10 08:52 - 2013-09-12 18:01 - 000000000 ____D C:\Windows\System32\Tasks\Hewlett-Packard 2011-05-10 08:50 - 2011-05-10 08:50 - 000521448 _____ (Sun Microsystems, Inc.) C:\Windows\system32\deployJava1.dll 2011-05-10 08:50 - 2011-05-10 08:50 - 000000000 ____D C:\Users\Public\Symantec 2011-05-10 08:50 - 2011-05-10 08:50 - 000000000 ____D C:\ProgramData\Sun 2011-05-10 08:49 - 2011-09-26 14:42 - 000000000 ___RD C:\Program Files\Online Services 2011-05-10 08:48 - 2015-09-23 11:19 - 000000000 ____D C:\Program Files (x86)\Xobni 2011-05-10 08:48 - 2011-05-10 08:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xobni 2011-05-10 08:47 - 2011-05-10 08:47 - 000001374 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk 2011-05-10 08:47 - 2011-05-10 08:47 - 000001305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk 2011-05-10 08:47 - 2011-05-10 08:47 - 000000020 _____ C:\Windows\xø® 2011-05-10 08:47 - 2011-05-10 08:47 - 000000000 ____D C:\Windows\en 2011-05-10 08:47 - 2011-05-10 08:47 - 000000000 ____D C:\Windows\de 2011-05-10 08:47 - 2011-05-10 08:47 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2011-05-10 08:46 - 2011-05-10 08:47 - 000000000 ____D C:\Program Files (x86)\Windows Live 2011-05-10 08:46 - 2009-09-04 16:44 - 000515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2011-05-10 08:46 - 2009-09-04 16:44 - 000069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2011-05-10 08:46 - 2009-09-04 16:29 - 000523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2011-05-10 08:46 - 2009-09-04 16:29 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2011-05-10 08:46 - 2006-11-29 12:06 - 004398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2011-05-10 08:46 - 2006-11-29 12:06 - 003426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2011-05-10 08:45 - 2016-09-14 15:51 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services 2011-05-10 08:45 - 2016-09-14 12:59 - 000000000 ____D C:\ProgramData\Skype 2011-05-10 08:45 - 2013-09-12 18:01 - 000000000 ____D C:\ProgramData\Hewlett-Packard 2011-05-10 08:44 - 2012-12-13 09:56 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2011-05-10 08:43 - 2011-05-10 08:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery Manager 2011-05-10 08:42 - 2017-02-14 14:02 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2011-05-10 08:42 - 2011-05-10 08:42 - 000000514 _____ C:\ProgramData\Microsoft\Windows\Start Menu\HP Virtual Rooms ausprobieren.lnk 2011-05-10 08:36 - 2012-02-26 15:35 - 000000000 ____D C:\ProgramData\WildTangent 2011-05-10 08:36 - 2012-02-26 15:35 - 000000000 ____D C:\Program Files (x86)\HP Games 2011-05-10 08:36 - 2011-09-26 14:42 - 000000000 ___RD C:\Program Files (x86)\Online Services 2011-05-10 08:36 - 2011-05-10 08:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote 2011-05-10 08:36 - 2011-05-10 08:36 - 000000000 ____D C:\Program Files (x86)\Evernote 2011-05-10 08:35 - 2017-09-16 18:39 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2011-05-10 08:35 - 2016-07-14 13:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2011-05-10 08:33 - 2017-02-02 10:46 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard 2011-03-14 07:36 - 2011-03-14 07:36 - 000011576 _____ (Samsung Electronics) C:\Windows\system32\Drivers\SSPORT.SYS 2011-03-14 07:35 - 2011-03-14 07:35 - 000074240 _____ (Samsung Electronics) C:\Windows\system32\ssdevm64.dll 2011-03-14 07:35 - 2011-03-14 07:35 - 000057344 _____ (Samsung Electronics) C:\Windows\SysWOW64\ssdevm.dll 2011-03-14 07:35 - 2011-03-14 07:35 - 000049152 _____ (Samsung Electronics) C:\Windows\SysWOW64\ssusbpn.dll 2011-03-14 07:35 - 2011-03-14 07:35 - 000047104 _____ (Samsung Electronics) C:\Windows\system32\ssusbp64.dll 2011-03-04 23:01 - 2011-03-04 23:01 - 008283136 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2011-03-04 22:31 - 2011-03-04 22:31 - 000058880 _____ (AMD) C:\Windows\system32\coinst.dll 2011-03-04 21:16 - 2011-03-04 21:16 - 006815232 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2011-03-04 21:16 - 2011-03-04 21:16 - 000051200 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2011-03-04 21:16 - 2011-03-04 21:16 - 000046080 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2011-03-04 21:16 - 2011-03-04 21:16 - 000044544 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2011-03-04 21:16 - 2011-03-04 21:16 - 000044032 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2011-03-04 21:15 - 2011-03-04 21:15 - 005441024 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2011-03-04 21:13 - 2011-03-04 21:13 - 022100480 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2011-03-04 20:55 - 2011-03-04 20:55 - 017044480 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2011-03-04 20:54 - 2011-03-04 20:54 - 000596480 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2011-03-04 20:54 - 2011-03-04 20:54 - 000143360 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2011-03-04 20:54 - 2011-03-04 20:54 - 000138760 _____ C:\Windows\system32\atiapfxx.blb 2011-03-04 20:53 - 2011-03-04 20:53 - 000708608 _____ (ATI Technologies Inc. ) C:\Windows\system32\aticfx64.dll 2011-03-04 20:51 - 2011-03-04 20:51 - 000462848 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll 2011-03-04 20:50 - 2011-03-04 20:50 - 000480256 _____ (AMD) C:\Windows\system32\atieclxx.exe 2011-03-04 20:50 - 2011-03-04 20:50 - 000203776 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2011-03-04 20:49 - 2011-03-04 20:49 - 000423424 _____ (ATI Technologies, Inc.) C:\Windows\system32\atipdl64.dll 2011-03-04 20:49 - 2011-03-04 20:49 - 000356352 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\atipdlxx.dll 2011-03-04 20:49 - 2011-03-04 20:49 - 000120320 _____ (AMD) C:\Windows\system32\atitmm64.dll 2011-03-04 20:48 - 2011-03-04 20:48 - 000278528 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\Oemdspif.dll 2011-03-04 20:48 - 2011-03-04 20:48 - 000059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2011-03-04 20:48 - 2011-03-04 20:48 - 000043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2011-03-04 20:48 - 2011-03-04 20:48 - 000016384 _____ (AMD) C:\Windows\system32\atimuixx.dll 2011-03-04 20:45 - 2011-03-04 20:45 - 004101632 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2011-03-04 20:38 - 2011-03-04 20:38 - 004844544 _____ (ATI Technologies Inc. ) C:\Windows\system32\atidxx64.dll 2011-03-04 20:29 - 2011-03-04 20:29 - 004162048 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2011-03-04 20:27 - 2011-03-04 20:27 - 001208320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6v.dll 2011-03-04 20:26 - 2011-03-04 20:26 - 003218944 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2011-03-04 20:24 - 2011-03-04 20:24 - 000675584 _____ C:\Windows\system32\atiumd6a.cap 2011-03-04 20:23 - 2011-03-04 20:23 - 005305856 _____ (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll 2011-03-04 20:19 - 2011-03-04 20:19 - 003461120 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2011-03-04 20:19 - 2011-03-04 20:19 - 000675584 _____ C:\Windows\SysWOW64\atiumdva.cap 2011-03-04 20:17 - 2011-03-04 20:17 - 000353792 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2011-03-04 20:17 - 2011-03-04 20:17 - 000249856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2011-03-04 20:17 - 2011-03-04 20:17 - 000032256 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2011-03-04 20:17 - 2011-03-04 20:17 - 000014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2011-03-04 20:17 - 2011-03-04 20:17 - 000012800 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2011-03-04 20:17 - 2011-03-04 20:17 - 000012800 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2011-03-04 20:16 - 2011-03-04 20:16 - 000295424 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2011-03-04 20:16 - 2011-03-04 20:16 - 000039936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2011-03-04 20:16 - 2011-03-04 20:16 - 000030720 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2011-03-04 20:16 - 2011-03-04 20:16 - 000027648 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2011-03-04 20:15 - 2011-03-04 20:15 - 000053248 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2011-03-04 20:15 - 2011-03-04 20:15 - 000038400 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2011-03-04 20:15 - 2011-03-04 20:15 - 000028672 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2011-03-04 20:08 - 2011-03-04 20:08 - 000053760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2011-03-04 20:08 - 2011-03-04 20:08 - 000053760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2011-03-04 20:07 - 2011-03-04 20:07 - 000052736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2011-03-04 20:07 - 2011-03-04 20:07 - 000052736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2011-03-01 19:17 - 2011-03-01 19:17 - 000115216 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys 2011-02-14 20:38 - 2011-06-08 16:12 - 000000000 ___HD C:\HP 2011-02-10 20:23 - 2015-09-23 12:03 - 000000000 ___HD C:\SYSTEM.SAV 2011-02-10 20:23 - 2013-09-12 18:26 - 000000000 ____D C:\SWSetup 2011-02-09 16:58 - 2011-02-09 16:58 - 000031088 _____ (CyberLink Corporation) C:\Windows\system32\Drivers\clwvd.sys 2011-01-06 19:07 - 2011-01-06 19:07 - 000298144 _____ (Atheros) C:\Windows\system32\Drivers\btath_a2dp.sys 2011-01-06 19:07 - 2011-01-06 19:07 - 000279200 _____ (Atheros) C:\Windows\system32\Drivers\btfilter.sys 2011-01-06 19:07 - 2011-01-06 19:07 - 000201376 _____ (Atheros) C:\Windows\system32\Drivers\btath_hcrp.sys 2011-01-06 19:07 - 2011-01-06 19:07 - 000154272 _____ (Atheros) C:\Windows\system32\Drivers\btath_rcp.sys 2011-01-06 19:07 - 2011-01-06 19:07 - 000055456 _____ (Atheros) C:\Windows\system32\Drivers\btath_lwflt.sys 2011-01-06 19:07 - 2011-01-06 19:07 - 000036000 _____ (Atheros) C:\Windows\system32\Drivers\btath_flt.sys 2011-01-06 19:07 - 2011-01-06 19:07 - 000028832 _____ (Atheros) C:\Windows\system32\Drivers\btath_bus.sys 2011-01-06 18:55 - 2011-06-08 15:51 - 000246804 _____ C:\Windows\system32\Drivers\AtherosBt.bin 2011-01-01 04:53 - 2011-01-01 04:55 - 000019871 _____ C:\Users\Rudi\Documents\FRST.txt 2011-01-01 04:53 - 2011-01-01 04:53 - 002399744 _____ (Farbar) C:\Users\Rudi\Documents\FRST64.exe 2011-01-01 04:53 - 2011-01-01 04:53 - 000000000 ____D C:\FRST 2011-01-01 04:52 - 2011-01-01 04:52 - 002399744 _____ (Farbar) C:\Users\Rudi\Downloads\FRST64.exe.cru1h2e.partial 2010-12-21 01:20 - 2010-12-21 01:20 - 001402416 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2010-12-21 01:20 - 2010-12-21 01:20 - 000216360 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2010-12-21 01:20 - 2010-12-21 01:20 - 000148776 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo4.dll 2010-12-21 01:20 - 2010-12-21 01:20 - 000107816 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCOM.dll 2010-12-21 01:20 - 2010-12-21 01:20 - 000066856 _____ C:\Windows\SysWOW64\SynTPEnhPS.dll 2010-12-21 01:19 - 2010-12-21 01:19 - 000404776 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2010-12-21 01:19 - 2010-12-21 01:19 - 000273704 _____ (Synaptics Incorporated) C:\Windows\system32\SynCtrl.dll 2010-12-21 01:19 - 2010-12-21 01:19 - 000218408 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCtrl.dll 2010-12-21 01:19 - 2010-12-21 01:19 - 000173352 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCOM.dll 2010-12-16 00:33 - 2010-12-16 00:33 - 000002975 _____ C:\Windows\SysWOW64\atipblag.dat 2010-12-16 00:33 - 2010-12-16 00:33 - 000002975 _____ C:\Windows\system32\atipblag.dat 2010-12-03 02:30 - 2015-11-05 14:13 - 000000000 ____D C:\Program Files\Hewlett-Packard ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-06-26 12:38 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache 2017-06-18 09:48 - 2009-07-14 05:45 - 000275320 _____ C:\Windows\system32\FNTCACHE.DAT 2017-06-18 09:45 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz 2017-06-18 09:44 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\migwiz 2017-05-13 10:37 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\PolicyDefinitions 2017-03-17 11:51 - 2009-07-14 06:32 - 000000000 ____D C:\Program Files\DVD Maker 2017-03-11 11:58 - 2009-07-14 06:08 - 000032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-10-30 17:03 - 2009-07-14 04:20 - 000000000 __RHD C:\Users\Public\Libraries 2016-10-26 17:29 - 2010-11-21 04:27 - 000485032 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-10-12 15:33 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\Dism 2016-10-12 15:32 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\Dism 2016-09-23 11:00 - 2009-07-14 06:32 - 000000000 ____D C:\Windows\Downloaded Program Files 2016-04-20 16:09 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\registration 2016-04-20 16:07 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\servicing 2016-04-20 16:03 - 2009-07-14 04:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared 2015-12-22 19:27 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\ModemLogs 2015-12-21 10:38 - 2009-07-14 03:34 - 000000461 _____ C:\Windows\win.ini 2015-09-26 11:35 - 2009-07-14 06:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD 2015-09-23 12:03 - 2007-01-02 02:25 - 000000000 ____D C:\Windows\Panther 2015-09-23 11:19 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\Msdtc 2015-08-24 15:10 - 2009-07-14 04:20 - 000000000 ____D C:\PerfLogs 2015-05-15 07:26 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\AdvancedInstallers 2015-04-20 12:08 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\AppCompat 2015-02-12 07:55 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\tracing 2014-01-12 21:05 - 2010-02-03 09:05 - 000113280 _____ (ITE ) C:\Windows\system32\Drivers\IT9135BDA.sys 2013-09-12 18:20 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\Help 2013-07-11 05:52 - 2009-07-14 06:32 - 000000000 ____D C:\Program Files\Windows Defender 2013-07-11 05:52 - 2009-07-14 06:32 - 000000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-01 18:08 - 2003-03-19 11:05 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ATL71.DLL 2012-05-15 17:08 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system 2012-02-26 15:35 - 2009-07-14 06:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2012-02-21 20:15 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\LiveKernelReports 2012-02-18 14:29 - 2009-07-14 04:20 - 000000000 ____D C:\Program Files\Common Files\System 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\SysWOW64\winrm 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\SysWOW64\WCN 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\SysWOW64\sysprep 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\SysWOW64\slmgr 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\system32\winrm 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\system32\WCN 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\system32\slmgr 2011-10-05 23:49 - 2010-11-21 08:06 - 000000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2011-10-05 23:49 - 2009-07-14 06:32 - 000000000 ____D C:\Program Files\Windows Sidebar 2011-10-05 23:49 - 2009-07-14 06:32 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2011-10-05 23:49 - 2009-07-14 06:32 - 000000000 ____D C:\Program Files (x86)\Windows Sidebar 2011-10-05 23:49 - 2009-07-14 06:32 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\Setup 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\oobe 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\MUI 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\com 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\sysprep 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\Setup 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\oobe 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\MUI 2011-10-05 23:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\com 2011-09-26 14:39 - 2009-07-14 04:20 - 000000000 ____D C:\Program Files\Windows NT 2011-06-09 01:33 - 2009-07-14 06:32 - 000000000 ____D C:\Program Files\Microsoft Games 2011-06-09 01:32 - 2009-07-14 06:32 - 000032768 _____ C:\Windows\system32\config\BCD-Template 2011-05-10 18:14 - 2009-07-14 06:37 - 000000000 ____D C:\Windows\DigitalLocker 2011-05-10 18:14 - 2009-07-14 06:32 - 000000000 ____D C:\Windows\system32\WinBioPlugIns 2011-05-10 18:14 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\IME 2011-05-10 18:07 - 2009-07-14 05:45 - 000000000 ____D C:\Windows\Setup 2011-05-10 08:43 - 2010-11-03 19:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Theft Protection 2011-01-01 04:38 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\NDF 2011-01-01 04:12 - 2009-07-14 05:45 - 000032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2011-01-01 04:12 - 2009-07-14 05:45 - 000032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2011-01-01 04:08 - 2009-07-14 06:13 - 001649664 _____ C:\Windows\system32\PerfStringBackup.INI 2011-01-01 04:08 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf 2011-01-01 04:02 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2012-03-21 18:36 - 2013-03-13 11:32 - 000001854 _____ () C:\Users\Rudi\AppData\Roaming\GhostObjGAFix.xml 2013-07-01 18:08 - 2014-11-18 07:15 - 000000000 _____ () C:\Users\Rudi\AppData\Roaming\Icons 2013-07-01 18:11 - 2014-11-18 07:25 - 000000000 _____ () C:\Users\Rudi\AppData\Roaming\Image Manipulation 2013-06-21 07:28 - 2013-06-21 07:29 - 000000004 _____ () C:\Users\Rudi\AppData\Roaming\skype.ini 2015-10-27 10:35 - 2016-09-11 15:38 - 000007620 _____ () C:\Users\Rudi\AppData\Local\Resmon.ResmonCfg 2013-07-27 14:30 - 2013-07-27 14:30 - 000000057 _____ () C:\ProgramData\Ament.ini 2013-07-27 15:31 - 2013-07-27 15:31 - 000000000 _____ () C:\ProgramData\awifocoq.dat 2013-07-01 18:08 - 2014-11-18 07:15 - 000000000 ____H () C:\ProgramData\PKP_DLdu.DAT 2013-07-01 18:11 - 2014-11-18 07:25 - 000000000 ____H () C:\ProgramData\PKP_DLdw.DAT 2013-07-27 15:21 - 2013-07-27 15:21 - 000000067 _____ () C:\ProgramData\wavav0bdtzbtb43b.bat 2013-07-27 15:21 - 2013-07-27 15:21 - 000000162 _____ () C:\ProgramData\wavav0bdtzbtb43b.reg 2016-06-29 17:59 - 2016-07-21 18:05 - 000000000 _____ () C:\ProgramData\WebEx Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\ProgramData\awifocoq.dat C:\ProgramData\wavav0bdtzbtb43b.bat C:\ProgramData\wavav0bdtzbtb43b.reg C:\Users\Rudi\AppData\Roaming\skype.ini ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-09-16 20:31 ==================== Ende von FRST.txt ============================ |
19.09.2017, 12:55 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Zertifikatfehler, Navigation Bitte Avira deinstallieren. Wir deinstallieren dann am besten auch gleich weiteren unnötigen oder veralteten Krempel. Avira empfehlen wir schon seit Jahren aus mehreren Gründen nicht mehr. Ein Grund ist ne rel. hohe Fehlalarmquote, der zweite Hauptgrund ist, dass die immer noch mit ASK zusammenarbeiten (Avira Suchfunktion geht über ASK). Auch andere Freewareanbieter wie AVG, Avast oder Panda sprangen auf diesen Zug auf; so was ist bei Sicherheitssoftware einfach inakzeptabel. Vgl. Antivirensoftware: Schutz Für Ihre Dateien, Aber Auf Kosten Ihrer Privatsphäre? | Emsisoft Blog Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Gib Bescheid wenn Avira weg ist; wenn wir hier durch sind, kannst du auf einen anderen Virenscanner umsteigen, Infos folgen dann im Abschlussposting. Bitte JETZT nix mehr ohne Absprache installieren!
__________________ Logfiles bitte immer in CODE-Tags posten |
19.09.2017, 14:38 | #9 |
| Zertifikatfehler, Navigation Hallo Cosinus, alle von Dir angegebenen Programme gelöscht. Um nicht den ganzen Datenmüll auf dem Rechner zu haben, gibt es doch auch Bereinigungs-Programme. Was wenn überhaupt würdest Du empfehlen? Gruß Rudi |
19.09.2017, 18:37 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Zertifikatfehler, Navigation Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ Logfiles bitte immer in CODE-Tags posten |
20.09.2017, 09:53 | #11 |
| Zertifikatfehler, Navigation Hallo Cosinus, zweimal den Anti-Rootkit durchlaufen lassen. Beide mal die Meldung: Scan Finished: No malware found! Kein LogFile ''mbar-log'' erstellt. Clean up nicht erforderlich/möglich. Gruß Rudi |
20.09.2017, 10:36 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Zertifikatfehler, Navigation Anleitung richtig lesen, Log wird immer erstellt und soll immer gepostet werden
__________________ Logfiles bitte immer in CODE-Tags posten |
20.09.2017, 11:25 | #13 |
| Zertifikatfehler, NavigationCode:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.9.3.1001 www.malwarebytes.org Database version: main: v2014.11.18.05 rootkit: v2014.11.12.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.18792 Rudi :: RUDI-HP [administrator] 20.09.2017 09:28:17 mbar-log-2017-09-20 (09-28-17).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 327507 Time elapsed: 31 minute(s), 14 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.9.3.1001 www.malwarebytes.org Database version: main: v2017.09.20.02 rootkit: v2017.09.13.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.18792 Rudi :: RUDI-HP [administrator] 20.09.2017 10:05:45 mbar-log-2017-09-20 (10-05-45).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 268505 Time elapsed: 28 minute(s), 18 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
20.09.2017, 14:54 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Zertifikatfehler, Navigation Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! 1. Schritt: adwCleaner v7.0.1.0 Downloade Dir bitte AdwCleaner auf deinen Desktop (Bebilderte Anleitung).
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ Logfiles bitte immer in CODE-Tags posten |
20.09.2017, 18:12 | #15 |
| Zertifikatfehler, NavigationCode:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.4 (07.09.2017) Operating System: Windows 7 Home Premium x64 Ran by Rudi (Administrator) on 20.09.2017 at 17:48:42,44 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 84 Successfully deleted: C:\ProgramData\pc1data (Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{034FDFE8-27D7-4943-9B21-B98B9CB146FB} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{0438DC80-9E09-4119-BC4D-6C86E5586651} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{0F8A34DC-4A8B-44E7-B7EF-631BE12CDEC7} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{12C52CCC-E87E-4A54-B1D3-9123C6416850} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{22CDE6C8-8F62-4C4C-93DB-78C3F393F480} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{23FC134B-1ACD-4878-9CA7-06BBD5D21B51} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{2846B882-0C65-4FED-908E-0FFDBBCA5B5E} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{2919DC2B-E0FD-4065-9012-6615B48C3425} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{2AAB1E71-4CEF-4544-99A0-06284543290B} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{2C54501D-D63A-4FD8-A713-424D6033FA10} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{2F73EFBA-A2D8-4417-814C-65C07F6AC923} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{36546064-8B8A-4375-9584-80E5C1944E6B} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{3803325C-C691-48DD-971B-81FE562ED737} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{42470E0F-B917-4A0A-B3D0-F2EA3CA55F6B} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{42B4BE17-8AF4-4408-B68D-CE3AD7A02C34} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{434596E4-B537-483B-8F27-A22A4838CC98} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{43890D96-840D-45D0-9063-A50DFB3C14E7} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{439C28F6-7641-42B9-9021-3CE1AE13E879} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{450F5E8A-ABCD-48FA-9BE8-1BAE77A879B3} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{4E969717-2096-4749-A6C4-16FFDC3F19A6} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{52BFEE37-115B-45C3-B61A-62741FFC7137} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{5305EBDB-6814-429B-BD30-86C68E56A075} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{579DC522-D085-4998-9457-3CBAEA8E2884} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{585E575F-E7F8-4E09-8560-56151CE4D760} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{5DD0F9E8-A83D-419F-B1B7-2F45C04E58C7} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{606805A1-86B0-41A5-90B9-775F3A690E90} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{672294EC-6FEB-4A93-97C1-C103D9603420} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{6754908E-CC15-4E62-B8CF-E68246AB0A88} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{6921E53E-0898-4B4C-A07F-F29C3607E500} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{6B070201-BFD2-40FD-B7ED-1637ADEA9C4A} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{6EEE6A8A-776F-4EDB-B96B-382F4E8E3D9F} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{7258F52A-C1F9-4672-AF5B-B26BF766D3D8} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{8750A028-5F5C-4847-939C-5913EBCF3E99} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{8EAB2585-0786-464C-9157-88AE6D34796A} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{930B3B9B-A57B-4162-9F1C-12EC7FAAE0BE} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{96B7A543-4D5E-4E26-A89D-73652A79EDFC} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{9796655F-EFD8-4EA2-8080-B5E58C67BB4B} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{B35265CB-0654-4C45-8811-86D20A392B40} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{B791B576-2C0B-4068-BC8C-34DDE1246DA6} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{BE2FB535-7F64-4CE2-B5C5-D24212E6B690} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{C1635CC3-3158-49EE-9574-7D69C2771953} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{C62911B6-2249-4E28-B35B-BD9C097F8B3A} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{C8E02B93-1613-47BD-965E-D0972D4506DB} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{C94D3025-2314-41CE-8989-BE04D9F3B24E} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{CE0EB4D7-D0BE-42DD-AABA-E45C966FA1D1} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{D0995299-7F6E-4F60-9367-F6A6E5581504} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{D146E770-6382-4A5F-97DB-3D8E9770661F} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{D5145900-15AC-4F97-B413-E569BF70F4EB} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{DC9A9976-A577-4324-8F00-6DEF082B0F88} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{E9FBF3D6-01A1-412B-B30E-2E662DC88F41} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{EAAF76D3-E4F0-4A06-A62C-1E453F2E91B3} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{ED68FA0C-EEBE-423A-AA74-CFC26BE7537C} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{EDB1A5A4-295E-4074-9395-4A4B09678660} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\{F4214A6A-18B5-4963-80B2-8680D891BFC9} (Empty Folder) Successfully deleted: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\xrow3d6a.default\searchplugins\myplaycity-search.xml (File) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1ADYHXJJ (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AK7SIVZ8 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AUAHPU41 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BKV3WTOS (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HG6VY5FE (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IP0YQJON (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OL08JUJR (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P1H61NZZ (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PGHS144Q (Temporary Internet Files Folder) Successfully deleted: C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VVNCX002 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1ADYHXJJ (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AK7SIVZ8 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AUAHPU41 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BKV3WTOS (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HG6VY5FE (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IP0YQJON (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OL08JUJR (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P1H61NZZ (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PGHS144Q (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VVNCX002 (Temporary Internet Files Folder) Deleted the following from C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\xrow3d6a.default\prefs.js user_pref(browser.search.selectedEngine, MyPlayCity Search); user_pref(keyword.URL, hxxp://home.myplaycity.com/results.php?category=web&s=); user_pref(browser.startup.homepage, hxxp://home.myplaycity.com/); Registry: 12 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e} (Registry Key) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL (Registry Value) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL (Registry Value) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page (Registry Value) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page (Registry Value) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.09.2017 at 17:55:41,87 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter # AdwCleaner 7.0.2.1 - Logfile created on Wed Sep 20 15:27:44 2017 # Updated on 2017/29/08 by Malwarebytes # Database: 09-18-2017.1 # Running on Windows 7 Home Premium (X64) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** PUP.Optional.Legacy, C:\Users\Default\Desktop\eBay.lnk PUP.Optional.Legacy, C:\Users\Default User\Desktop\eBay.lnk ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cloudfront.net PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d1af033869koo7.cloudfront.net PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d31bfnnwekbny6.cloudfront.net PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\researchnow.com PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\survey-au.researchnow.com PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\survey-d.researchnow.com PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\surveymyopinion.researchnow.com PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ttdetect.staticimgfarm.com PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Start Page_TIMESTAMP [됭뉸ꥢNjs:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Start Page_TIMESTAMP [됭뉸ꥢNjs:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms\browserpolicy [됭뉸ꥢNjs:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms\browserpolicy [됭뉸ꥢNjs:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Start Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Start Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Search Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Search Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Value] - HKCU\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} PUP.Optional.SofTonicAssistant, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amcap.de.softonic.com PUP.Optional.SofTonicAssistant, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amcap.en.softonic.com PUP.Optional.SofTonicAssistant, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries. ************************* ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ########## Code:
ATTFilter # AdwCleaner 7.0.2.1 - Logfile created on Wed Sep 20 15:31:35 2017 # Updated on 2017/29/08 by Malwarebytes # Running on Windows 7 Home Premium (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** No malicious folders deleted. ***** [ Files ] ***** Deleted: C:\Users\Default\Desktop\eBay.lnk Deleted: C:\Users\Default User\Desktop\eBay.lnk ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d1af033869koo7.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d31bfnnwekbny6.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\researchnow.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\survey-au.researchnow.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\survey-d.researchnow.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\surveymyopinion.researchnow.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ttdetect.staticimgfarm.com Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Start Page_TIMESTAMP [됭뉸ꥢNjs:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Start Page_TIMESTAMP [됭뉸ꥢNjs:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms\browserpolicy [됭뉸ꥢNjs:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms\browserpolicy [됭뉸ꥢNjs:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page [https:\\safesearch.avira.com\#web\result?source=art&q=] Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain Deleted: [Value] - HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain Deleted: [Value] - HKU\S-1-5-21-3229228620-787667599-3763351482-1001\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amcap.de.softonic.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amcap.en.softonic.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Prefetch files deleted ::Proxy settings cleared ::IE policies deleted ::Chrome policies deleted ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [5838 B] - [2017/9/20 15:27:44] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ########## Code:
ATTFilter Malwarebytes www.malwarebytes.com -Protokolldetails- Scan-Datum: 01.01.11 Scan-Zeit: 06:34 Protokolldatei: cdbf8de4-1568-11e0-8aee-68a3c4d1c179.json Administrator: Ja -Softwaredaten- Version: 3.2.2.2018 Komponentenversion: 1.0.186 Version des Aktualisierungspakets: 1.0.2630 Lizenz: Kostenlos -Systemdaten- Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Rudi-HP\Rudi -Scan-Übersicht- Scan-Typ: Bedrohungs-Scan Ergebnis: Abgeschlossen Gescannte Objekte: 311301 Erkannte Bedrohungen: 7 In die Quarantäne verschobene Bedrohungen: 0 (keine bösartigen Elemente erkannt) Abgelaufene Zeit: 23 Min., 20 Sek. -Scan-Optionen- Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Erkennung PUM: Erkennung -Scan-Details- Prozess: 0 (keine bösartigen Elemente erkannt) Modul: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 3 PUP.Optional.ASK, HKU\S-1-5-21-3229228620-787667599-3763351482-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2FA28606-DE77-4029-AF96-B231E3B8F827}, Keine Aktion durch Benutzer, [510], [184157],1.0.2630 PUP.Optional.ASK, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2FA28606-DE77-4029-AF96-B231E3B8F827}, Keine Aktion durch Benutzer, [510], [184157],1.0.2630 PUP.Optional.ASK, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}, Keine Aktion durch Benutzer, [510], [184157],1.0.2630 Registrierungswert: 4 Trojan.Agent.WNL, HKU\S-1-5-21-3229228620-787667599-3763351482-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|JICC7N9BYXBTRVW, Keine Aktion durch Benutzer, [5449], [224148],1.0.2630 PUP.Optional.ASK, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}|URL, Keine Aktion durch Benutzer, [510], [184157],1.0.2630 PUP.Optional.ASK, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}|URL, Keine Aktion durch Benutzer, [510], [184157],1.0.2630 PUP.Optional.ASK, HKU\S-1-5-21-3229228620-787667599-3763351482-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}|URL, Keine Aktion durch Benutzer, [510], [184156],1.0.2630 Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Daten-Stream: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Datei: 0 (keine bösartigen Elemente erkannt) Physischer Sektor: 0 (keine bösartigen Elemente erkannt) (end) hatte da noch was gefunden, was ich vorher gemacht habe, hoffe das es dir keine zusätzliche arbeit jetzt macht. Gruß rudi Hallo Cosinus, wann darf ich Adobe Acrobat installieren? Komme mit der Arbeit nicht weiter. Gruß Rudi |
Themen zu Zertifikatfehler, Navigation |
datum, einfügen, ellung, fehler, früheren, navigation, nicht, punkt, reagiert, seite, seiten, sende, symbol, web.de |