Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 12-01-2017
durchgeführt von Fabsn (13-01-2017 14:16:09) Run:1
Gestartet von C:\Users\Fabsn\Desktop
Geladene Profile: Fabsn (Verfügbare Profile: Albert & Sandra & Fabsn)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
start
CloseProcesses:
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2017-01-07]
C:\TOSTACK
Folder: C:\WINDOWS\system32\sstmp
Folder: C:\WINDOWS\SysWOW64\sstmp
File: C:\WINDOWS\rsrcs.dll
Unlock: C:\WINDOWS\system32\Drivers\etc\hosts
C:\WINDOWS\system32\Drivers\etc\hosts
Hosts:
RemoveProxy:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
EmptyTemp:
end
*****************
Prozess erfolgreich geschlossen.
C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js => erfolgreich verschoben
C:\TOSTACK => erfolgreich verschoben
========================= Folder: C:\WINDOWS\system32\sstmp ========================
====== Ende von Folder: ======
========================= Folder: C:\WINDOWS\SysWOW64\sstmp ========================
====== Ende von Folder: ======
========================= File: C:\WINDOWS\rsrcs.dll ========================
Datei ist nicht signiert
MD5: AA6B2587095984518F7D32D4859A585C
Erstellungs- und Änderungsdatum: 2017-01-07 19:01 - 2017-01-08 20:53
Größe: 0187904
Attribute: ----A
Firmenname:
Interne Name:
Original Name:
Produkt:
Beschreibung:
Datei Version: 1.0.1.2
Produkt Version: 1.0.1.2
Urheberrecht:
====== Ende von File: ======
"C:\WINDOWS\system32\Drivers\etc\hosts" => wurde entsperrt
C:\WINDOWS\system32\Drivers\etc\hosts => erfolgreich verschoben
Hosts erfolgreich wiederhergestellt.
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
HKU\S-1-5-21-408302080-641097058-262151635-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-408302080-641097058-262151635-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
========= Ende von RemoveProxy: =========
========= ipconfig /flushdns =========
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
========= Ende von CMD: =========
========= netsh winsock reset =========
Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.
========= Ende von CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 313119 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18166791 B
Java, Flash, Steam htmlcache => 1008 B
Windows/system/drivers => 502146 B
Edge => 0 B
Chrome => 0 B
Firefox => 17021420 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 37506 B
NetworkService => 21928 B
TEMP => 25655680 B
Albert => 1721009837 B
Sandra => 25816126 B
Fabsn => 86897877 B
RecycleBin => 0 B
EmptyTemp: => 1.8 GB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 14:16:32 ====
Code:
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 12-01-2017
durchgeführt von Fabsn (13-01-2017 14:16:09) Run:1
Gestartet von C:\Users\Fabsn\Desktop
Geladene Profile: Fabsn (Verfügbare Profile: Albert & Sandra & Fabsn)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
start
CloseProcesses:
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2017-01-07]
C:\TOSTACK
Folder: C:\WINDOWS\system32\sstmp
Folder: C:\WINDOWS\SysWOW64\sstmp
File: C:\WINDOWS\rsrcs.dll
Unlock: C:\WINDOWS\system32\Drivers\etc\hosts
C:\WINDOWS\system32\Drivers\etc\hosts
Hosts:
RemoveProxy:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
EmptyTemp:
end
*****************
Prozess erfolgreich geschlossen.
C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js => erfolgreich verschoben
C:\TOSTACK => erfolgreich verschoben
========================= Folder: C:\WINDOWS\system32\sstmp ========================
====== Ende von Folder: ======
========================= Folder: C:\WINDOWS\SysWOW64\sstmp ========================
====== Ende von Folder: ======
========================= File: C:\WINDOWS\rsrcs.dll ========================
Datei ist nicht signiert
MD5: AA6B2587095984518F7D32D4859A585C
Erstellungs- und Änderungsdatum: 2017-01-07 19:01 - 2017-01-08 20:53
Größe: 0187904
Attribute: ----A
Firmenname:
Interne Name:
Original Name:
Produkt:
Beschreibung:
Datei Version: 1.0.1.2
Produkt Version: 1.0.1.2
Urheberrecht:
====== Ende von File: ======
"C:\WINDOWS\system32\Drivers\etc\hosts" => wurde entsperrt
C:\WINDOWS\system32\Drivers\etc\hosts => erfolgreich verschoben
Hosts erfolgreich wiederhergestellt.
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
HKU\S-1-5-21-408302080-641097058-262151635-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-408302080-641097058-262151635-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
========= Ende von RemoveProxy: =========
========= ipconfig /flushdns =========
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
========= Ende von CMD: =========
========= netsh winsock reset =========
Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.
========= Ende von CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 313119 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18166791 B
Java, Flash, Steam htmlcache => 1008 B
Windows/system/drivers => 502146 B
Edge => 0 B
Chrome => 0 B
Firefox => 17021420 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 37506 B
NetworkService => 21928 B
TEMP => 25655680 B
Albert => 1721009837 B
Sandra => 25816126 B
Fabsn => 86897877 B
RecycleBin => 0 B
EmptyTemp: => 1.8 GB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 14:16:32 ====
AdwCleaner Logfile:
Code:
# AdwCleaner v6.042 - Bericht erstellt am 13/01/2017 um 14:37:06
# Aktualisiert am 06/01/2017 von Malwarebytes
# Datenbank : 2017-01-11.1 [Server]
# Betriebssystem : Windows 10 Home (X64)
# Benutzername : Fabsn - DESKTOP-G05R34I
# Gestartet von : C:\Users\Fabsn\Desktop\adwcleaner_6.042.exe
# Modus: Löschen
# Unterstützung : https://www.malwarebytes.com/support
***** [ Dienste ] *****
***** [ Ordner ] *****
***** [ Dateien ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Verknüpfungen ] *****
***** [ Aufgabenplanung ] *****
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\HDWallpaper
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cmptch.com
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\static.cmptch.com
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cmptch.com
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\static.cmptch.com
***** [ Browser ] *****
*************************
:: "Tracing" Schlüssel gelöscht
:: Winsock Einstellungen zurückgesetzt
:: "Prefetch" Dateien gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht
:: Hosts-Datei wiederhergestellt
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [5884 Bytes] - [07/01/2017 20:09:15]
C:\AdwCleaner\AdwCleaner[C2].txt - [1376 Bytes] - [07/01/2017 22:35:06]
C:\AdwCleaner\AdwCleaner[C3].txt - [1558 Bytes] - [07/01/2017 22:41:08]
C:\AdwCleaner\AdwCleaner[C4].txt - [1609 Bytes] - [07/01/2017 22:43:51]
C:\AdwCleaner\AdwCleaner[C5].txt - [4255 Bytes] - [08/01/2017 20:58:13]
C:\AdwCleaner\AdwCleaner[C6].txt - [5933 Bytes] - [08/01/2017 21:32:50]
C:\AdwCleaner\AdwCleaner[C7].txt - [1901 Bytes] - [13/01/2017 14:37:06]
C:\AdwCleaner\AdwCleaner[S0].txt - [5577 Bytes] - [07/01/2017 20:05:57]
C:\AdwCleaner\AdwCleaner[S1].txt - [1557 Bytes] - [07/01/2017 22:34:02]
C:\AdwCleaner\AdwCleaner[S2].txt - [1696 Bytes] - [07/01/2017 22:40:49]
C:\AdwCleaner\AdwCleaner[S3].txt - [1865 Bytes] - [07/01/2017 22:43:40]
C:\AdwCleaner\AdwCleaner[S4].txt - [1988 Bytes] - [07/01/2017 22:49:04]
C:\AdwCleaner\AdwCleaner[S5].txt - [4537 Bytes] - [08/01/2017 20:57:20]
C:\AdwCleaner\AdwCleaner[S6].txt - [5767 Bytes] - [08/01/2017 21:31:55]
C:\AdwCleaner\AdwCleaner[S7].txt - [2371 Bytes] - [08/01/2017 21:40:37]
C:\AdwCleaner\AdwCleaner[S8].txt - [2722 Bytes] - [13/01/2017 14:36:38]
########## EOF - C:\AdwCleaner\AdwCleaner[C7].txt - [2631 Bytes] ##########
--- --- ---
[/CODE]
Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 13.01.17
Scan-Zeit: 14:50
Protokolldatei: mbam.txt
Administrator: Ja
-Softwaredaten-
Version: 3.0.5.1299
Komponentenversion: 1.0.43
Version des Aktualisierungspakets: 1.0.1003
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: DESKTOP-G05R34I\Fabsn
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 494502
Abgelaufene Zeit: 3 Min., 34 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswert: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 0
(keine bösartigen Elemente erkannt)
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end)
Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 12-01-2017
durchgeführt von Fabsn (Administrator) auf DESKTOP-G05R34I (13-01-2017 15:01:14)
Gestartet von C:\Users\Fabsn\Desktop
Geladene Profile: Fabsn & (Verfügbare Profile: Albert & Sandra & Fabsn)
Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Chip Digital GmbH) C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe
() C:\Windows\jmesoft\Service.exe
(Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
(Lenovo) C:\Windows\jmesoft\hotkey.exe
() C:\Windows\jmesoft\JME_LOAD.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD12\PDVD12Serv.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13876952 2015-05-20] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-04] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [jmekey] => C:\Windows\jmesoft\hotkey.exe [118784 2013-07-24] (Lenovo)
HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-08-16] ()
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [60408 2016-12-16] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-06] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-408302080-641097058-262151635-1002-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144952915\...\Run: [OneDrive] => C:\Users\TEMP\AppData\Local\Microsoft\OneDrive\OneDrive.exe [1517280 2017-01-11] (Microsoft Corporation) <===== ACHTUNG
HKU\S-1-5-21-408302080-641097058-262151635-1002-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144952915\...\RunOnce: [Uninstall 17.3.6381.0405\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\TEMP\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64" <===== ACHTUNG
HKU\S-1-5-21-408302080-641097058-262151635-1002-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144952915\...\RunOnce: [Uninstall 17.3.6381.0405] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\TEMP\AppData\Local\Microsoft\OneDrive\17.3.6381.0405" <===== ACHTUNG
HKU\S-1-5-21-408302080-641097058-262151635-1002.bak-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144953165\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2876704 2016-12-20] (Valve Corporation)
HKU\S-1-5-21-408302080-641097058-262151635-1002.bak-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144953165\...\MountPoints2: {433a0a15-cb8c-11e6-9bcd-a8a79514f6fe} - "D:\setup.exe"
HKU\S-1-5-21-408302080-641097058-262151635-1004\...\MountPoints2: {433a0a15-cb8c-11e6-9bcd-a8a79514f6fe} - "E:\setup.exe"
HKU\S-1-5-21-408302080-641097058-262151635-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01132017145104530\...\MountPoints2: {433a0a15-cb8c-11e6-9bcd-a8a79514f6fe} - "E:\setup.exe"
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{4a52eac4-57f4-4278-82d1-dbf386785767}: [DhcpNameServer] 172.16.25.22 172.16.25.31
Tcpip\..\Interfaces\{d8e7013b-2396-438e-b7da-ed76903217f7}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
HKU\S-1-5-21-408302080-641097058-262151635-1002-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144952915\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1002-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144952915\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1002-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144952915\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-408302080-641097058-262151635-1002.bak-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144953165\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1002.bak-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144953165\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-408302080-641097058-262151635-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144954087\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144954087\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144954087\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-408302080-641097058-262151635-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-408302080-641097058-262151635-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01132017145104530\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01132017145104530\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-408302080-641097058-262151635-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01132017145104530\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
SearchScopes: HKU\S-1-5-21-408302080-641097058-262151635-1002.bak-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144953165 -> DefaultScope {1977674C-28FE-42F8-8033-85C8EC667C60} URL =
SearchScopes: HKU\S-1-5-21-408302080-641097058-262151635-1002.bak-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01132017144953165 -> {1977674C-28FE-42F8-8033-85C8EC667C60} URL =
SearchScopes: HKU\S-1-5-21-408302080-641097058-262151635-1004 -> DefaultScope {1977674C-28FE-42F8-8033-85C8EC667C60} URL =
SearchScopes: HKU\S-1-5-21-408302080-641097058-262151635-1004 -> {1977674C-28FE-42F8-8033-85C8EC667C60} URL =
SearchScopes: HKU\S-1-5-21-408302080-641097058-262151635-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01132017145104530 -> DefaultScope {1977674C-28FE-42F8-8033-85C8EC667C60} URL =
SearchScopes: HKU\S-1-5-21-408302080-641097058-262151635-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-01132017145104530 -> {1977674C-28FE-42F8-8033-85C8EC667C60} URL =
FireFox:
========
FF DefaultProfile: euh5mdkk.default
FF ProfilePath: C:\Users\Fabsn\AppData\Roaming\Mozilla\Firefox\Profiles\euh5mdkk.default [2017-01-13]
FF Extension: (Strict Pop-up Blocker) - C:\Users\Fabsn\AppData\Roaming\Mozilla\Firefox\Profiles\euh5mdkk.default\Extensions\jid1-P34HaABBBpOerQ@jetpack.xpi [2017-01-09]
FF Extension: (uBlock Origin) - C:\Users\Fabsn\AppData\Roaming\Mozilla\Firefox\Profiles\euh5mdkk.default\Extensions\uBlock0@raymondhill.net.xpi [2017-01-09]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-19] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-06] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-06] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-06] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-06] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272 2016-12-16] (Avira Operations GmbH & Co. KG)
R2 chip1click; C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe [91136 2016-10-27] (Chip Digital GmbH) [Datei ist nicht signiert]
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [62792 2016-12-01] (Lenovo Group Limited)
R2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-08-16] () [Datei ist nicht signiert]
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [271296 2015-07-01] (Lenovo)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-12-26] (Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2180624 2016-12-26] (Electronic Arts)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0309270.inf_amd64_47c09dd18e1ee4c5\atikmdag.sys [28729240 2016-12-07] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0309270.inf_amd64_47c09dd18e1ee4c5\atikmpag.sys [530328 2016-12-07] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [110104 2016-09-28] (Advanced Micro Devices)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [151352 2016-12-06] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [153904 2016-12-06] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [35488 2016-12-06] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [78208 2016-12-06] (Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [28272 2016-12-06] (Avira Operations GmbH & Co. KG)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77416 2016-12-14] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176064 2017-01-13] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [102856 2017-01-13] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-01-13] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [250816 2017-01-13] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [91584 2017-01-13] (Malwarebytes)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3354384 2015-07-10] (Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [895256 2015-06-23] (Realtek )
R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [598784 2015-06-15] (Realtek Semiconductor Corporation)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [411712 2015-05-19] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [6382080 2016-11-11] (Realtek Semiconductor Corporation )
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-01-13 15:01 - 2017-01-13 15:02 - 00016352 _____ C:\Users\Fabsn\Desktop\FRST.txt
2017-01-13 14:57 - 2017-01-13 14:57 - 00001177 _____ C:\Users\Fabsn\Desktop\mbam.txt
2017-01-13 14:50 - 2017-01-13 14:51 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-01-13 14:50 - 2017-01-13 14:50 - 00176064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-01-13 14:50 - 2017-01-13 14:50 - 00102856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-01-13 14:49 - 2017-01-13 14:49 - 00250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-01-13 14:49 - 2017-01-13 14:49 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-01-13 14:49 - 2017-01-13 14:49 - 00001919 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-13 14:49 - 2017-01-13 14:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-13 14:49 - 2017-01-13 14:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-13 14:49 - 2017-01-13 14:49 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-13 14:49 - 2016-12-14 12:55 - 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-01-13 14:48 - 2017-01-13 14:49 - 54199488 _____ (Malwarebytes ) C:\Users\Fabsn\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2017-01-13 14:46 - 2017-01-13 14:46 - 00566128 _____ (Malwarebytes) C:\Users\Fabsn\Desktop\mbam-clean-2.3.0.1001.exe
2017-01-13 14:32 - 2017-01-13 14:32 - 03988944 _____ C:\Users\Fabsn\Desktop\adwcleaner_6.042.exe
2017-01-13 14:16 - 2017-01-13 14:16 - 00003658 _____ C:\Users\Fabsn\Desktop\Fixlog.txt
2017-01-13 14:15 - 2017-01-13 14:15 - 00000000 ____D C:\Users\Fabsn\Desktop\FRST-OlderVersion
2017-01-11 18:23 - 2017-01-11 18:25 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-01-11 16:30 - 2017-01-11 16:30 - 00000000 ____D C:\Users\TEMP\AppData\Local\NetworkTiles
2017-01-11 16:29 - 2017-01-11 16:30 - 00002383 _____ C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-01-11 16:29 - 2017-01-11 16:30 - 00000000 ___RD C:\Users\TEMP\OneDrive
2017-01-11 16:29 - 2017-01-11 16:29 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\Skype
2017-01-11 16:28 - 2017-01-13 14:49 - 00000000 ____D C:\Users\TEMP
2017-01-11 16:28 - 2017-01-11 16:30 - 00000000 ____D C:\Users\TEMP\AppData\Local\Packages
2017-01-11 16:28 - 2017-01-11 16:28 - 00000020 ___SH C:\Users\TEMP\ntuser.ini
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Vorlagen
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Startmenü
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Netzwerkumgebung
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Lokale Einstellungen
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Eigene Dateien
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Druckumgebung
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Documents\Eigene Videos
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Documents\Eigene Musik
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\Documents\Eigene Bilder
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 _SHDL C:\Users\TEMP\AppData\Local\Verlauf
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\Adobe
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 ____D C:\Users\TEMP\AppData\Local\VirtualStore
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 ____D C:\Users\TEMP\AppData\Local\TileDataLayer
2017-01-11 16:28 - 2017-01-11 16:28 - 00000000 ____D C:\Users\TEMP\AppData\Local\Power2Go
2017-01-10 19:38 - 2017-01-10 19:38 - 00000000 ____D C:\Users\Fabsn\AppData\Local\NetworkTiles
2017-01-10 18:42 - 2017-01-10 18:42 - 00000000 ____D C:\Users\Fabsn\Documents\My Games
2017-01-10 17:37 - 2017-01-10 17:37 - 02419200 _____ (Farbar) C:\Users\Fabsn\Downloads\FRST64(1).exe
2017-01-09 19:43 - 2017-01-09 19:43 - 00000000 ____D C:\Users\Fabsn\AppData\Roaming\OpenOffice
2017-01-09 19:42 - 2017-01-09 19:42 - 00000000 ____D C:\Users\Fabsn\Desktop\OpenOffice 4.1.3 (de) Installation Files
2017-01-09 19:40 - 2017-01-09 19:42 - 171330228 _____ C:\Users\Fabsn\Downloads\Apache_OpenOffice_4.1.3_Win_x86_install_de.exe
2017-01-09 18:08 - 2017-01-13 14:14 - 00004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{653ACA43-8FD5-4B1D-A978-F86355A697BB}
2017-01-09 18:08 - 2017-01-09 18:08 - 00000000 ____D C:\Users\Fabsn\AppData\Roaming\Macromedia
2017-01-09 18:07 - 2017-01-09 18:07 - 00000000 ____D C:\Users\Fabsn\AppData\LocalLow\AMD
2017-01-09 17:41 - 2017-01-10 17:40 - 00033957 _____ C:\Users\Fabsn\Downloads\Addition.txt
2017-01-09 17:39 - 2017-01-09 17:40 - 22851472 _____ (Malwarebytes ) C:\Users\Fabsn\Downloads\mbam-setup-2.2.1.1043.exe
2017-01-09 17:37 - 2017-01-13 15:01 - 00000000 ____D C:\FRST
2017-01-09 17:37 - 2017-01-13 14:15 - 02419200 _____ (Farbar) C:\Users\Fabsn\Desktop\FRST64.exe
2017-01-09 17:37 - 2017-01-10 17:40 - 00248978 _____ C:\Users\Fabsn\Downloads\FRST.txt
2017-01-09 17:28 - 2017-01-09 17:28 - 00000000 ____D C:\Users\Fabsn\Documents\FUSSBALL MANAGER 16-17
2017-01-09 17:27 - 2017-01-09 17:27 - 00001715 _____ C:\Users\Fabsn\Desktop\.Manager16-17 -.lnk
2017-01-09 17:27 - 2017-01-09 17:27 - 00000000 ____D C:\Users\Fabsn\AppData\Local\Comms
2017-01-09 17:21 - 2017-01-09 17:21 - 00001728 _____ C:\Users\Fabsn\Desktop\EdManager16-17 -.lnk
2017-01-09 17:13 - 2017-01-09 17:13 - 00000000 ____D C:\Users\Fabsn\AppData\Roaming\LSC
2017-01-09 17:11 - 2017-01-09 17:11 - 00000000 ____D C:\Users\Fabsn\AppData\Roaming\Avira
2017-01-09 17:07 - 2017-01-09 17:08 - 00002386 _____ C:\Users\Fabsn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-01-09 17:07 - 2017-01-09 17:08 - 00000000 ___RD C:\Users\Fabsn\OneDrive
2017-01-09 17:07 - 2017-01-09 17:07 - 00000000 ____D C:\Users\Fabsn\AppData\Roaming\Skype
2017-01-09 17:06 - 2017-01-13 14:58 - 00000000 ____D C:\Users\Fabsn\AppData\LocalLow\Mozilla
2017-01-09 17:06 - 2017-01-09 17:17 - 00000000 ____D C:\Users\Fabsn\AppData\Local\Mozilla
2017-01-09 17:06 - 2017-01-09 17:06 - 00000000 ____D C:\Users\Fabsn\AppData\Roaming\Mozilla
2017-01-09 17:06 - 2017-01-09 17:06 - 00000000 ____D C:\Users\Fabsn\AppData\Local\Power2Go
2017-01-09 17:05 - 2017-01-09 18:08 - 00000000 ____D C:\Users\Fabsn\AppData\Local\Packages
2017-01-09 17:05 - 2017-01-09 17:05 - 00000000 ____D C:\Users\Fabsn\AppData\Roaming\Adobe
2017-01-09 17:05 - 2017-01-09 17:05 - 00000000 ____D C:\Users\Fabsn\AppData\Local\VirtualStore
2017-01-09 17:05 - 2017-01-09 17:05 - 00000000 ____D C:\Users\Fabsn\AppData\Local\TileDataLayer
2017-01-09 17:05 - 2017-01-09 17:05 - 00000000 ____D C:\Users\Fabsn\AppData\Local\Publishers
2017-01-09 17:04 - 2017-01-09 19:50 - 00000000 ____D C:\Users\Fabsn
2017-01-09 17:04 - 2017-01-09 19:03 - 00000000 ____D C:\Users\Fabsn\AppData\Local\ConnectedDevicesPlatform
2017-01-09 17:04 - 2017-01-09 17:04 - 00000020 ___SH C:\Users\Fabsn\ntuser.ini
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Vorlagen
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Startmenü
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Netzwerkumgebung
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Lokale Einstellungen
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Eigene Dateien
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Druckumgebung
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Documents\Eigene Videos
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Documents\Eigene Musik
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Documents\Eigene Bilder
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\AppData\Local\Verlauf
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\AppData\Local\Anwendungsdaten
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 _SHDL C:\Users\Fabsn\Anwendungsdaten
2017-01-09 17:04 - 2017-01-09 17:04 - 00000000 ____D C:\Users\Fabsn\AppData\Local\AMD
2017-01-09 17:00 - 2017-01-09 17:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2017-01-09 17:00 - 2017-01-09 17:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Problem Report Wizard
2017-01-09 17:00 - 2017-01-09 17:00 - 00000000 ____D C:\Program Files (x86)\AMD
2017-01-09 16:58 - 2017-01-09 16:58 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-01-09 16:58 - 2016-09-09 19:25 - 00269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-01-09 16:58 - 2016-09-09 19:25 - 00261920 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-01-09 16:58 - 2016-09-09 19:25 - 00110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-01-09 16:58 - 2016-09-09 19:24 - 00125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-01-09 16:56 - 2017-01-09 16:57 - 00000000 ____D C:\AMD
2017-01-08 21:07 - 2017-01-08 21:07 - 00001086 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2017-01-08 21:07 - 2017-01-08 21:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2017-01-08 21:07 - 2017-01-08 21:07 - 00000000 ____D C:\Program Files\VS Revo Group
2017-01-07 21:38 - 2017-01-08 21:21 - 00000000 ____D C:\Users\Albert\Desktop\Alte Firefox-Daten
2017-01-07 21:38 - 2017-01-08 20:58 - 00001133 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-01-07 21:38 - 2017-01-08 20:58 - 00001121 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-01-07 21:38 - 2017-01-07 21:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-07 20:58 - 2017-01-07 20:58 - 00292184 _____ (Microsoft Corporation) C:\Users\Albert\Downloads\dxwebsetup.exe
2017-01-07 20:58 - 2017-01-07 20:58 - 00000000 ___HD C:\WINDOWS\msdownld.tmp
2017-01-07 20:58 - 2017-01-07 20:58 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2017-01-07 20:51 - 2017-01-07 20:51 - 00000000 ____D C:\Users\Albert\AppData\Local\ElevatedDiagnostics
2017-01-07 20:16 - 2017-01-07 20:41 - 00001311 _____ C:\Users\Albert\Desktop\FIFA Manager 17.lnk
2017-01-07 20:07 - 2017-01-07 20:07 - 00000000 _____ C:\Users\Albert\Downloads\rld(2).exe
2017-01-07 20:02 - 2017-01-13 14:37 - 00000000 ____D C:\AdwCleaner
2017-01-07 20:02 - 2017-01-07 20:02 - 03988944 _____ C:\Users\Albert\Desktop\adwcleaner_6.042.exe
2017-01-07 19:40 - 2017-01-09 17:09 - 00004168 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E0D62842-B9D0-4144-A043-E50AEF06658D}
2017-01-07 19:01 - 2017-01-08 20:53 - 00187904 _____ C:\WINDOWS\rsrcs.dll
2017-01-07 19:00 - 2017-01-07 19:00 - 00594944 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Albert\Downloads\libeay32.dll
2017-01-07 19:00 - 2017-01-07 19:00 - 00152576 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Albert\Downloads\ssleay32.dll
2017-01-07 19:00 - 2017-01-07 19:00 - 00000000 ____D C:\WINDOWS\SysWOW64\sstmp
2017-01-07 19:00 - 2017-01-07 19:00 - 00000000 ____D C:\WINDOWS\system32\sstmp
2017-01-05 16:02 - 2017-01-05 16:04 - 14235880 _____ () C:\Users\Albert\Downloads\fm17_megapatch_datenbank_v1-1(1).exe
2017-01-05 12:30 - 2017-01-05 12:30 - 00031459 _____ C:\Users\Albert\Downloads\Kilometerstandsmeldung_MeinAuto_digital__AS_9828845411_20161227_000000.pdf
2017-01-03 17:31 - 2016-11-11 08:38 - 06382080 _____ (Realtek Semiconductor Corporation ) C:\WINDOWS\system32\Drivers\rtwlane.sys
2017-01-03 17:31 - 2016-11-11 08:38 - 01156096 _____ (Realtek Semiconductor Corp. ) C:\WINDOWS\system32\Rtlihvs.dll
2017-01-03 17:31 - 2016-11-11 04:36 - 00022454 _____ C:\WINDOWS\system32\Drivers\rtldata.txt
2017-01-01 20:25 - 2017-01-01 20:25 - 00001227 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2017-01-01 20:25 - 2017-01-01 20:25 - 00001177 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2017-01-01 20:25 - 2017-01-01 20:25 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Canneverbe Limited
2017-01-01 20:25 - 2017-01-01 20:25 - 00000000 ____D C:\ProgramData\Canneverbe Limited
2017-01-01 20:25 - 2017-01-01 20:25 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP
2017-01-01 20:24 - 2017-01-01 20:25 - 05387352 _____ (Canneverbe Limited ) C:\Users\Albert\Downloads\cdbxp_setup_4.5.7.6452_minimal.exe
2016-12-31 15:11 - 2017-01-09 19:43 - 00039642 _____ C:\Users\Fabsn\Desktop\FMZocker_Calc_V.7.1.2016.12.31.beta.ods
2016-12-31 15:11 - 2017-01-05 16:11 - 00039642 _____ C:\Users\Albert\Desktop\FMZocker_Calc_V.7.1.2016.12.31.beta.ods
2016-12-30 19:35 - 2016-12-30 19:39 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Pro Cycling Manager 2016
2016-12-30 19:35 - 2016-12-30 19:37 - 00000000 ____D C:\Users\Albert\Documents\Pro Cycling Manager 2016
2016-12-30 19:05 - 2016-12-30 19:05 - 00001132 _____ C:\Users\Public\Desktop\OpenOffice 4.1.3.lnk
2016-12-30 19:05 - 2016-12-30 19:05 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.3
2016-12-30 19:05 - 2016-12-30 19:05 - 00000000 ____D C:\Users\Albert\AppData\Roaming\OpenOffice
2016-12-30 19:05 - 2016-12-30 19:05 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2016-12-30 19:03 - 2016-12-30 19:03 - 00000000 ____D C:\Users\Albert\Desktop\OpenOffice 4.1.3 (de) Installation Files
2016-12-30 18:58 - 2016-12-30 18:58 - 00001417 _____ C:\Users\Albert\Desktop\7zFM - Verknüpfung.lnk
2016-12-30 18:58 - 2016-12-30 18:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-12-30 18:58 - 2016-12-30 18:58 - 00000000 ____D C:\Program Files (x86)\7-Zip
2016-12-30 18:57 - 2016-12-30 18:57 - 00305453 _____ C:\Users\Albert\Downloads\Auf-Abwertung-Icons.rar
2016-12-30 18:50 - 2016-12-30 18:50 - 02451354 ____R C:\Users\Albert\Desktop\Ticker.zip
2016-12-30 18:45 - 2016-12-30 18:46 - 14235880 _____ () C:\Users\Albert\Downloads\fm17_megapatch_datenbank_v1-1.exe
2016-12-30 18:35 - 2016-12-30 18:46 - 00000000 ____D C:\Users\Albert\Documents\FUSSBALL MANAGER 16-17
2016-12-30 18:19 - 2017-01-07 20:16 - 00001321 _____ C:\Users\Albert\Desktop\FM17 Editor.lnk
2016-12-30 18:19 - 2017-01-07 20:16 - 00001301 _____ C:\Users\Albert\Desktop\FM17 Auflösung.lnk
2016-12-30 18:13 - 2016-12-30 18:49 - 00000000 ____D C:\Users\Albert\Desktop\FM17
2016-12-30 17:19 - 2016-12-30 17:19 - 00001296 _____ C:\Users\Public\Desktop\FUSSBALL MANAGER 13.lnk
2016-12-30 17:19 - 2016-12-30 17:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FUSSBALL MANAGER 13
2016-12-30 17:19 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2016-12-30 17:19 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2016-12-30 17:19 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2016-12-30 17:19 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2016-12-30 17:19 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2016-12-30 17:19 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2016-12-30 17:19 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2016-12-30 17:19 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2016-12-30 17:19 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
2016-12-30 17:19 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
2016-12-30 17:19 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2016-12-30 17:19 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2016-12-30 17:19 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
2016-12-30 17:19 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2016-12-30 17:19 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
2016-12-30 17:19 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2016-12-30 17:19 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2016-12-30 17:19 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2016-12-30 17:19 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2016-12-30 17:19 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2016-12-30 17:19 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2016-12-30 17:19 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
2016-12-30 17:19 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2016-12-30 17:19 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
2016-12-30 17:19 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
2016-12-30 17:19 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2016-12-30 17:19 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2016-12-30 17:19 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
2016-12-30 17:19 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2016-12-30 17:19 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
2016-12-30 17:19 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2016-12-30 17:19 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
2016-12-30 17:19 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2016-12-30 17:19 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
2016-12-30 17:19 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
2016-12-30 17:19 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
2016-12-30 17:19 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
2016-12-30 17:19 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2016-12-30 17:19 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
2016-12-30 17:19 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
2016-12-30 17:19 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
2016-12-30 17:19 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
2016-12-30 17:19 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2016-12-30 17:19 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2016-12-30 17:19 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2016-12-30 17:19 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2016-12-30 17:19 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2016-12-30 17:19 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2016-12-30 17:19 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
2016-12-30 17:19 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2016-12-30 17:19 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2016-12-30 17:19 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2016-12-30 17:19 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2016-12-30 17:19 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2016-12-30 17:19 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2016-12-30 17:19 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2016-12-30 17:19 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2016-12-30 17:19 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2016-12-30 17:19 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2016-12-30 17:19 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2016-12-30 17:19 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2016-12-30 17:19 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
2016-12-30 17:19 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
2016-12-30 17:19 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2016-12-30 17:19 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2016-12-30 17:19 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
2016-12-30 17:19 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
2016-12-30 17:19 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2016-12-30 17:19 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2016-12-30 17:19 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2016-12-30 17:19 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2016-12-30 17:19 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
2016-12-30 17:19 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2016-12-30 17:19 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
2016-12-30 17:19 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2016-12-30 17:19 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
2016-12-30 17:19 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
2016-12-30 17:19 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2016-12-30 17:19 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2016-12-30 17:19 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
2016-12-30 17:19 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2016-12-30 17:19 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
2016-12-30 17:19 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2016-12-30 17:19 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
2016-12-30 17:19 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2016-12-30 17:19 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
2016-12-30 17:19 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2016-12-30 17:19 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
2016-12-30 17:19 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2016-12-30 17:19 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
2016-12-30 17:19 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2016-12-30 17:19 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
2016-12-30 17:19 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2016-12-30 17:19 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
2016-12-30 17:19 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2016-12-30 17:19 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
2016-12-30 17:19 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2016-12-30 17:19 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
2016-12-30 17:19 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2016-12-30 17:19 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2016-12-30 17:19 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2016-12-30 17:19 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
2016-12-30 17:19 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2016-12-30 17:19 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
2016-12-30 17:19 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2016-12-30 17:19 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
2016-12-30 17:19 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2016-12-30 17:19 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2016-12-30 17:19 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2016-12-30 17:19 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
2016-12-30 17:19 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2016-12-30 17:19 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
2016-12-30 17:19 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2016-12-30 17:19 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
2016-12-30 17:19 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
2016-12-30 17:19 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
2016-12-30 17:19 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2016-12-30 17:19 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
2016-12-30 17:19 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2016-12-30 17:19 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
2016-12-30 17:19 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2016-12-30 17:19 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
2016-12-30 17:19 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2016-12-30 17:19 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
2016-12-30 17:19 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2016-12-30 17:19 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
2016-12-30 17:19 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
2016-12-30 17:19 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
2016-12-30 17:19 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2016-12-30 17:19 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2016-12-30 17:19 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
2016-12-30 17:19 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
2016-12-30 17:19 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
2016-12-30 17:19 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
2016-12-30 17:19 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
2016-12-30 17:19 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
2016-12-30 17:19 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
2016-12-30 17:19 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
2016-12-30 17:19 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
2016-12-30 17:19 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
2016-12-30 17:19 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
2016-12-30 17:19 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
2016-12-30 17:18 - 2016-12-30 19:35 - 00027598 _____ C:\WINDOWS\DirectX.log
2016-12-30 17:18 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
2016-12-30 17:18 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2016-12-30 17:18 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
2016-12-30 17:18 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
2016-12-30 17:18 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
2016-12-30 17:18 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
2016-12-30 17:18 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
2016-12-30 17:18 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
2016-12-30 17:18 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
2016-12-30 17:18 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
2016-12-30 17:18 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
2016-12-30 17:18 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
2016-12-30 17:18 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
2016-12-30 17:18 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
2016-12-30 17:18 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
2016-12-30 17:18 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
2016-12-30 17:18 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
2016-12-30 17:18 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
2016-12-30 17:18 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
2016-12-30 17:18 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
2016-12-30 17:18 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
2016-12-30 17:18 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
2016-12-29 17:45 - 2016-12-29 17:46 - 01181167 _____ C:\Users\Albert\Desktop\20161229_173622.jpg
2016-12-29 17:45 - 2016-12-29 17:37 - 01500665 ____N C:\Users\Albert\Desktop\20161229_173710.jpg
2016-12-29 17:45 - 2016-12-29 17:36 - 01508728 ____N C:\Users\Albert\Desktop\20161229_173649.jpg
2016-12-29 17:44 - 2016-12-29 17:44 - 00000000 ____D C:\Users\Albert\AppData\LocalLow\Adobe
2016-12-29 17:44 - 2016-12-29 17:44 - 00000000 ____D C:\Users\Albert\AppData\Local\Adobe
2016-12-29 17:37 - 2016-12-29 17:37 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-12-29 17:29 - 2016-12-29 17:29 - 00000000 ___RD C:\Users\Albert\Documents\Scanned Documents
2016-12-29 17:29 - 2016-12-29 17:29 - 00000000 ____D C:\Users\Albert\Documents\Fax
2016-12-29 17:26 - 2017-01-11 16:40 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-12-29 17:25 - 2016-12-29 17:49 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-12-29 17:25 - 2016-12-29 17:25 - 00002131 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-12-29 17:25 - 2016-12-29 17:25 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-12-29 17:23 - 2016-12-29 17:48 - 00000000 ____D C:\ProgramData\Adobe
2016-12-29 17:18 - 2016-12-29 17:23 - 95497400 _____ (Adobe Systems Incorporated) C:\Users\Albert\Downloads\AcroRdrDC1502020039_de_DE.exe
2016-12-28 12:43 - 2017-01-08 21:48 - 00014982 ____H C:\Users\Sandra\AppData\Local\IconCache.db
2016-12-28 11:30 - 2016-12-28 12:43 - 00000000 ____D C:\Users\Sandra\AppData\LocalLow\Mozilla
2016-12-28 11:30 - 2016-12-28 11:36 - 00000000 ____D C:\Users\Sandra\AppData\Local\Mozilla
2016-12-28 11:30 - 2016-12-28 11:30 - 00000000 ____D C:\Users\Sandra\AppData\Roaming\Mozilla
2016-12-28 11:25 - 2016-12-28 11:25 - 00000000 ____D C:\Users\Sandra\AppData\Local\Comms
2016-12-28 11:18 - 2016-12-28 11:18 - 00000000 ____D C:\Users\Sandra\AppData\Roaming\LSC
2016-12-28 11:11 - 2016-12-28 11:12 - 00002389 _____ C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-12-28 11:11 - 2016-12-28 11:12 - 00000000 ___RD C:\Users\Sandra\OneDrive
2016-12-28 11:11 - 2016-12-28 11:11 - 00000000 ____D C:\Users\Sandra\AppData\Roaming\Skype
2016-12-28 11:09 - 2016-12-28 11:09 - 00000000 ____D C:\Users\Sandra\AppData\Roaming\ATI
2016-12-28 11:09 - 2016-12-28 11:09 - 00000000 ____D C:\Users\Sandra\AppData\Local\Power2Go
2016-12-28 11:09 - 2016-12-28 11:09 - 00000000 ____D C:\Users\Sandra\AppData\Local\ATI
2016-12-28 11:09 - 2016-12-28 11:09 - 00000000 ____D C:\Users\Sandra\AppData\Local\AMD
2016-12-28 11:08 - 2017-01-13 14:49 - 00000000 ____D C:\Users\Sandra
2016-12-28 11:08 - 2017-01-13 14:16 - 00000000 ____D C:\Users\Sandra\AppData\Local\Temp
2016-12-28 11:08 - 2017-01-08 21:48 - 01048576 ____H C:\Users\Sandra\NTUSER.DAT
2016-12-28 11:08 - 2016-12-28 12:43 - 00524288 ___SH C:\Users\Sandra\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TMContainer00000000000000000002.regtrans-ms
2016-12-28 11:08 - 2016-12-28 12:43 - 00524288 ___SH C:\Users\Sandra\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TMContainer00000000000000000001.regtrans-ms
2016-12-28 11:08 - 2016-12-28 12:43 - 00065536 ___SH C:\Users\Sandra\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TM.blf
2016-12-28 11:08 - 2016-12-28 12:43 - 00000000 ____D C:\Users\Sandra\AppData\Local\Microsoft
2016-12-28 11:08 - 2016-12-28 12:43 - 00000000 ____D C:\Users\Sandra\AppData\Local
2016-12-28 11:08 - 2016-12-28 12:16 - 00000000 ____D C:\Users\Sandra\AppData\Local\Packages
2016-12-28 11:08 - 2016-12-28 11:30 - 00000000 ____D C:\Users\Sandra\AppData\Roaming
2016-12-28 11:08 - 2016-12-28 11:30 - 00000000 ____D C:\Users\Sandra\AppData\LocalLow
2016-12-28 11:08 - 2016-12-28 11:12 - 00000000 ___RD C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
2016-12-28 11:08 - 2016-12-28 11:10 - 00000000 ___SD C:\Users\Sandra\AppData\Roaming\Microsoft
2016-12-28 11:08 - 2016-12-28 11:09 - 00000000 ___RD C:\Users\Sandra\Searches
2016-12-28 11:08 - 2016-12-28 11:09 - 00000000 ___RD C:\Users\Sandra\Pictures
2016-12-28 11:08 - 2016-12-28 11:09 - 00000000 ____D C:\Users\Sandra\AppData\Local\ConnectedDevicesPlatform
2016-12-28 11:08 - 2016-12-28 11:08 - 00634880 ___SH C:\Users\Sandra\ntuser.dat.LOG2
2016-12-28 11:08 - 2016-12-28 11:08 - 00081920 ___SH C:\Users\Sandra\ntuser.dat.LOG1
2016-12-28 11:08 - 2016-12-28 11:08 - 00000402 ___SH C:\Users\Sandra\Documents\desktop.ini
2016-12-28 11:08 - 2016-12-28 11:08 - 00000282 ___SH C:\Users\Sandra\Downloads\desktop.ini
2016-12-28 11:08 - 2016-12-28 11:08 - 00000282 ___SH C:\Users\Sandra\Desktop\desktop.ini
2016-12-28 11:08 - 2016-12-28 11:08 - 00000174 ___SH C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
2016-12-28 11:08 - 2016-12-28 11:08 - 00000174 ___SH C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
2016-12-28 11:08 - 2016-12-28 11:08 - 00000020 ___SH C:\Users\Sandra\ntuser.ini
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Vorlagen
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Startmenü
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\SendTo
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Recent
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Netzwerkumgebung
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Lokale Einstellungen
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Eigene Dateien
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Druckumgebung
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Documents\Eigene Videos
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Documents\Eigene Musik
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Documents\Eigene Bilder
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Cookies
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\AppData\Local\Verlauf
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\AppData\Local\Temporary Internet Files
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\AppData\Local\Anwendungsdaten
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 _SHDL C:\Users\Sandra\Anwendungsdaten
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___SD C:\Users\Sandra\AppData\LocalLow\Microsoft
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Videos
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Saved Games
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Music
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Links
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Favorites
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Downloads
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Documents
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Desktop
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\Contacts
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___RD C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ___HD C:\Users\Sandra\AppData
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ____D C:\Users\Sandra\AppData\Roaming\Adobe
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ____D C:\Users\Sandra\AppData\Local\VirtualStore
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ____D C:\Users\Sandra\AppData\Local\TileDataLayer
2016-12-28 11:08 - 2016-12-28 11:08 - 00000000 ____D C:\Users\Sandra\AppData\Local\Publishers
2016-12-28 11:08 - 2016-12-23 14:24 - 00000000 ___RD C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2016-12-28 11:08 - 2016-12-23 14:24 - 00000000 ___RD C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2016-12-28 11:08 - 2016-07-16 12:47 - 00000000 ___RD C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2016-12-28 11:08 - 2016-07-16 12:47 - 00000000 ____D C:\Users\Sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2016-12-27 20:44 - 2016-12-27 20:45 - 50193077 ____R C:\Users\Albert\Downloads\Demonstrating My Saiya Style - Rise Of The Northstar.zip
2016-12-27 20:39 - 2016-12-27 20:40 - 00000685 _____ C:\WINDOWS\wmsetup.log
2016-12-27 20:37 - 2016-12-27 20:37 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Avira
2016-12-27 20:35 - 2016-12-27 20:35 - 00000222 _____ C:\Users\Albert\Desktop\Pro Cycling Manager 2016.url
2016-12-27 20:35 - 2016-12-27 20:35 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-12-27 20:26 - 2016-12-27 20:26 - 00000000 ____D C:\Users\Albert\AppData\Local\Steam
2016-12-27 20:26 - 2016-12-27 20:26 - 00000000 ____D C:\Users\Albert\AppData\Local\Chromium
2016-12-27 20:26 - 2016-12-27 20:26 - 00000000 ____D C:\Users\Albert\AppData\Local\CEF
2016-12-26 18:24 - 2016-12-30 16:37 - 00000000 ____D C:\Program Files (x86)\Origin Games
2016-12-26 18:22 - 2016-12-30 20:51 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Origin
2016-12-26 18:22 - 2016-12-26 18:22 - 00001065 _____ C:\Users\Public\Desktop\Origin.lnk
2016-12-26 18:22 - 2016-12-26 18:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2016-12-26 18:22 - 2016-12-26 18:22 - 00000000 ____D C:\Program Files (x86)\Origin
2016-12-26 18:20 - 2016-12-30 16:37 - 00000000 ____D C:\ProgramData\Origin
2016-12-26 18:20 - 2016-12-26 18:24 - 00000000 ____D C:\Users\Albert\AppData\Local\Origin
2016-12-26 18:20 - 2016-12-26 18:20 - 00000000 ____D C:\Users\Albert\.QtWebEngineProcess
2016-12-26 18:20 - 2016-12-26 18:20 - 00000000 ____D C:\Users\Albert\.Origin
2016-12-26 18:19 - 2017-01-09 17:04 - 00000000 ____D C:\Program Files (x86)\Steam
2016-12-26 18:19 - 2016-12-26 18:20 - 55364064 _____ (Electronic Arts) C:\Users\Albert\Downloads\OriginThinSetup.exe
2016-12-26 18:19 - 2016-12-26 18:19 - 00001035 _____ C:\Users\Public\Desktop\Steam.lnk
2016-12-26 18:19 - 2016-12-26 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2016-12-26 18:18 - 2016-12-26 18:18 - 01446792 _____ C:\Users\Albert\Downloads\SteamSetup.exe
2016-12-26 18:08 - 2016-12-26 18:08 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2016-12-26 18:07 - 2016-12-06 16:01 - 00153904 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2016-12-26 18:07 - 2016-12-06 16:01 - 00151352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2016-12-26 18:07 - 2016-12-06 16:01 - 00078208 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2016-12-26 18:07 - 2016-12-06 16:01 - 00035488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2016-12-26 18:07 - 2016-12-06 16:01 - 00028272 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2016-12-26 18:04 - 2016-12-26 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-12-26 18:04 - 2016-12-26 18:07 - 00000000 ____D C:\ProgramData\Avira
2016-12-26 18:04 - 2016-12-26 18:07 - 00000000 ____D C:\Program Files (x86)\Avira
2016-12-26 18:04 - 2016-12-26 18:04 - 04608592 _____ (Avira Operations GmbH & Co. KG) C:\Users\Albert\Downloads\avira_de_av_58614d8089a3e__ws.exe
2016-12-26 18:04 - 2016-12-26 18:04 - 00001284 _____ C:\Users\Public\Desktop\Avira Connect.lnk
2016-12-26 18:03 - 2017-01-13 14:53 - 00031971 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2016-12-26 17:55 - 2016-12-26 17:55 - 00001989 _____ C:\Users\Albert\Desktop\SonyEditor.lnk
2016-12-26 17:55 - 2016-12-26 17:55 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SonyEditor
2016-12-26 17:55 - 2016-12-26 17:55 - 00000000 ____D C:\Users\Albert\AppData\Local\Downloaded Installations
2016-12-26 17:55 - 2016-12-26 17:55 - 00000000 ____D C:\Program Files (x86)\SonyEditor
2016-12-26 17:55 - 2016-12-26 17:55 - 00000000 ____D C:\Program Files (x86)\Chip Digital GmbH
2016-12-26 17:50 - 2017-01-08 21:35 - 00000000 ____D C:\Users\Albert\AppData\LocalLow\Mozilla
2016-12-26 17:50 - 2017-01-07 21:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-26 17:50 - 2016-12-26 18:02 - 00000000 ____D C:\Users\Albert\AppData\Local\Mozilla
2016-12-26 17:50 - 2016-12-26 17:50 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Mozilla
2016-12-26 17:50 - 2016-12-26 17:49 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-12-26 17:49 - 2016-12-26 17:49 - 00524288 ___SH C:\Users\Public\NTUSER.DAT{200e5119-cb8a-11e6-9bcc-a8a79514f6fe}.TMContainer00000000000000000002.regtrans-ms
2016-12-26 17:49 - 2016-12-26 17:49 - 00524288 ___SH C:\Users\Public\NTUSER.DAT{200e5119-cb8a-11e6-9bcc-a8a79514f6fe}.TMContainer00000000000000000001.regtrans-ms
2016-12-26 17:49 - 2016-12-26 17:49 - 00524288 ___SH C:\Users\Default.migrated\NTUSER.DAT{200e5115-cb8a-11e6-9bcc-a8a79514f6fe}.TMContainer00000000000000000002.regtrans-ms
2016-12-26 17:49 - 2016-12-26 17:49 - 00524288 ___SH C:\Users\Default.migrated\NTUSER.DAT{200e5115-cb8a-11e6-9bcc-a8a79514f6fe}.TMContainer00000000000000000001.regtrans-ms
2016-12-26 17:49 - 2016-12-26 17:49 - 00243720 _____ C:\Users\Albert\Downloads\Firefox Setup Stub 50.1.0.exe
2016-12-26 17:49 - 2016-12-26 17:49 - 00065536 ___SH C:\Users\Public\NTUSER.DAT{200e5119-cb8a-11e6-9bcc-a8a79514f6fe}.TM.blf
2016-12-26 17:49 - 2016-12-26 17:49 - 00065536 ___SH C:\Users\Default.migrated\NTUSER.DAT{200e5115-cb8a-11e6-9bcc-a8a79514f6fe}.TM.blf
2016-12-26 17:49 - 2016-12-26 17:49 - 00008192 ___SH C:\Users\Public\NTUSER.DAT.LOG1
2016-12-26 17:49 - 2016-12-26 17:49 - 00008192 ___SH C:\Users\Default.migrated\NTUSER.DAT.LOG1
2016-12-26 17:49 - 2016-12-26 17:49 - 00008192 _____ C:\Users\Public\NTUSER.DAT
2016-12-26 17:49 - 2016-12-26 17:49 - 00008192 _____ C:\Users\Default.migrated\NTUSER.DAT
2016-12-26 17:49 - 2016-12-26 17:49 - 00000000 ___SH C:\Users\Public\NTUSER.DAT.LOG2
2016-12-26 17:49 - 2016-12-26 17:49 - 00000000 ___SH C:\Users\Default.migrated\NTUSER.DAT.LOG2
2016-12-23 17:19 - 2017-01-13 14:47 - 00193220 _____ C:\WINDOWS\PFRO.log
2016-12-23 16:12 - 2016-12-26 17:57 - 02365296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WudfUpdate_01011.dll
2016-12-23 16:11 - 2017-01-09 18:22 - 00166162 ____H C:\Users\Albert\AppData\Local\IconCache.db
2016-12-23 14:47 - 2017-01-11 16:30 - 00003292 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2016-12-23 14:47 - 2016-12-23 14:46 - 21628640 _____ (Microsoft Corporation) C:\Users\Albert\Downloads\OneDriveSetup.exe
2016-12-23 14:46 - 2017-01-13 14:16 - 00000000 ____D C:\Users\Albert\AppData\Local\Temp
2016-12-23 14:46 - 2016-12-26 17:48 - 00000000 ____D C:\Users\Albert\AppData\Local\MicrosoftEdge
2016-12-23 14:46 - 2016-12-23 14:46 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Skype
2016-12-23 14:35 - 2016-12-23 14:35 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-12-23 14:34 - 2016-12-23 14:34 - 00000000 ____D C:\Users\Albert\AppData\Local\NetworkTiles
2016-12-23 14:33 - 2016-12-23 14:33 - 00000000 ____D C:\ProgramData\USOShared
2016-12-23 14:32 - 2016-12-23 18:09 - 00000000 ____D C:\Users\Albert\AppData\Local\ConnectedDevicesPlatform
2016-12-23 14:32 - 2016-12-23 14:32 - 00000174 ___SH C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
2016-12-23 14:32 - 2016-12-23 14:32 - 00000020 ___SH C:\Users\Albert\ntuser.ini
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Vorlagen
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Startmenü
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\SendTo
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Recent
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Cookies
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\AppData\Local\Temporary Internet Files
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Temporary Internet Files
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 _SHDL C:\ProgramData\Desktop
2016-12-23 14:32 - 2016-12-23 14:32 - 00000000 ____D C:\Users\Albert\AppData\Local\Comms
2016-12-23 14:31 - 2016-12-23 14:31 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2016-12-23 14:31 - 2016-12-23 14:31 - 00007623 _____ C:\WINDOWS\diagerr.xml
2016-12-23 14:29 - 2016-12-23 14:29 - 00022960 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-12-23 14:28 - 2017-01-13 14:47 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-12-23 14:28 - 2016-12-27 20:27 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2016-12-23 14:28 - 2016-12-23 14:28 - 00002212 _____ C:\WINDOWS\System32\Tasks\PDVDServ12 Task
2016-12-23 14:27 - 2016-12-23 14:31 - 00008101 _____ C:\WINDOWS\comsetup.log
2016-12-23 14:25 - 2017-01-13 14:47 - 2984538112 ___SH C:\hiberfil.sys
2016-12-23 14:24 - 2016-12-23 14:24 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-12-23 14:22 - 2016-12-23 14:24 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-12-23 14:21 - 2017-01-13 14:49 - 00000000 ____D C:\Users\Albert
2016-12-23 14:21 - 2017-01-09 18:22 - 01572864 ____H C:\Users\Albert\NTUSER.DAT
2016-12-23 14:21 - 2017-01-08 21:27 - 00000000 ___RD C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
2016-12-23 14:21 - 2017-01-08 21:27 - 00000000 ____D C:\Users\Albert\AppData\Local
2016-12-23 14:21 - 2017-01-08 20:58 - 00000000 ___RD C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2016-12-23 14:21 - 2017-01-07 19:12 - 00000000 ____D C:\Users\Albert\AppData\Roaming
2016-12-23 14:21 - 2017-01-02 17:42 - 00000000 ____D C:\Users\Albert\AppData\Local\Microsoft
2016-12-23 14:21 - 2016-12-30 20:53 - 00524288 ___SH C:\Users\Albert\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 14:21 - 2016-12-30 20:53 - 00065536 ___SH C:\Users\Albert\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TM.blf
2016-12-23 14:21 - 2016-12-29 17:44 - 00000000 ___SD C:\Users\Albert\AppData\Roaming\Microsoft
2016-12-23 14:21 - 2016-12-23 14:24 - 00524288 ___SH C:\WINDOWS\system32\config\ELAM{1cc41df8-4b1b-11e6-80cc-e41d2d1026d0}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 14:21 - 2016-12-23 14:24 - 00524288 ___SH C:\WINDOWS\system32\config\ELAM{1cc41df8-4b1b-11e6-80cc-e41d2d1026d0}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 14:21 - 2016-12-23 14:24 - 00065536 ___SH C:\WINDOWS\system32\config\ELAM{1cc41df8-4b1b-11e6-80cc-e41d2d1026d0}.TM.blf
2016-12-23 14:21 - 2016-12-23 14:22 - 00000000 ___HD C:\Users\Albert\AppData
2016-12-23 14:21 - 2016-12-23 14:21 - 00524288 ___SH C:\Users\Albert\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 14:21 - 2016-12-23 14:21 - 00053248 ___SH C:\Users\Albert\ntuser.dat.LOG1
2016-12-23 14:21 - 2016-12-23 14:21 - 00008192 ___SH C:\Users\Albert\ntuser.dat.LOG2
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Vorlagen
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Startmenü
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\SendTo
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Recent
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Netzwerkumgebung
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Lokale Einstellungen
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Eigene Dateien
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Druckumgebung
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Documents\Eigene Videos
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Documents\Eigene Musik
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Documents\Eigene Bilder
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Cookies
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\AppData\Local\Verlauf
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\AppData\Local\Temporary Internet Files
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\AppData\Local\Anwendungsdaten
2016-12-23 14:21 - 2016-12-23 14:21 - 00000000 _SHDL C:\Users\Albert\Anwendungsdaten
2016-12-23 14:21 - 2016-07-16 12:48 - 00000000 ___RD C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2016-12-23 14:21 - 2016-07-16 12:47 - 00000000 ___RD C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2016-12-23 14:21 - 2016-07-16 12:47 - 00000000 ___RD C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2016-12-23 14:21 - 2016-07-16 12:47 - 00000000 ____D C:\Users\Albert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2016-12-23 14:20 - 2017-01-12 21:06 - 00524288 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 14:20 - 2017-01-12 21:06 - 00065536 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TM.blf
2016-12-23 14:20 - 2017-01-06 16:31 - 00524288 ___SH C:\WINDOWS\system32\config\COMPONENTS{f8d8b5e2-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 14:18 - 2017-01-13 14:46 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2016-12-23 14:18 - 2017-01-09 17:00 - 00000000 ____D C:\Program Files\AMD
2016-12-23 14:18 - 2016-12-23 14:18 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-12-23 14:18 - 2016-12-23 14:18 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2016-12-23 14:18 - 2016-12-23 14:18 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2016-12-23 14:18 - 2016-12-23 14:18 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2016-12-23 14:17 - 2016-12-23 14:17 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-12-23 14:17 - 2016-12-23 14:17 - 00000000 ____D C:\Program Files\Realtek
2016-12-23 14:17 - 2016-07-16 12:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-12-23 14:16 - 2017-01-13 14:49 - 00067584 ____S C:\WINDOWS\bootstat.dat
2016-12-23 14:15 - 2017-01-12 20:13 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-12-23 14:15 - 2017-01-09 16:58 - 00016530 _____ C:\WINDOWS\setupact.log
2016-12-23 14:15 - 2016-12-23 14:17 - 00000156 _____ C:\WINDOWS\setuperr.log
2016-12-23 14:15 - 2016-12-23 14:15 - 00524288 ___SH C:\Users\Default\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 14:15 - 2016-12-23 14:15 - 00524288 ___SH C:\Users\Default\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 14:15 - 2016-12-23 14:15 - 00065536 ___SH C:\Users\Default\NTUSER.DAT{ab2f3adf-c911-11e6-888b-f6da8e7d0775}.TM.blf
2016-12-23 14:15 - 2016-12-23 14:15 - 00033830 _____ C:\WINDOWS\system32\NetSetupMig.log
2016-12-23 14:15 - 2016-12-23 14:15 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-12-23 14:14 - 2017-01-13 15:01 - 00000000 ____D C:\WINDOWS\Prefetch
2016-12-23 14:14 - 2017-01-01 13:59 - 00223720 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-12-23 14:14 - 2016-12-23 14:20 - 00524288 ___SH C:\WINDOWS\system32\config\DRIVERS{f8d8b5e8-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 14:14 - 2016-12-23 14:20 - 00524288 ___SH C:\WINDOWS\system32\config\DRIVERS{f8d8b5e8-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 14:14 - 2016-12-23 14:20 - 00065536 ___SH C:\WINDOWS\system32\config\DRIVERS{f8d8b5e8-4ba6-11e6-80cd-0026b955b121}.TM.blf
2016-12-23 14:14 - 2016-12-23 14:14 - 00524288 ___SH C:\Users\Default\NTUSER.DAT{f8d8b5f1-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 14:14 - 2016-12-23 14:14 - 00524288 ___SH C:\Users\Default\NTUSER.DAT{f8d8b5f1-4ba6-11e6-80cd-0026b955b121}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 14:14 - 2016-12-23 14:14 - 00065536 ___SH C:\Users\Default\NTUSER.DAT{f8d8b5f1-4ba6-11e6-80cd-0026b955b121}.TM.blf
2016-12-23 14:13 - 2017-01-09 18:23 - 00000000 ___DC C:\WINDOWS\Panther
2016-12-23 14:13 - 2016-07-16 23:49 - 00048862 _____ C:\WINDOWS\SysWOW64\license.rtf
2016-12-23 14:13 - 2016-07-16 23:49 - 00048862 _____ C:\WINDOWS\system32\license.rtf