FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:07-06-2016
durchgeführt von clara (Administrator) auf DESKTOP-15IT3MI (08-06-2016 16:27:01)
Gestartet von C:\Users\clara\Downloads
Geladene Profile: clara & Bereich2 & (Verfügbare Profile: clara & Bereich2)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Edge)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
() C:\Program Files (x86)\PHotkey\PGFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\PHotkey\Atouch64.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files (x86)\PHotkey\POsd.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Program Files (x86)\PHotkey\GPMTray.exe
() C:\Program Files (x86)\PHotkey\KeyboardMonitorTool.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Nico Mak Computing) C:\Program Files\WinZip\FAHWindow64.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WZUpdateNotifier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(1und1 Mail und Media GmbH) C:\Program Files (x86)\GMX MailCheck\IE\GMX_MailCheck_Broker.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6868.40731.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6868.40731.0_x64__8wekyb3d8bbwe\HxTsr.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x64__8wekyb3d8bbwe\Calculator.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe
(Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13876952 2015-04-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3352808 2016-02-16] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [110008 2015-05-26] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [499128 2015-05-26] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [814608 2016-05-10] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66328 2016-04-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [23745808 2016-05-07] (Dropbox, Inc.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [186640 2016-05-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5890848 2016-04-26] (IObit)
HKLM-x32\...\Run: [MailCheck IE Broker] => C:\Program Files (x86)\GMX MailCheck\IE\GMX_MailCheck_Broker.exe [2184040 2016-03-23] (1und1 Mail und Media GmbH)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003\...\Run: [ApowersoftScreenRecorder] => C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe /autoStart
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8698584 2016-04-15] (Piriform Ltd)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleChromeAutoLaunch_7F31E156738512CA29F2870A44423CA2] => "C:\Users\clara\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ApowersoftScreenRecorder] => C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe /autoStart
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8698584 2016-04-15] (Piriform Ltd)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [ApowersoftScreenRecorder] => C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe /autoStart
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8698584 2016-04-15] (Piriform Ltd)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\...\Run: [ApowersoftScreenRecorder] => C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe /autoStart
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8698584 2016-04-15] (Piriform Ltd)
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2016-06-06]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Benachrichtigungsdienst.lnk [2016-06-06]
ShortcutTarget: Update Benachrichtigungsdienst.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (WinZip Computing, S.L.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-06-06]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{3399b2e2-ad14-4ded-af21-0547afa59d36}: [DhcpNameServer] 192.168.178.1
ManualProxies:
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.gmx.net/tb/ie_startpage
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.gmx.net/tb/ie_startpage
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.gmx.net/tb/ie_startpage
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.gmx.net/tb/ie_startpage
HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {2246954B-EC67-4488-9F95-53C4A609C3F4} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-a53168d9&q={searchTerms}
SearchScopes: HKLM -> {d4fee3d1-1014-4db8-a824-573bf9ab51c7} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-a53168d9&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003 -> {01236F7B-0990-49C2-B44F-4725DFCBDEE8} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003 -> {0D138C86-4E14-49E8-BBD8-89C30A0C9F90} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003 -> {D3F5E96D-DBB3-4DC3-B317-AFCCFC980D73} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003 -> {E0B247D5-CD83-4C3F-9AF3-612BC90BD03E} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {01236F7B-0990-49C2-B44F-4725DFCBDEE8} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0D138C86-4E14-49E8-BBD8-89C30A0C9F90} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {D3F5E96D-DBB3-4DC3-B317-AFCCFC980D73} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {E0B247D5-CD83-4C3F-9AF3-612BC90BD03E} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> {01236F7B-0990-49C2-B44F-4725DFCBDEE8} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> {0D138C86-4E14-49E8-BBD8-89C30A0C9F90} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> {D3F5E96D-DBB3-4DC3-B317-AFCCFC980D73} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> {E0B247D5-CD83-4C3F-9AF3-612BC90BD03E} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2 -> {01236F7B-0990-49C2-B44F-4725DFCBDEE8} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2 -> {0D138C86-4E14-49E8-BBD8-89C30A0C9F90} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2 -> {D3F5E96D-DBB3-4DC3-B317-AFCCFC980D73} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2 -> {E0B247D5-CD83-4C3F-9AF3-612BC90BD03E} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004 -> {1AE38B7E-3B7B-43F2-8E5D-71BE1AE71252} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004 -> {3A9E5498-73DA-44AA-83AE-DD7A7ABD8EDE} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004 -> {7FAB4C91-526A-4C6D-A4E1-CC3CFC4F0A08} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004 -> {AC15117D-57AA-4C28-9105-FD56E72FFF85} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {1AE38B7E-3B7B-43F2-8E5D-71BE1AE71252} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {3A9E5498-73DA-44AA-83AE-DD7A7ABD8EDE} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {7FAB4C91-526A-4C6D-A4E1-CC3CFC4F0A08} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {AC15117D-57AA-4C28-9105-FD56E72FFF85} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> {1AE38B7E-3B7B-43F2-8E5D-71BE1AE71252} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> {3A9E5498-73DA-44AA-83AE-DD7A7ABD8EDE} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> {7FAB4C91-526A-4C6D-A4E1-CC3CFC4F0A08} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> {AC15117D-57AA-4C28-9105-FD56E72FFF85} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2 -> {1AE38B7E-3B7B-43F2-8E5D-71BE1AE71252} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2 -> {3A9E5498-73DA-44AA-83AE-DD7A7ABD8EDE} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2 -> {7FAB4C91-526A-4C6D-A4E1-CC3CFC4F0A08} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1396311255-3119801075-1131251309-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2 -> {AC15117D-57AA-4C28-9105-FD56E72FFF85} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: GMX MailCheck BHO -> {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} -> C:\Program Files\GMX MailCheck\IE\GMX_MailCheck.dll [2016-03-23] (1und1 Mail und Media GmbH)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: GMX MailCheck BHO -> {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} -> C:\Program Files (x86)\GMX MailCheck\IE\GMX_MailCheck.dll [2016-03-23] (1und1 Mail und Media GmbH)
Toolbar: HKLM - GMX MailCheck - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\GMX MailCheck\IE\GMX_MailCheck.dll [2016-03-23] (1und1 Mail und Media GmbH)
Toolbar: HKLM-x32 - GMX MailCheck - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files (x86)\GMX MailCheck\IE\GMX_MailCheck.dll [2016-03-23] (1und1 Mail und Media GmbH)
Handler: gmx - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\GMX MailCheck\IE\GMX_MailCheck.dll [2016-03-23] (1und1 Mail und Media GmbH)
Handler-x32: gmx - {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files (x86)\GMX MailCheck\IE\GMX_MailCheck.dll [2016-03-23] (1und1 Mail und Media GmbH)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-1396311255-3119801075-1131251309-1003 -> hxxp://go.gmx.net/tb/ie_startpage
FireFox:
========
FF ProfilePath: C:\Users\clara\AppData\Roaming\Mozilla\Firefox\Profiles\4EFccKAs.default
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll [2008-10-15] (CANON INC.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll [2013-07-26] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-23] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-23] (Google Inc.)
FF Extension: pdfit - C:\Users\clara\AppData\Roaming\Mozilla\Firefox\Profiles\4EFccKAs.default\extensions\service@touchpdf.com.xpi [2016-05-18]
FF Extension: Avira Browser Safety - C:\Users\clara\AppData\Roaming\Mozilla\Firefox\Profiles\4EFccKAs.default\Extensions\abs@avira.com [2016-05-18]
FF Extension: Adblock Plus - C:\Users\clara\AppData\Roaming\Mozilla\Firefox\Profiles\4EFccKAs.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-06-05]
Chrome:
=======
CHR HomePage: Default -> hxxp://www-searching.com/?pid=s&s=g5dztutbl10bp,53d3da4b-2265-4af3-9e4b-f46a69f7fe3a,&vp=ch&prd=set_ch
CHR StartupUrls: Default -> "hxxp://www-searching.com/?pid=s&s=g5dztutbl10bp,53d3da4b-2265-4af3-9e4b-f46a69f7fe3a,&vp=ch&prd=set_ch"
CHR DefaultSearchURL: Default -> hxxp://www-searching.com/search.aspx?site=shyos&prd=set_ch&q={searchTerms}&s=g5dztutbl10bp,53d3da4b-2265-4af3-9e4b-f46a69f7fe3a,
CHR DefaultSearchKeyword: Default -> www-searching.com
CHR DefaultSuggestURL: Default -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
CHR Profile: C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-12]
CHR Extension: (Google Docs) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-12]
CHR Extension: (Google Drive) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-12]
CHR Extension: (YouTube) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-12]
CHR Extension: (Google Tabellen) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-12]
CHR Extension: (Avira Browserschutz) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-12]
CHR Extension: (Google Docs Offline) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-25]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-12]
CHR Extension: (Google Mail) - C:\Users\clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-12]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1396311255-3119801075-1131251309-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bahkljhhdeciiaodlkppoonappfnheoi] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [970656 2016-05-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [467016 2016-05-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [467016 2016-05-10] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1435704 2016-05-10] (Avira Operations GmbH & Co. KG)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1080592 2016-05-18] (AVG Technologies CZ, s.r.o.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [280008 2016-04-25] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
S2 chip1click; C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe [81408 2016-04-28] (Chip Digital GmbH) [Datei ist nicht signiert]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-05-12] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-05-12] (Dropbox, Inc.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144104 2016-02-16] (ELAN Microelectronics Corp.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
R2 ibtsiva; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [150256 2015-06-09] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373160 2016-04-05] (Intel Corporation)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [1580320 2016-04-22] (IObit)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-04-21] (IObit)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-06-12] ()
R2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software)
R2 PGFNEXSrv; C:\Program Files (x86)\PHotkey\PGFNEXSrv.exe [135680 2014-08-07] () [Datei ist nicht signiert]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [4803344 2016-06-01] (AVG Technologies CZ, s.r.o.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831200 2015-06-12] (Intel® Corporation)
S2 0135741465131193mcinstcleanup; C:\Users\clara\AppData\Local\Temp\013574~1.EXE -cleanup -nolog [X]
S2 037e713cd56be5a1dbcb4a2442b5fdbc; "C:\Program Files\4ce3892986d8fffb2dabbf5939305440\2ba62e02bd2c18306b7bc8a5aba4a273.exe" [X]
S4 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [X]
S2 mfemms; "C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe" [X]
S2 mfevtp; "C:\Windows\system32\mfevtps.exe" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128664 2016-03-26] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [146712 2016-05-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [35488 2016-03-26] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [78208 2016-05-10] (Avira Operations GmbH & Co. KG)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
S3 clwvd6; C:\Windows\system32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [30808 2016-02-16] (ELAN Microelectronic Corp.)
U0 hpsl; C:\Windows\System32\drivers\yffqig.sys [79064 2016-06-05] (Malwarebytes)
R3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [46856 2015-06-15] (Intel Corporation)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [263952 2016-04-05] (Intel Corporation)
R3 IMFFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [22208 2016-03-31] (IObit)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-06-08] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [183584 2015-06-12] (Intel Corporation)
R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3776792 2015-06-22] (Intel Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
R3 PegaRadioSwitch; C:\Windows\System32\drivers\PegaRadioSwitch.sys [33560 2015-06-05] (Windows (R) Win 7 DDK provider)
R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2016-03-31] (IObit.com)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [411712 2015-05-19] (Realsil Semiconductor Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2016-03-29] (AVG Netherlands B.V.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R1 1b3fda65ea3ff3344cf1d4c4d8144437; system32\DRIVERS\1b3fda65ea3ff3344cf1d4c4d8144437.sys [X]
S0 cfwids; system32\drivers\cfwids.sys [X]
R0 mfeaack; system32\drivers\mfeaack.sys [X]
R0 mfeavfk; system32\drivers\mfeavfk.sys [X]
S0 mfeelamk; system32\drivers\mfeelamk.sys [X]
S0 mfefirek; system32\drivers\mfefirek.sys [X]
R0 mfehidk; system32\drivers\mfehidk.sys [X]
R0 mfewfpk; system32\drivers\mfewfpk.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-06-08 16:27 - 2016-06-08 16:29 - 00040384 _____ C:\Users\clara\Downloads\FRST.txt
2016-06-08 16:26 - 2016-06-08 16:27 - 00000000 ____D C:\FRST
2016-06-08 16:26 - 2016-06-08 16:26 - 02385408 _____ (Farbar) C:\Users\clara\Downloads\FRST64.exe
2016-06-07 19:38 - 2016-06-07 19:38 - 00025475 _____ C:\Users\clara\AppData\Local\recently-used.xbel
2016-06-06 23:28 - 2016-06-06 23:29 - 00543552 _____ C:\Users\clara\Downloads\bwp-2008-h6-49f.pdf
2016-06-05 17:24 - 2016-06-05 17:24 - 00079064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\yffqig.sys
2016-06-05 16:45 - 2016-06-08 15:56 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-06-05 16:43 - 2016-06-06 14:53 - 00001173 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-06-05 16:43 - 2016-06-05 16:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-06-05 16:43 - 2016-06-05 16:43 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-06-05 16:43 - 2016-06-05 16:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-06-05 16:43 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-06-05 16:43 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-06-05 16:43 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-06-05 16:41 - 2016-06-05 16:41 - 01473544 _____ C:\Users\clara\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe
2016-06-05 14:52 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2016-06-05 14:50 - 2016-06-06 14:53 - 00001468 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2016-06-05 14:50 - 2016-06-06 14:53 - 00001450 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2016-06-05 14:50 - 2016-06-05 15:50 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-06-05 14:50 - 2016-06-05 14:50 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2016-06-05 14:50 - 2016-06-05 14:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2016-06-05 14:50 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2016-06-05 14:49 - 2016-06-05 19:52 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-06-05 14:47 - 2016-06-05 14:47 - 01473544 _____ C:\Users\clara\Downloads\SpyBot Search Destroy - CHIP-Installer.exe
2016-06-05 14:24 - 2016-06-05 14:24 - 00000000 ____D C:\Users\clara\Downloads\Edge.Adblock.v2.1
2016-06-05 14:22 - 2016-06-05 14:22 - 00010026 _____ C:\Users\clara\Downloads\Edge.Adblock.v2.1.zip
2016-06-03 18:08 - 2016-06-03 19:44 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-06-03 18:05 - 2016-06-03 18:05 - 00000000 ____D C:\WINDOWS\pss
2016-06-03 00:06 - 2016-06-03 00:06 - 00000000 ____D C:\Users\Default\AppData\Local\AVG
2016-06-03 00:06 - 2016-06-03 00:06 - 00000000 ____D C:\Users\Default User\AppData\Local\AVG
2016-05-26 22:18 - 2016-05-26 22:19 - 28618552 _____ (TuneUp Software) C:\Users\clara\Downloads\TuneUpUtilities2014353_de-DE (1).exe
2016-05-26 22:03 - 2016-05-26 22:03 - 00000000 ____D C:\Users\Bereich2\AppData\Roaming\Mozilla
2016-05-26 22:03 - 2016-05-26 22:03 - 00000000 ____D C:\Users\Bereich2\AppData\Local\Mozilla
2016-05-26 21:46 - 2016-05-26 21:46 - 00000000 ____D C:\Users\Bereich2\AppData\Roaming\Avira
2016-05-26 21:46 - 2016-05-26 21:46 - 00000000 ____D C:\Users\Bereich2\AppData\Local\Comms
2016-05-26 21:44 - 2016-05-26 21:45 - 00002400 _____ C:\Users\Bereich2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-05-26 21:44 - 2016-05-26 21:45 - 00000000 ___RD C:\Users\Bereich2\OneDrive
2016-05-26 21:42 - 2016-05-26 21:42 - 00000000 ____D C:\Users\Bereich2\AppData\Local\MicrosoftEdge
2016-05-26 21:42 - 2016-05-26 21:42 - 00000000 ____D C:\Users\Bereich2\AppData\Local\ActiveSync
2016-05-26 21:41 - 2016-05-26 21:41 - 00000000 ____D C:\Users\Bereich2\AppData\Local\Publishers
2016-05-26 21:38 - 2016-05-26 21:39 - 00000000 ____D C:\Users\Bereich2\AppData\Local\Dropbox
2016-05-26 21:38 - 2016-05-26 21:38 - 00000000 ____D C:\Users\Bereich2\AppData\Roaming\Intel Corporation
2016-05-26 21:38 - 2016-05-26 21:38 - 00000000 ____D C:\Users\Bereich2\AppData\LocalLow\IObit
2016-05-26 21:37 - 2016-05-26 21:37 - 00000000 ____D C:\Users\Bereich2\AppData\Roaming\ProductData
2016-05-26 21:37 - 2016-05-26 21:37 - 00000000 ____D C:\Users\Bereich2\AppData\LocalLow\1&1 Mail & Media GmbH
2016-05-26 21:37 - 2016-05-26 21:37 - 00000000 ____D C:\Users\Bereich2\AppData\Local\WinZip Computing, S.L
2016-05-26 21:37 - 2016-05-26 21:37 - 00000000 ____D C:\Users\Bereich2\AppData\Local\Power2Go8
2016-05-26 21:33 - 2016-05-26 21:47 - 00000000 ____D C:\Users\Bereich2\AppData\Local\Packages
2016-05-26 21:33 - 2016-05-26 21:44 - 00000000 ____D C:\Users\Bereich2
2016-05-26 21:33 - 2016-05-26 21:40 - 00000000 __SHD C:\Users\Bereich2\IntelGraphicsProfiles
2016-05-26 21:33 - 2016-05-26 21:38 - 00000000 ____D C:\Users\Bereich2\AppData\Roaming\IObit
2016-05-26 21:33 - 2016-05-26 21:33 - 00000020 ___SH C:\Users\Bereich2\ntuser.ini
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Vorlagen
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Startmenü
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Netzwerkumgebung
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Lokale Einstellungen
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Eigene Dateien
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Druckumgebung
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Documents\Eigene Videos
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Documents\Eigene Musik
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Documents\Eigene Bilder
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\AppData\Local\Verlauf
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\AppData\Local\Anwendungsdaten
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 _SHDL C:\Users\Bereich2\Anwendungsdaten
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 ____D C:\Users\Bereich2\AppData\Roaming\Intel
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 ____D C:\Users\Bereich2\AppData\Roaming\Adobe
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 ____D C:\Users\Bereich2\AppData\Local\VirtualStore
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 ____D C:\Users\Bereich2\AppData\Local\TileDataLayer
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 ____D C:\Users\Bereich2\AppData\Local\Google
2016-05-26 21:33 - 2016-05-26 21:33 - 00000000 ____D C:\Users\Bereich2\AppData\Local\Avg
2016-05-26 21:33 - 2016-05-12 21:56 - 00000000 ____D C:\Users\Bereich2\AppData\Roaming\Macromedia
2016-05-26 21:33 - 2014-04-23 14:47 - 00002007 _____ C:\Users\Bereich2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\McAfee LiveSafe - Internet Security.lnk
2016-05-23 23:49 - 2016-05-23 23:49 - 00434820 _____ C:\Users\clara\Documents\Anti-AfD.odt
2016-05-23 21:37 - 2016-05-23 21:37 - 00408122 _____ C:\Users\clara\Downloads\AfD_Programm_Lang (1).pdf
2016-05-23 21:04 - 2016-05-23 21:04 - 00408122 _____ C:\Users\clara\Downloads\AfD_Programm_Lang.pdf
2016-05-19 01:49 - 2016-05-19 01:49 - 42384097 _____ C:\Users\clara\Documents\Sportler.xcf
2016-05-18 17:57 - 2016-05-18 17:57 - 00439850 _____ C:\Users\clara\Documents\Prinzessionenrep..pdf
2016-05-18 17:54 - 2016-05-18 17:54 - 00401019 _____ C:\Users\clara\Documents\Seite.pdf
2016-05-18 17:53 - 2016-05-18 17:53 - 00354317 _____ C:\Users\clara\Documents\Trialog.pdf
2016-05-18 17:52 - 2016-05-18 17:52 - 00387740 _____ C:\Users\clara\Documents\Zeilen.pdf
2016-05-18 17:52 - 2016-05-18 17:52 - 00345989 _____ C:\Users\clara\Documents\Nürnberg.pdf
2016-05-18 17:51 - 2016-05-18 17:51 - 00396465 _____ C:\Users\clara\Documents\Geburtshelfer.pdf
2016-05-18 17:49 - 2016-05-18 17:49 - 01956288 _____ C:\Users\clara\Documents\Symbolischer Auftakt – haGalil.pdf
2016-05-18 17:48 - 2016-05-18 17:48 - 02288609 _____ C:\Users\clara\Documents\Koscherer Genuss und Natürlichkeit – Die Hofpfisterei – haGalil.pdf
2016-05-18 17:43 - 2016-05-18 17:43 - 00358642 _____ C:\Users\clara\Documents\Emotionale Heimat.pdf
2016-05-18 17:39 - 2016-05-18 17:39 - 02281981 _____ C:\Users\clara\Documents\1. Abrahamitisches Fest in Nürnberg – haGalil.pdf
2016-05-18 17:36 - 2016-06-01 19:45 - 00000000 ____D C:\Users\clara\AppData\Roaming\Nitro PDF
2016-05-18 17:29 - 2016-05-18 17:29 - 00000000 ____D C:\Users\clara\AppData\Roaming\Nitro
2016-05-18 17:29 - 2016-05-18 17:29 - 00000000 ____D C:\Users\clara\AppData\Roaming\FileOpen
2016-05-18 17:29 - 2016-05-18 17:29 - 00000000 ____D C:\ProgramData\FileOpen
2016-05-18 17:28 - 2016-06-06 14:53 - 00002515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Reader 3.lnk
2016-05-18 17:28 - 2016-06-06 14:53 - 00002074 _____ C:\Users\Public\Desktop\Nitro Reader.lnk
2016-05-18 17:28 - 2016-05-18 17:28 - 00000000 ____D C:\ProgramData\Nitro
2016-05-18 17:28 - 2016-05-18 17:28 - 00000000 ____D C:\Program Files\Common Files\Nitro
2016-05-18 17:28 - 2016-05-18 17:28 - 00000000 ____D C:\Program Files (x86)\Nitro
2016-05-18 17:28 - 2013-07-26 06:57 - 00029712 _____ (Nitro PDF Software) C:\WINDOWS\system32\nitrolocalmon2.dll
2016-05-18 17:28 - 2013-07-26 06:57 - 00017936 _____ (Nitro PDF Software) C:\WINDOWS\system32\nitrolocalui2.dll
2016-05-18 17:18 - 2016-05-18 17:18 - 00000000 ____D C:\Users\clara\AppData\Roaming\Downloaded Installations
2016-05-18 17:16 - 2016-05-18 17:16 - 01475080 _____ C:\Users\clara\Downloads\Nitro PDF Reader 64 Bit - CHIP-Installer.exe
2016-05-18 17:13 - 2016-05-18 17:14 - 00331822 _____ C:\Users\clara\Documents\Den Trialog feiern 1. Abrahamitisches Fest in Nürnberg – haGalil.htm
2016-05-18 17:13 - 2016-05-18 17:14 - 00000000 ____D C:\Users\clara\Documents\Den Trialog feiern 1. Abrahamitisches Fest in Nürnberg – haGalil-Dateien
2016-05-18 00:43 - 2016-06-06 14:53 - 00001013 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-05-18 00:43 - 2016-06-06 14:53 - 00000995 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-05-18 00:43 - 2016-05-18 14:56 - 00000000 ____D C:\Users\clara\AppData\Local\Mozilla
2016-05-18 00:43 - 2016-05-18 00:43 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-05-18 00:43 - 2016-05-18 00:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-05-18 00:41 - 2016-05-18 00:42 - 46412928 _____ C:\Users\clara\Downloads\Firefox_Setup_46.0.1_x64.exe
2016-05-17 00:38 - 2016-05-17 00:38 - 00000138 _____ C:\Users\clara\Documents\Kalorientabelle.klf
2016-05-17 00:34 - 2016-05-20 19:30 - 00000000 ____D C:\Program Files (x86)\KaloMa
2016-05-17 00:34 - 2016-05-17 00:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KaloMa
2016-05-17 00:32 - 2012-12-24 09:59 - 01893458 _____ (Frank Böpple ) C:\Users\clara\Downloads\KaloMa_4.94_Setup.exe
2016-05-17 00:31 - 2016-05-17 00:31 - 01821022 _____ C:\Users\clara\Downloads\kaloma494.zip
2016-05-16 21:46 - 2016-06-06 14:51 - 00002213 _____ C:\Users\clara\Desktop\DirectX - CHIP Downloader.lnk
2016-05-16 21:28 - 2010-06-02 04:58 - 00006796 ____N C:\Users\clara\Documents\d3dcsx_43_x86.cat
2016-05-16 21:28 - 2010-06-02 04:58 - 00006796 ____N C:\Users\clara\Documents\d3dcsx_43_x64.cat
2016-05-16 21:28 - 2010-06-02 04:58 - 00006796 ____N C:\Users\clara\Documents\D3DCompiler_43_x86.cat
2016-05-16 21:28 - 2010-06-02 04:58 - 00006796 ____N C:\Users\clara\Documents\D3DCompiler_43_x64.cat
2016-05-16 21:28 - 2010-05-26 11:41 - 02106216 ____N (Microsoft Corporation) C:\Users\clara\Documents\D3DCompiler_43.dll
2016-05-16 21:28 - 2010-05-26 11:41 - 01868128 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dcsx_43.dll
2016-05-16 21:28 - 2009-09-04 17:46 - 00007094 ____N C:\Users\clara\Documents\XAudio2_5_x86.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00007081 ____N C:\Users\clara\Documents\XAudio2_5_x64.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006796 ____N C:\Users\clara\Documents\XACT3_5_x86.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006796 ____N C:\Users\clara\Documents\XACT3_5_x64.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006796 ____N C:\Users\clara\Documents\d3dx9_42_x86.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006796 ____N C:\Users\clara\Documents\d3dx11_42_x86.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006796 ____N C:\Users\clara\Documents\d3dx10_42_x64.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006783 ____N C:\Users\clara\Documents\d3dx9_42_x64.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006783 ____N C:\Users\clara\Documents\d3dx11_42_x64.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006783 ____N C:\Users\clara\Documents\d3dx10_42_x86.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006783 ____N C:\Users\clara\Documents\d3dcsx_42_x86.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006783 ____N C:\Users\clara\Documents\d3dcsx_42_x64.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006783 ____N C:\Users\clara\Documents\D3DCompiler_42_x86.cat
2016-05-16 21:28 - 2009-09-04 17:46 - 00006783 ____N C:\Users\clara\Documents\D3DCompiler_42_x64.cat
2016-05-16 21:28 - 2009-09-04 17:44 - 00515416 ____N (Microsoft Corporation) C:\Users\clara\Documents\XAudio2_5.dll
2016-05-16 21:28 - 2009-09-04 17:44 - 00238936 ____N (Microsoft Corporation) C:\Users\clara\Documents\xactengine3_5.dll
2016-05-16 21:28 - 2009-09-04 17:44 - 00069464 ____N (Microsoft Corporation) C:\Users\clara\Documents\XAPOFX1_3.dll
2016-05-16 21:28 - 2009-09-04 17:29 - 05501792 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dcsx_42.dll
2016-05-16 21:28 - 2009-09-04 17:29 - 01974616 ____N (Microsoft Corporation) C:\Users\clara\Documents\D3DCompiler_42.dll
2016-05-16 21:28 - 2009-09-04 17:29 - 01892184 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_42.dll
2016-05-16 21:28 - 2009-09-04 17:29 - 00453456 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dx10_42.dll
2016-05-16 21:28 - 2009-09-04 17:29 - 00235344 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dx11_42.dll
2016-05-16 21:28 - 2008-07-31 10:44 - 00010342 ____N C:\Users\clara\Documents\XAudio2_2_x86.cat
2016-05-16 21:28 - 2008-07-31 10:44 - 00010342 ____N C:\Users\clara\Documents\XAudio2_2_x64.cat
2016-05-16 21:28 - 2008-07-31 10:44 - 00010044 ____N C:\Users\clara\Documents\XACT3_2_x86.cat
2016-05-16 21:28 - 2008-07-31 10:44 - 00010044 ____N C:\Users\clara\Documents\XACT3_2_x64.cat
2016-05-16 21:28 - 2008-07-31 10:41 - 00238088 ____N (Microsoft Corporation) C:\Users\clara\Documents\xactengine3_2.dll
2016-05-16 21:28 - 2008-07-31 10:41 - 00068616 ____N (Microsoft Corporation) C:\Users\clara\Documents\XAPOFX1_1.dll
2016-05-16 21:28 - 2008-07-31 10:40 - 00509448 ____N (Microsoft Corporation) C:\Users\clara\Documents\XAudio2_2.dll
2016-05-16 21:28 - 2008-07-30 06:23 - 00010342 ____N C:\Users\clara\Documents\d3dx10_39_x86.cat
2016-05-16 21:28 - 2008-07-30 06:23 - 00010342 ____N C:\Users\clara\Documents\d3dx10_39_x64.cat
2016-05-16 21:28 - 2008-07-30 06:23 - 00010044 ____N C:\Users\clara\Documents\d3dx9_39_x86.cat
2016-05-16 21:28 - 2008-07-30 06:23 - 00010044 ____N C:\Users\clara\Documents\d3dx9_39_x64.cat
2016-05-16 21:28 - 2008-07-10 11:01 - 00467984 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dx10_39.dll
2016-05-16 21:28 - 2008-07-10 11:00 - 03851784 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_39.dll
2016-05-16 21:28 - 2008-07-10 11:00 - 01493528 ____N (Microsoft Corporation) C:\Users\clara\Documents\D3DCompiler_39.dll
2016-05-16 21:28 - 2008-05-30 14:23 - 00010342 ____N C:\Users\clara\Documents\XAudio2_1_x86.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010342 ____N C:\Users\clara\Documents\XAudio2_1_x64.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010342 ____N C:\Users\clara\Documents\d3dx10_38_x86.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010342 ____N C:\Users\clara\Documents\d3dx10_38_x64.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010044 ____N C:\Users\clara\Documents\XACT3_1_x86.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010044 ____N C:\Users\clara\Documents\XACT3_1_x64.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010044 ____N C:\Users\clara\Documents\X3DAudio1_4_x86.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010044 ____N C:\Users\clara\Documents\X3DAudio1_4_x64.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010044 ____N C:\Users\clara\Documents\d3dx9_38_x86.cat
2016-05-16 21:28 - 2008-05-30 14:23 - 00010044 ____N C:\Users\clara\Documents\d3dx9_38_x64.cat
2016-05-16 21:28 - 2008-05-30 14:19 - 00507400 ____N (Microsoft Corporation) C:\Users\clara\Documents\XAudio2_1.dll
2016-05-16 21:28 - 2008-05-30 14:18 - 00238088 ____N (Microsoft Corporation) C:\Users\clara\Documents\xactengine3_1.dll
2016-05-16 21:28 - 2008-05-30 14:17 - 00065032 ____N (Microsoft Corporation) C:\Users\clara\Documents\XAPOFX1_0.dll
2016-05-16 21:28 - 2008-05-30 14:17 - 00025608 ____N (Microsoft Corporation) C:\Users\clara\Documents\X3DAudio1_4.dll
2016-05-16 21:28 - 2008-05-30 14:11 - 03850760 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_38.dll
2016-05-16 21:28 - 2008-05-30 14:11 - 01491992 ____N (Microsoft Corporation) C:\Users\clara\Documents\D3DCompiler_38.dll
2016-05-16 21:28 - 2008-05-30 14:11 - 00467984 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dx10_38.dll
2016-05-16 21:28 - 2007-07-20 01:10 - 00010690 _____ C:\Users\clara\Documents\xact2_9_x86.cat
2016-05-16 21:28 - 2007-07-20 01:10 - 00010690 _____ C:\Users\clara\Documents\xact2_9_x64.cat
2016-05-16 21:28 - 2007-07-20 01:10 - 00010690 _____ C:\Users\clara\Documents\d3dx10_35_x86.cat
2016-05-16 21:28 - 2007-07-20 01:10 - 00010690 _____ C:\Users\clara\Documents\d3dx10_35_x64.cat
2016-05-16 21:28 - 2007-07-20 01:10 - 00010392 _____ C:\Users\clara\Documents\d3dx9_35_x86.cat
2016-05-16 21:28 - 2007-07-20 01:10 - 00010392 _____ C:\Users\clara\Documents\d3dx9_35_x64.cat
2016-05-16 21:28 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Users\clara\Documents\xactengine2_9.dll
2016-05-16 21:28 - 2007-07-20 00:54 - 00018280 _____ (Microsoft Corporation) C:\Users\clara\Documents\x3daudio1_2.dll
2016-05-16 21:28 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_35.dll
2016-05-16 21:28 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dcompiler_35.dll
2016-05-16 21:28 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx10_35.dll
2016-05-16 21:28 - 2007-06-20 21:00 - 00010690 _____ C:\Users\clara\Documents\xact2_8_x86.cat
2016-05-16 21:28 - 2007-06-20 21:00 - 00010690 _____ C:\Users\clara\Documents\xact2_8_x64.cat
2016-05-16 21:28 - 2007-06-20 21:00 - 00010690 _____ C:\Users\clara\Documents\d3dx10_34_x86.cat
2016-05-16 21:28 - 2007-06-20 21:00 - 00010690 _____ C:\Users\clara\Documents\d3dx10_34_x64.cat
2016-05-16 21:28 - 2007-06-20 21:00 - 00010392 _____ C:\Users\clara\Documents\d3dx9_34_x86.cat
2016-05-16 21:28 - 2007-06-20 21:00 - 00010392 _____ C:\Users\clara\Documents\d3dx9_34_x64.cat
2016-05-16 21:28 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Users\clara\Documents\xactengine2_8.dll
2016-05-16 21:28 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_34.dll
2016-05-16 21:28 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dcompiler_34.dll
2016-05-16 21:28 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx10_34.dll
2016-05-16 21:28 - 2007-04-04 19:04 - 00010690 _____ C:\Users\clara\Documents\xact2_7_x86.cat
2016-05-16 21:28 - 2007-04-04 19:04 - 00010690 _____ C:\Users\clara\Documents\xact2_7_x64.cat
2016-05-16 21:28 - 2007-04-04 19:04 - 00010690 _____ C:\Users\clara\Documents\d3dx10_33_x64.cat
2016-05-16 21:28 - 2007-04-04 19:03 - 00010690 _____ C:\Users\clara\Documents\d3dx10_33_x86.cat
2016-05-16 21:28 - 2007-04-04 19:03 - 00010392 _____ C:\Users\clara\Documents\xinput1_3_x86.cat
2016-05-16 21:28 - 2007-04-04 19:03 - 00010392 _____ C:\Users\clara\Documents\d3dx9_33_x86.cat
2016-05-16 21:28 - 2007-04-04 19:03 - 00010392 _____ C:\Users\clara\Documents\d3dx9_33_x64.cat
2016-05-16 21:28 - 2007-04-04 19:01 - 00010392 _____ C:\Users\clara\Documents\xinput1_3_x64.cat
2016-05-16 21:28 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Users\clara\Documents\xactengine2_7.dll
2016-05-16 21:28 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Users\clara\Documents\xinput1_3.dll
2016-05-16 21:28 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx10_33.dll
2016-05-16 21:28 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_33.dll
2016-05-16 21:28 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dcompiler_33.dll
2016-05-16 21:28 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Users\clara\Documents\x3daudio1_1.dll
2016-05-16 21:28 - 2006-07-28 10:23 - 00008225 _____ C:\Users\clara\Documents\xact2_3_x86.cat
2016-05-16 21:28 - 2006-07-28 10:23 - 00008225 _____ C:\Users\clara\Documents\xact2_3_x64.cat
2016-05-16 21:28 - 2006-07-28 10:23 - 00007927 _____ C:\Users\clara\Documents\xinput1_2_x86.cat
2016-05-16 21:28 - 2006-07-28 10:23 - 00007927 _____ C:\Users\clara\Documents\xinput1_2_x64.cat
2016-05-16 21:28 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Users\clara\Documents\xactengine2_3.dll
2016-05-16 21:28 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Users\clara\Documents\xinput1_2.dll
2016-05-16 21:28 - 2006-05-31 07:33 - 00008225 _____ C:\Users\clara\Documents\xact2_2_x86.cat
2016-05-16 21:28 - 2006-05-31 07:33 - 00008225 _____ C:\Users\clara\Documents\xact2_2_x64.cat
2016-05-16 21:28 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Users\clara\Documents\xactengine2_2.dll
2016-05-16 21:28 - 2006-03-31 12:51 - 01263976 _____ C:\Users\clara\Documents\mdx_1.0.2903.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:51 - 01196964 _____ C:\Users\clara\Documents\mdx_1.0.2902.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:51 - 00245752 _____ C:\Users\clara\Documents\mdx_1.0.2910.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:51 - 00245577 _____ C:\Users\clara\Documents\mdx_1.0.2908.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:51 - 00245558 _____ C:\Users\clara\Documents\mdx_1.0.2909.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:51 - 00245262 _____ C:\Users\clara\Documents\mdx_1.0.2907.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:51 - 00244821 _____ C:\Users\clara\Documents\mdx_1.0.2906.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:51 - 00240867 _____ C:\Users\clara\Documents\mdx_1.0.2905.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:51 - 00239102 _____ C:\Users\clara\Documents\mdx_1.0.2904.0_x86.cab
2016-05-16 21:28 - 2006-03-31 12:49 - 00008225 _____ C:\Users\clara\Documents\xact2_1_x86.cat
2016-05-16 21:28 - 2006-03-31 12:49 - 00008225 _____ C:\Users\clara\Documents\xact2_1_x64.cat
2016-05-16 21:28 - 2006-03-31 12:49 - 00007927 _____ C:\Users\clara\Documents\xinput1_1_x86.cat
2016-05-16 21:28 - 2006-03-31 12:49 - 00007927 _____ C:\Users\clara\Documents\xinput1_1_x64.cat
2016-05-16 21:28 - 2006-03-31 12:49 - 00007927 _____ C:\Users\clara\Documents\d3dx9_30_x86.cat
2016-05-16 21:28 - 2006-03-31 12:49 - 00007927 _____ C:\Users\clara\Documents\d3dx9_30_x64.cat
2016-05-16 21:28 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_30.dll
2016-05-16 21:28 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Users\clara\Documents\xactengine2_1.dll
2016-05-16 21:28 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Users\clara\Documents\xinput1_1.dll
2016-05-16 21:28 - 2006-03-31 11:27 - 00578560 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.direct3dx.dll
2016-05-16 21:28 - 2006-03-07 22:46 - 01437695 _____ C:\Users\clara\Documents\microsoft.directx.direct3dx.xml
2016-05-16 21:28 - 2006-03-07 22:46 - 01252798 _____ C:\Users\clara\Documents\microsoft.directx.directplay.xml
2016-05-16 21:28 - 2006-03-07 22:46 - 00849122 _____ C:\Users\clara\Documents\microsoft.directx.direct3d.xml
2016-05-16 21:28 - 2006-03-07 22:46 - 00755962 _____ C:\Users\clara\Documents\microsoft.directx.directdraw.xml
2016-05-16 21:28 - 2006-03-07 22:46 - 00348085 _____ C:\Users\clara\Documents\microsoft.directx.directsound.xml
2016-05-16 21:28 - 2006-03-07 22:46 - 00345509 _____ C:\Users\clara\Documents\microsoft.directx.directinput.xml
2016-05-16 21:28 - 2006-03-07 22:46 - 00265390 _____ C:\Users\clara\Documents\microsoft.directx.xml
2016-05-16 21:28 - 2006-03-07 22:46 - 00033914 _____ C:\Users\clara\Documents\microsoft.directx.audiovideoplayback.xml
2016-05-16 21:28 - 2006-03-07 22:46 - 00010439 _____ C:\Users\clara\Documents\microsoft.directx.diagnostics.xml
2016-05-16 21:28 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Users\clara\Documents\x3daudio1_0.dll
2016-05-16 21:28 - 2005-07-22 20:08 - 00007740 _____ C:\Users\clara\Documents\d3dx9_27_x86.cat
2016-05-16 21:28 - 2005-07-22 20:08 - 00007740 _____ C:\Users\clara\Documents\d3dx9_27_x64.cat
2016-05-16 21:28 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_27.dll
2016-05-16 21:28 - 2005-05-26 15:43 - 00007479 _____ C:\Users\clara\Documents\d3dx9_26_x86.cat
2016-05-16 21:28 - 2005-05-26 15:43 - 00007479 _____ C:\Users\clara\Documents\d3dx9_26_x64.cat
2016-05-16 21:28 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_26.dll
2016-05-16 21:28 - 2005-03-18 17:31 - 00007479 _____ C:\Users\clara\Documents\d3dx9_25_x86.cat
2016-05-16 21:28 - 2005-03-18 17:31 - 00007479 _____ C:\Users\clara\Documents\d3dx9_25_x64.cat
2016-05-16 21:28 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_25.dll
2016-05-16 21:28 - 2005-03-18 16:23 - 00473600 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.direct3d.dll
2016-05-16 21:28 - 2005-03-18 16:23 - 00364544 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.directplay.dll
2016-05-16 21:28 - 2005-03-18 16:23 - 00223232 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.dll
2016-05-16 21:28 - 2005-03-18 16:23 - 00178176 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.directsound.dll
2016-05-16 21:28 - 2005-03-18 16:23 - 00159232 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.directinput.dll
2016-05-16 21:28 - 2005-03-18 16:23 - 00145920 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.directdraw.dll
2016-05-16 21:28 - 2005-03-18 16:23 - 00053248 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.audiovideoplayback.dll
2016-05-16 21:28 - 2005-03-18 16:23 - 00012800 _____ (Microsoft Corporation) C:\Users\clara\Documents\microsoft.directx.diagnostics.dll
2016-05-16 21:27 - 2010-06-02 04:58 - 00006796 ____N C:\Users\clara\Documents\d3dx9_43_x86.cat
2016-05-16 21:27 - 2010-05-26 11:41 - 01998168 ____N (Microsoft Corporation) C:\Users\clara\Documents\d3dx9_43.dll
2016-05-16 21:27 - 2009-09-04 16:13 - 00075776 ____N C:\Users\clara\Documents\infinst.exe
2016-05-16 21:26 - 2016-05-16 21:26 - 01378405 _____ (Igor Pavlov) C:\Users\clara\Downloads\7z1600-x64.exe
2016-05-16 21:26 - 2016-05-16 21:26 - 00003968 _____ C:\WINDOWS\System32\Tasks\Registration 1und1 Task
2016-05-16 21:26 - 2016-05-16 21:26 - 00000000 ____D C:\Users\clara\AppData\LocalLow\1&1 Mail & Media GmbH
2016-05-16 21:26 - 2016-05-16 21:26 - 00000000 ____D C:\ProgramData\UUdb
2016-05-16 21:26 - 2016-05-16 21:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-05-16 21:26 - 2016-05-16 21:26 - 00000000 ____D C:\Program Files\7-Zip
2016-05-16 21:26 - 2016-05-16 21:26 - 00000000 ____D C:\Program Files (x86)\1und1Softwareaktualisierung
2016-05-16 21:25 - 2016-06-06 14:53 - 00002142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp.lnk
2016-05-16 21:25 - 2016-06-01 15:12 - 00053008 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\TURegOpt.exe
2016-05-16 21:25 - 2016-05-16 21:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GMX MailCheck
2016-05-16 21:25 - 2016-05-16 21:25 - 00000000 ____D C:\ProgramData\1&1 Mail & Media GmbH
2016-05-16 21:25 - 2016-05-16 21:25 - 00000000 ____D C:\Program Files\GMX MailCheck
2016-05-16 21:25 - 2016-05-16 21:25 - 00000000 ____D C:\Program Files (x86)\GMX MailCheck
2016-05-16 20:44 - 2016-05-16 20:44 - 00000000 ____D C:\Users\clara\AppData\Local\Downloaded Installations
2016-05-16 20:44 - 2016-05-16 20:44 - 00000000 ____D C:\Program Files (x86)\Chip Digital GmbH
2016-05-16 20:27 - 2016-05-16 20:27 - 01475080 _____ C:\Users\clara\Downloads\DirectX - CHIP-Installer.exe
2016-05-16 20:16 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2016-05-16 20:14 - 2016-05-16 20:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iClone 6
2016-05-16 20:07 - 2016-05-16 20:10 - 00000000 ____D C:\Users\Public\Documents\Reallusion
2016-05-16 20:06 - 2016-05-16 20:06 - 00000000 ____D C:\Program Files\Reallusion
2016-05-16 19:29 - 2016-05-16 19:29 - 00000000 ____D C:\Users\clara\Downloads\IC4Std_manual_DE
2016-05-16 19:25 - 2016-05-16 19:27 - 18681558 _____ C:\Users\clara\Downloads\IC4Std_manual_DE.zip
2016-05-16 19:16 - 2016-05-16 20:03 - 634167856 _____ C:\Users\clara\Downloads\iclone_deu_trial.exe
2016-05-16 14:17 - 2016-05-16 14:18 - 295483820 _____ C:\Users\clara\Documents\Fotorahmen.xcf
2016-05-15 23:56 - 2016-05-16 00:32 - 306617416 _____ (Acresso Software Inc. ) C:\Users\clara\Downloads\CTA_Std_Deu.exe
2016-05-15 20:05 - 2016-05-15 20:05 - 00002870 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-05-15 20:04 - 2016-06-06 14:53 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-05-15 20:04 - 2016-05-15 20:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-05-15 20:04 - 2016-05-15 20:04 - 00000000 ____D C:\Program Files\CCleaner
2016-05-15 20:02 - 2016-05-15 20:02 - 05643176 _____ (Piriform Ltd) C:\Users\clara\Downloads\ccsetup517_slim.exe
2016-05-15 19:57 - 2016-05-15 20:04 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-05-15 19:57 - 2016-05-15 19:57 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\clara\Downloads\revosetup95.exe
2016-05-15 19:57 - 2016-05-15 19:57 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\clara\Downloads\revosetup95 (1).exe
2016-05-14 22:20 - 2016-05-14 22:23 - 00000000 ____D C:\Users\clara\AppData\Roaming\InfraRecorder
2016-05-14 22:14 - 2016-05-14 22:14 - 01475080 _____ C:\Users\clara\Downloads\InfraRecorder 64 Bit - CHIP-Installer.exe
2016-05-13 19:18 - 2016-05-13 19:18 - 00000000 ____D C:\MyAudio
2016-05-13 19:09 - 2016-06-06 14:53 - 00001248 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk
2016-05-13 19:09 - 2016-05-13 19:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2016-05-13 18:48 - 2016-05-13 18:49 - 00000000 ____D C:\Users\clara\AppData\Roaming\WikiZ
2016-05-13 18:48 - 2016-05-13 18:49 - 00000000 ____D C:\Users\clara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WikiZ
2016-05-13 18:48 - 2016-05-13 18:49 - 00000000 ____D C:\8e6b9c2ddbcf1d9c5424ba7c4d70e4
2016-05-13 18:48 - 2016-05-13 18:48 - 00000000 ____T C:\WINDOWS\system32\mfsA0C5.tmp
2016-05-13 18:48 - 2016-05-13 18:48 - 00000000 ____D C:\Users\clara\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-05-13 18:47 - 2016-05-22 01:02 - 00000000 ____D C:\Program Files (x86)\Deratain
2016-05-13 18:47 - 2016-05-13 18:47 - 00000000 ____D C:\Program Files (x86)\Venakstunory
2016-05-13 18:47 - 2016-05-13 18:47 - 00000000 ____D C:\Program Files (x86)\Kibasstrsh
2016-05-13 18:45 - 2016-05-13 18:45 - 00000000 ____D C:\Users\clara\AppData\Roaming\Brotsoft
2016-05-13 18:42 - 2016-05-13 18:45 - 00000000 ____D C:\WINDOWS\system32\SSL
2016-05-13 18:40 - 2016-06-06 14:53 - 00001185 _____ C:\Users\Public\Desktop\AoA Audio Extractor.lnk
2016-05-13 18:40 - 2016-05-13 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AoA Audio Extractor
2016-05-13 18:40 - 2016-05-13 19:18 - 00000000 ____D C:\Program Files (x86)\AoA Audio Extractor
2016-05-13 18:40 - 2007-05-13 12:24 - 00086683 _____ (Open Source Software community project) C:\WINDOWS\SysWOW64\pthreadGC2.dll
2016-05-13 18:39 - 2016-05-13 18:40 - 00000000 ____D C:\Users\clara\AppData\Roaming\ProductData
2016-05-13 18:39 - 2016-05-13 18:40 - 00000000 ____D C:\Users\clara\AppData\LocalLow\IObit
2016-05-13 18:38 - 2016-05-13 18:38 - 08368579 _____ (AoAMedia.com ) C:\Users\clara\Downloads\audioextractor.exe
2016-05-13 18:38 - 2016-05-13 18:38 - 00000000 ____D C:\WINDOWS\Tasks\ImCleanDisabled
2016-05-13 18:37 - 2016-06-08 13:06 - 00000000 ____D C:\ProgramData\ProductData
2016-05-13 18:37 - 2016-05-13 19:10 - 00000000 ____D C:\ProgramData\IObit
2016-05-13 18:35 - 2016-05-14 17:09 - 00000000 ____D C:\Program Files (x86)\IObit
2016-05-13 18:34 - 2016-05-13 19:10 - 00000000 ____D C:\Users\clara\AppData\Roaming\IObit
2016-05-13 17:19 - 2016-05-13 17:20 - 00000000 ____D C:\Users\clara\AppData\Roaming\dvdcss
2016-05-13 17:04 - 2016-05-13 17:07 - 00000000 ____D C:\Users\clara\Documents\VirtualDub-1.10.4-AMD64
2016-05-13 16:59 - 2016-05-13 17:31 - 00000000 ____D C:\Users\clara\Documents\X-WinFF_1.5.4_rev6
2016-05-13 16:57 - 2016-05-13 16:58 - 27936399 _____ C:\Users\clara\Downloads\X-WinFF_1.5.4_rev6.zip
2016-05-13 15:04 - 2016-05-13 15:04 - 02209528 _____ C:\Users\clara\Downloads\VirtualDub-1.10.4-AMD64.zip
2016-05-13 15:02 - 2016-05-13 15:03 - 01475080 _____ C:\Users\clara\Downloads\VirtualDub 64 Bit - CHIP-Installer.exe
2016-05-13 01:45 - 2016-05-13 01:45 - 00000408 _____ C:\Users\clara\AppData\Roaming\CamShapes.ini
2016-05-13 01:45 - 2016-05-13 01:45 - 00000408 _____ C:\Users\clara\AppData\Roaming\CamLayout.ini
2016-05-13 01:45 - 2016-05-13 01:45 - 00000075 _____ C:\Users\clara\AppData\Roaming\Camdata.ini
2016-05-13 01:43 - 2016-06-06 14:53 - 00000958 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-05-13 01:43 - 2016-05-17 19:57 - 00000000 ____D C:\Users\clara\AppData\Roaming\vlc
2016-05-13 01:43 - 2016-05-13 01:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-05-13 01:42 - 2016-05-13 01:42 - 00000000 ____D C:\Program Files\VideoLAN
2016-05-13 01:36 - 2016-05-13 01:36 - 00002904 _____ C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance
2016-05-13 01:31 - 2016-05-13 01:32 - 31710248 _____ C:\Users\clara\Downloads\vlc-2.2.3-win64.exe
2016-05-13 01:29 - 2016-06-06 14:53 - 00000876 _____ C:\Users\Public\Desktop\AVG.lnk
2016-05-13 01:29 - 2016-05-16 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2016-05-13 01:26 - 2016-05-13 01:31 - 00000000 ____D C:\ProgramData\Avg
2016-05-13 01:26 - 2016-05-13 01:31 - 00000000 ____D C:\Program Files (x86)\AVG
2016-05-13 01:25 - 2016-05-16 21:25 - 00000000 ____D C:\Users\clara\AppData\Local\AvgSetupLog
2016-05-13 01:25 - 2016-05-13 01:31 - 00000000 ____D C:\Users\clara\AppData\Local\Avg
2016-05-13 01:02 - 2016-06-06 14:53 - 00001451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2016-05-13 01:02 - 2016-06-06 14:53 - 00001382 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2016-05-13 01:02 - 2016-05-13 01:02 - 00000000 ____D C:\WINDOWS\de
2016-05-13 01:01 - 2016-05-13 01:01 - 00000000 ____D C:\WINDOWS\PCHEALTH
2016-05-13 01:01 - 2016-05-13 01:01 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-05-13 01:00 - 2016-05-15 20:14 - 00000000 ____D C:\Program Files (x86)\Windows Live
2016-05-13 01:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2016-05-13 01:00 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2016-05-13 01:00 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2016-05-13 01:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2016-05-13 01:00 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2016-05-13 01:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2016-05-13 01:00 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2016-05-13 01:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2016-05-13 01:00 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2016-05-13 01:00 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2016-05-13 01:00 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2016-05-13 01:00 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2016-05-13 00:58 - 2016-05-17 19:59 - 00000000 ____D C:\Users\clara\AppData\Local\Windows Live
2016-05-13 00:54 - 2016-05-13 00:58 - 142182064 _____ (Microsoft Corporation) C:\Users\clara\Downloads\wlsetup3528-all.exe
2016-05-12 23:32 - 2016-05-12 23:32 - 00000045 _____ C:\Users\clara\AppData\Roaming\WB.CFG
2016-05-12 23:01 - 2016-05-12 23:02 - 17145008 _____ (APOWERSOFT LIMITED ) C:\Users\clara\Downloads\apowersoft-screen-recorder-pro (1).exe
2016-05-12 22:51 - 2016-05-12 22:51 - 00000000 ____D C:\Users\clara\Documents\Apowersoft
2016-05-12 22:50 - 2016-05-12 22:50 - 00000000 ____D C:\Users\clara\AppData\Roaming\Apowersoft
2016-05-12 22:48 - 2016-05-12 22:49 - 01475080 _____ C:\Users\clara\Downloads\Screen Recorder - CHIP-Installer.exe
2016-05-12 22:47 - 2016-05-12 22:47 - 17145008 _____ (APOWERSOFT LIMITED ) C:\Users\clara\Downloads\apowersoft-screen-recorder-pro.exe
2016-05-12 22:40 - 2016-05-12 22:40 - 00000000 ____D C:\Users\clara\AppData\Local\WinZip Computing, S.L
2016-05-12 22:40 - 2016-05-12 22:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-05-12 22:39 - 2016-06-06 14:53 - 00002175 _____ C:\Users\Public\Desktop\WinZip.lnk
2016-05-12 22:39 - 2016-06-06 14:52 - 00002187 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2016-05-12 22:39 - 2016-05-13 15:50 - 00000000 ____D C:\Users\clara\AppData\Local\WinZip
2016-05-12 22:39 - 2016-05-12 22:39 - 00004536 _____ C:\Users\clara\AppData\Roaming\CamStudio.cfg
2016-05-12 22:39 - 2016-05-12 22:39 - 00000000 ____D C:\ProgramData\WinZip
2016-05-12 22:39 - 2016-05-12 22:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2016-05-12 22:39 - 2016-05-12 22:39 - 00000000 ____D C:\Program Files\WinZip
2016-05-12 22:37 - 2016-05-12 22:37 - 00000000 ____D C:\Users\clara\AppData\Roaming\Dropbox
2016-05-12 22:35 - 2016-05-12 22:35 - 00000000 ____D C:\Users\clara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium
2016-05-12 22:35 - 2016-05-12 22:35 - 00000000 ____D C:\Users\clara\AppData\Local\Chromium
2016-05-12 22:32 - 2016-05-13 13:32 - 00000302 _____ C:\WINDOWS\Tasks\{01D2C66B-959A-B26C-CBB3-2D2859F99FFC}.job
2016-05-12 22:32 - 2016-05-12 22:38 - 00000000 ____D C:\Users\clara\Documents\My CamStudio Temp Files
2016-05-12 22:32 - 2016-05-12 22:37 - 00000000 ____D C:\Users\clara\Documents\My CamStudio Videos
2016-05-12 22:32 - 2016-05-12 22:32 - 00002842 _____ C:\WINDOWS\System32\Tasks\{01D2C66B-959A-B26C-CBB3-2D2859F99FFC}
2016-05-12 22:31 - 2016-06-06 14:43 - 00000306 __RSH C:\ProgramData\ntuser.pol
2016-05-12 22:31 - 2016-05-13 01:36 - 00001244 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-05-12 22:31 - 2016-05-12 22:41 - 00000000 ____D C:\Users\clara\AppData\Local\Dropbox
2016-05-12 22:31 - 2016-05-12 22:40 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-05-12 22:31 - 2016-05-12 22:36 - 00001240 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-05-12 22:31 - 2016-05-12 22:31 - 00004304 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2016-05-12 22:31 - 2016-05-12 22:31 - 00004072 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2016-05-12 22:31 - 2016-05-12 22:31 - 00003574 _____ C:\WINDOWS\System32\Tasks\Dropbox 1D
2016-05-12 22:31 - 2016-05-12 22:31 - 00000096 _____ C:\Users\clara\AppData\Roaming\version2.xml
2016-05-12 22:31 - 2016-05-12 22:31 - 00000000 ____D C:\ProgramData\Dropbox
2016-05-12 22:12 - 2016-06-06 14:53 - 00001058 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skillstraining_2.0.lnk
2016-05-12 22:12 - 2016-06-06 14:53 - 00001040 _____ C:\Users\Public\Desktop\Skillstraining_2.0.lnk
2016-05-12 22:12 - 2016-05-12 22:12 - 00000000 ____D C:\Users\clara\AppData\Roaming\com.mmm.app.schattauer.skillstraining2
2016-05-12 22:11 - 2016-05-12 22:12 - 00000000 ____D C:\Program Files (x86)\Skillstraining_2.0
2016-05-12 21:56 - 2016-05-12 21:56 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-05-12 21:56 - 2016-05-12 21:56 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-05-12 21:56 - 2016-05-12 21:56 - 00000000 ____D C:\Users\clara\AppData\Local\Adobe
2016-05-12 21:56 - 2016-05-12 21:56 - 00000000 ____D C:\ProgramData\Adobe
2016-05-12 21:56 - 2016-05-12 21:56 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-05-12 21:55 - 2016-05-12 21:56 - 18681728 _____ (Adobe Systems Inc.) C:\Users\clara\Downloads\AdobeAIRInstaller.exe
2016-05-12 20:04 - 2016-05-12 20:04 - 00003158 _____ C:\WINDOWS\System32\Tasks\{412D223D-FBC6-4A3A-B1C5-C78B273D33D0}
2016-05-11 21:23 - 2016-05-11 21:23 - 00023281 _____ C:\Users\clara\Downloads\Abiturtermine_2016.pdf
2016-05-11 17:20 - 2016-05-11 20:50 - 00023749 _____ C:\Users\clara\Documents\Fotobuch.pbf
2016-05-11 17:20 - 2016-05-11 17:35 - 00000000 ____D C:\Users\clara\Documents\Fotobuch-Dateien
2016-05-11 16:26 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
2016-05-11 16:25 - 2016-05-11 16:25 - 00000000 ____D C:\Users\clara\AppData\Local\posterXXL Designer
2016-05-11 16:24 - 2016-06-06 14:53 - 00001136 _____ C:\Users\Public\Desktop\posterXXL Designer.lnk
2016-05-11 16:24 - 2016-05-11 16:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\posterXXL Designer
2016-05-11 16:21 - 2016-05-11 16:21 - 00000000 ____D C:\ProgramData\posterXXL Designer
2016-05-11 16:20 - 2016-05-11 16:23 - 00000000 ____D C:\Program Files (x86)\posterXXL Designer
2016-05-11 16:18 - 2016-05-11 16:40 - 00000000 ____D C:\ProgramData\tmp
2016-05-11 16:17 - 2016-06-06 14:53 - 00001118 _____ C:\Users\Public\Desktop\Mein CEWE FOTOBUCH.lnk
2016-05-11 16:17 - 2016-06-06 14:53 - 00001098 _____ C:\Users\Public\Desktop\CEWE FOTOSCHAU.lnk
2016-05-11 16:17 - 2016-05-11 16:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mein CEWE FOTOBUCH
2016-05-11 16:17 - 2016-05-11 16:17 - 00000000 ____D C:\ProgramData\hps
2016-05-11 15:46 - 2016-05-11 15:52 - 175300946 _____ C:\Users\clara\Downloads\posterXXL (1).zip
2016-05-11 15:46 - 2016-05-11 15:46 - 00000000 ____D C:\Program Files\CEWE
2016-05-11 15:45 - 2016-05-11 16:17 - 175300946 _____ C:\Users\clara\Downloads\posterXXL.zip
2016-05-11 15:44 - 2016-05-11 15:45 - 01632600 _____ C:\Users\clara\Downloads\setup_Mein_CEWE_FOTOBUCH.exe
2016-05-11 15:35 - 2016-05-11 15:35 - 00732900 _____ C:\Users\clara\Documents\Anmeldebogen FSJ.pdf
2016-05-11 15:34 - 2016-05-11 15:34 - 00732900 _____ C:\Users\clara\Downloads\pdf-zusammengefasst.pdf
2016-05-11 14:57 - 2016-05-11 14:57 - 00564736 _____ C:\WINDOWS\system32\bitst.exe
2016-05-10 14:57 - 2016-05-10 14:57 - 00037868 _____ C:\Users\clara\Downloads\Ku PUM 2ku3 (1).pdf
2016-05-09 06:26 - 2016-05-09 06:27 - 00000902 _____ C:\Users\clara\Downloads\README.txt
2016-05-09 06:26 - 2016-05-09 06:20 - 00006494 _____ C:\Users\clara\Downloads\Edge Adblock.bat
2016-05-09 06:26 - 2016-05-09 02:16 - 00018387 _____ C:\Users\clara\Downloads\LICENSE.txt
2016-05-09 06:26 - 2016-05-09 02:16 - 00000298 _____ C:\Users\clara\Downloads\regenable.reg
2016-05-09 06:26 - 2016-05-09 02:16 - 00000272 _____ C:\Users\clara\Downloads\regdisable.reg
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-06-08 16:23 - 2016-03-24 23:19 - 00000000 ____D C:\Users\clara\AppData\Roaming\Skype
2016-06-08 14:43 - 2016-02-13 18:59 - 00782086 _____ C:\WINDOWS\system32\perfh007.dat
2016-06-08 14:43 - 2016-02-13 18:59 - 00160170 _____ C:\WINDOWS\system32\perfc007.dat
2016-06-08 14:43 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-06-08 14:43 - 2015-07-25 19:00 - 01802588 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-08 13:10 - 2016-04-14 18:35 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-06-08 13:10 - 2016-03-24 22:43 - 00000000 __SHD C:\Users\clara\IntelGraphicsProfiles
2016-06-07 19:38 - 2016-03-29 21:33 - 00000000 ____D C:\Users\clara\AppData\Local\gtk-2.0
2016-06-07 19:38 - 2016-02-17 16:03 - 00000000 ____D C:\Users\clara\.gimp-2.8
2016-06-06 14:53 - 2016-04-30 22:24 - 00001371 _____ C:\Users\Public\Desktop\ZoomBrowser EX.lnk
2016-06-06 14:53 - 2016-04-30 22:21 - 00001172 _____ C:\Users\Public\Desktop\Picture Style Editor.lnk
2016-06-06 14:53 - 2016-04-30 22:20 - 00001142 _____ C:\Users\Public\Desktop\EOS Utility.lnk
2016-06-06 14:53 - 2016-04-30 22:19 - 00001207 _____ C:\Users\Public\Desktop\Digital Photo Professional.lnk
2016-06-06 14:53 - 2016-04-14 18:41 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-06-06 14:53 - 2016-04-12 18:17 - 00002512 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-06 14:53 - 2016-04-12 18:17 - 00002494 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-06-06 14:53 - 2016-04-05 19:57 - 00001126 _____ C:\Users\Public\Desktop\OpenOffice 4.1.2.lnk
2016-06-06 14:53 - 2016-04-02 22:15 - 00001922 _____ C:\Users\Public\Desktop\GeoGebra.lnk
2016-06-06 14:53 - 2016-03-27 23:15 - 00000987 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2016-06-06 14:53 - 2016-03-24 23:16 - 00001209 _____ C:\Users\Public\Desktop\Avira Launcher.lnk
2016-06-06 14:53 - 2016-02-17 12:56 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk
2016-06-06 14:53 - 2015-08-03 18:37 - 00001756 _____ C:\Users\Public\Desktop\Support Information.lnk
2016-06-06 14:53 - 2015-08-03 17:24 - 00000724 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2016-06-06 14:53 - 2015-08-03 17:13 - 00002057 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk
2016-06-06 14:53 - 2015-08-03 17:11 - 00001451 _____ C:\Users\Public\Desktop\CyberLink Media Suite.lnk
2016-06-06 14:52 - 2016-03-24 22:48 - 00002391 _____ C:\Users\clara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-06-06 14:52 - 2016-03-24 22:32 - 00002031 _____ C:\Users\clara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\McAfee LiveSafe - Internet Security.lnk
2016-06-06 14:51 - 2016-04-12 18:15 - 00001108 _____ C:\Users\clara\Desktop\PhotoScape.lnk
2016-06-06 14:51 - 2016-02-18 22:45 - 00001892 _____ C:\Users\clara\Desktop\Start Tor Browser.lnk
2016-06-05 17:24 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\Registration
2016-06-05 14:54 - 2015-10-30 09:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-06-05 14:54 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-06-05 14:54 - 2015-08-03 18:06 - 00000000 ____D C:\ProgramData\McAfee
2016-06-05 14:53 - 2016-04-13 20:55 - 00000000 ____D C:\ProgramData\Intel Security
2016-06-05 14:53 - 2016-03-25 06:37 - 00000000 ____D C:\Users\Default.migrated
2016-06-05 14:52 - 2016-03-25 18:04 - 00000000 ____D C:\Program Files\Common Files\AV
2016-06-03 19:46 - 2016-02-13 19:25 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-06-03 19:45 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-06-03 18:06 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-05-29 23:17 - 2015-08-03 18:06 - 00000000 ____D C:\Program Files\Common Files\McAfee
2016-05-27 13:54 - 2016-03-24 23:19 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-05-27 13:54 - 2016-03-24 23:19 - 00000000 ____D C:\ProgramData\Skype
2016-05-26 21:42 - 2016-04-14 18:37 - 00000000 ____D C:\Users\clara
2016-05-26 21:33 - 2016-04-12 18:15 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-26 21:33 - 2016-02-13 19:30 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-05-26 21:05 - 2016-04-12 18:15 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-23 16:01 - 2016-04-12 18:15 - 00003996 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-23 16:00 - 2016-04-12 18:15 - 00003764 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-20 14:32 - 2016-02-16 21:16 - 00000000 ___RD C:\Users\clara\OneDrive
2016-05-18 00:43 - 2016-03-25 18:36 - 00000000 ____D C:\Users\clara\AppData\Roaming\Mozilla
2016-05-16 20:16 - 2015-08-03 17:09 - 00000000 ____D C:\ProgramData\Package Cache
2016-05-16 20:06 - 2015-07-25 19:19 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-05-16 00:02 - 2016-02-17 19:46 - 00000000 ____D C:\Users\clara\.thumbnails
2016-05-15 20:08 - 2016-03-24 22:43 - 00000000 ____D C:\Users\clara\AppData\Local\Packages
2016-05-15 20:08 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-05-14 22:01 - 2015-07-25 19:15 - 00000000 ____D C:\ProgramData\Temp
2016-05-13 13:49 - 2016-03-24 23:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-05-13 01:31 - 2016-03-24 22:53 - 00000000 ____D C:\ProgramData\TuneUp Software
2016-05-13 01:07 - 2016-02-17 12:57 - 00000000 ____D C:\Users\clara\Tracing
2016-05-13 01:01 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-05-12 22:31 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-05-12 22:31 - 2015-07-10 13:04 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-05-12 21:56 - 2016-03-24 22:43 - 00000000 ____D C:\Users\clara\AppData\Roaming\Adobe
2016-05-11 20:04 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-05-10 20:35 - 2016-03-24 23:08 - 00146712 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2016-05-10 20:35 - 2016-03-24 23:08 - 00078208 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2016-05-13 01:45 - 2016-05-13 01:45 - 0000075 _____ () C:\Users\clara\AppData\Roaming\Camdata.ini
2016-05-13 01:45 - 2016-05-13 01:45 - 0000408 _____ () C:\Users\clara\AppData\Roaming\CamLayout.ini
2016-05-13 01:45 - 2016-05-13 01:45 - 0000408 _____ () C:\Users\clara\AppData\Roaming\CamShapes.ini
2016-05-12 22:39 - 2016-05-12 22:39 - 0004536 _____ () C:\Users\clara\AppData\Roaming\CamStudio.cfg
2016-05-12 22:31 - 2016-05-12 22:31 - 0000096 _____ () C:\Users\clara\AppData\Roaming\version2.xml
2016-05-12 23:32 - 2016-05-12 23:32 - 0000045 _____ () C:\Users\clara\AppData\Roaming\WB.CFG
2016-06-07 19:38 - 2016-06-07 19:38 - 0025475 _____ () C:\Users\clara\AppData\Local\recently-used.xbel
2016-04-14 18:34 - 2016-04-14 18:34 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-08-03 17:11 - 2015-08-03 17:11 - 0000119 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log
2015-08-03 17:08 - 2015-08-03 17:09 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log
2015-08-03 17:09 - 2015-08-03 17:10 - 0000108 _____ () C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log
2015-08-03 17:08 - 2015-08-03 17:08 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2015-08-03 17:09 - 2015-08-03 17:09 - 0000110 _____ () C:\ProgramData\{E3D04529-6EDB-11D8-A372-0050BAE317E1}.log
Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Windows\Tasks\{01D2C66B-959A-B26C-CBB3-2D2859F99FFC}.job
Einige Dateien in TEMP:
====================
C:\Users\Bereich2\AppData\Local\Temp\avgnt.exe
C:\Users\clara\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2016-04-24 22:28
==================== Ende von FRST.txt ============================ |