Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Auf Rechnung im Mailanhang geklickt (Zip + doc) (https://www.trojaner-board.de/177772-rechnung-mailanhang-geklickt-zip-doc.html)

Ikarius 12.04.2016 12:19

Auf Rechnung im Mailanhang geklickt (Zip + doc)
 
Hallo Liebes Forum
Hab mich wohl gerade mit etwas infiziert und möchte es so schnell wie möglich loswerden.
Das ganze war als sehr gute Mail von g2apay/paypal getarnt. Ein Rechtsanwalt wollte angeblich das ich meine offene Zahlung begleiche und die Rechnung sei als Anhang hinzugefügt. In der Mail wurden meine Kompletten Kontaktdaten genannt, weshalb ich dem ganzen mal getraut habe.

Hab jetzt mal noch nichts gemacht, um eure empfohlenen Wege zu gehen.
Hier mal die ersten Logs

FRST:
Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (12-04-2016 12:31:46)
Gestartet von C:\Users\hauptaccount\Downloads
Geladene Profile: hauptaccount &  (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
() C:\Windows\SysWOW64\WinService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Apple Inc.) C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Mozilla Messaging) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Malwarebytes) D:\mbar\mbar.exe
(Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [807392 2016-03-13] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66328 2016-01-27] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [523144 2015-09-07] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [ReCycle Patch] => C:\Users\hauptaccount\Downloads\ReasonPatch(1).exe [184320 2016-02-18] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5361440 2016-02-26] (IObit)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-burden\manchester_authentication.exe [210432 2016-04-12] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-burden\manchester_authentication.exe [210432 2016-04-12] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-burden\manchester_authentication.exe [210432 2016-04-12] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-burden\manchester_authentication.exe [210432 2016-04-12] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: []
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-30] (Microsoft Corporation)
HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  Keine Datei
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Kein Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  Keine Datei
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Kein Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S:
FF DefaultSearchUrl: hxxp://websearch.mocaflix.com/?l=1&q=
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SelectedSearchEngine: Web Search
FF SelectedSearchEngine,S:
FF Homepage: about:home
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome:
=======
CHR HomePage: Default -> hxxp://feed.helperbar.com/?publisher=QuickOC&dpid=QuickOC&co=DE&userid=35e67f97-7787-40cf-897d-5c56a5625e15&searchtype=hp&installDate=
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.110\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.110\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.110\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-03-16]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx <nicht gefunden>
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1136520 2015-09-07] (Autodesk Inc.)
R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [955736 2016-03-13] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [466504 2016-03-13] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [466504 2016-03-13] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1424880 2016-03-13] (Avira Operations GmbH & Co. KG)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [260456 2016-01-27] (Avira Operations GmbH & Co. KG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [955168 2016-02-26] (IObit)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128664 2016-03-13] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [137952 2016-03-13] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [35488 2015-12-03] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [68936 2016-03-13] (Avira Operations GmbH & Co. KG)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
R3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [109272 2016-04-12] (Malwarebytes)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-12] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-12 12:31 - 2016-04-12 12:31 - 02375168 _____ (Farbar) C:\Users\hauptaccount\Downloads\FRST64.exe
2016-04-12 12:31 - 2016-04-12 12:31 - 00039460 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:31 - 2016-04-12 12:31 - 00000000 ____D C:\FRST
2016-04-12 12:22 - 2016-04-12 12:24 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\nachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-03-24 16:09 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM_2016 (1).pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega
2016-03-22 08:49 - 2016-03-22 08:49 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-03-21 22:52 - 2016-03-28 00:40 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt
2016-03-21 22:52 - 2016-03-21 22:52 - 00000208 _____ C:\Users\hauptaccount\Desktop\c.txt
2016-03-21 17:49 - 2016-03-21 17:50 - 00000000 ____D C:\Users\hauptaccount\Desktop\CYBERGAUNER
2016-03-21 17:35 - 2016-03-21 17:35 - 01596260 _____ C:\Users\hauptaccount\Downloads\flyer.pdf
2016-03-21 14:27 - 2016-03-21 14:28 - 08186625 _____ C:\Users\hauptaccount\Downloads\wordpress-4.4.2-de_DE.zip
2016-03-19 16:25 - 2016-03-19 16:25 - 00000000 ____D C:\Users\hauptaccount\Desktop\Neuer Ordner
2016-03-17 00:44 - 2016-03-21 00:55 - 00000291 _____ C:\Users\hauptaccount\Desktop\Steffi.txt
2016-03-16 14:41 - 2016-03-16 14:41 - 00180855 _____ C:\Users\hauptaccount\Desktop\Anmeldung.pdf
2016-03-16 14:40 - 2016-03-16 14:40 - 00067540 _____ C:\Users\hauptaccount\Desktop\Lebenslauf.pdf
2016-03-16 14:38 - 2016-03-16 14:38 - 00073672 _____ C:\Users\hauptaccount\Desktop\Berufschule.pdf
2016-03-16 14:36 - 2016-03-16 14:36 - 00072497 _____ C:\Users\hauptaccount\Desktop\HBFSWI.pdf
2016-03-15 20:01 - 2016-03-15 20:01 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM_2016.pdf
2016-03-15 19:10 - 2016-03-15 19:19 - 100431872 _____ C:\Users\hauptaccount\Downloads\cprogramme.part02.rar
2016-03-15 19:08 - 2016-03-15 19:43 - 104857600 _____ C:\Users\hauptaccount\Downloads\cprogramme.part01.rar
2016-03-15 16:50 - 2016-03-15 16:50 - 00001212 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk
2016-03-15 16:50 - 2016-03-15 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2016-03-15 16:13 - 2016-03-15 16:15 - 28320589 _____ C:\Users\hauptaccount\Downloads\eunp1ddf5h456dfh4df.rar
2016-03-15 16:02 - 2016-03-15 16:02 - 11245295 _____ C:\Users\hauptaccount\Downloads\zwspf_2010_Frühjahr.pdf
2016-03-14 23:40 - 2016-03-14 23:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\aquarium.txt
2016-03-14 00:55 - 2016-03-14 01:02 - 00000000 ____D C:\Users\hauptaccount\Desktop\tfghd
2016-03-13 03:08 - 2016-03-13 03:08 - 00000079 _____ C:\Users\hauptaccount\Desktop\th.txt

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-12 12:22 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-12 12:20 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-12 12:03 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-12 11:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-12 11:43 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-12 11:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-12 11:23 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-12 11:22 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-12 11:19 - 2016-03-06 02:39 - 00000000 ____D C:\ProgramData\ProductData
2016-04-11 22:46 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-11 22:46 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-11 22:46 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-11 22:46 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-11 21:14 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 21:26 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-10 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-10 15:58 - 2013-05-19 15:16 - 00000404 _____ C:\WINDOWS\Tasks\Wise Turbo Checker.job
2016-04-09 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-04-05 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-27 14:29 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-27 14:29 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-03-27 14:29 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-03-27 14:29 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-03-24 18:57 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-22 08:49 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-03-21 15:35 - 2011-01-17 18:08 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Paint.NET
2016-03-15 16:50 - 2016-03-06 02:39 - 00000000 ____D C:\ProgramData\IObit
2016-03-15 16:50 - 2016-03-06 02:39 - 00000000 ____D C:\Program Files (x86)\IObit
2016-03-13 18:35 - 2013-03-19 20:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-03-13 18:34 - 2013-05-07 21:17 - 00068936 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2016-03-13 18:34 - 2013-03-21 00:38 - 00137952 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2016-03-13 18:34 - 2013-03-21 00:38 - 00128664 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\hauptaccount\AppData\Local\Temp\Manchester-burden\manchester_authentication.exe


Einige Dateien in TEMP:
====================
C:\Users\hauptaccount\AppData\Local\Temp\avgnt.exe
C:\Users\hauptaccount\AppData\Local\Temp\ubiB78A.tmp.exe


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-11 12:08

==================== Ende von FRST.txt ============================


Ikarius 12.04.2016 12:20

Addition:
Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-12 12:35:24)
Gestartet von C:\Users\hauptaccount\Downloads
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Enabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Akamai) (Version:  - Akamai Technologies, Inc)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.5 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.16.282 - Avira Operations GmbH & Co. KG)
Avira Launcher (HKLM-x32\...\{3b87484e-d70b-4b4f-ad59-2ae89571e2cf}) (Version: 1.1.56.9119 - Avira Operations GmbH & Co. KG)
Avira Launcher (x32 Version: 1.1.56.9119 - Avira Operations GmbH & Co. KG) Hidden
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Dropbox) (Version: 3.8.5 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
IObit Malware Fighter 4 (HKLM-x32\...\IObit Malware Fighter_is1) (Version: 4.0 - IObit)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.2.1.126 - IObit)
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
MyFreeCodec (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MyFreeCodec) (Version:  - )
MyFreeCodec (HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MyFreeCodec) (Version:  - )
MyFreeCodec (HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MyFreeCodec) (Version:  - )
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Spotify) (Version: 1.0.10.107.gd0dfca3a - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {0549C0DB-913F-4411-B577-6A5D9C5D6CEB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {06AD79CF-3049-4E43-A011-BABF6A39B4DF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {08259CC4-9134-4DA6-B2D1-A2067A39767C} - System32\Tasks\Uninstaller_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-01-12] (IObit)
Task: {0FE5D209-B132-4972-B77D-AC0A78A3FF06} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {11DDFDAD-C35F-4461-90F9-16E92773139F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {15EE9EF4-3824-44CA-8DE2-6C81AD1785D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {242E14E3-E262-42F4-8B7B-A16CC962477C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {29CA4BA7-9156-431C-88C7-69741974F3CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {406C9318-4C8B-41DE-8D30-9294CF6DC20F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {4266230F-065B-4BE2-9BEE-50CE8AADFD46} - System32\Tasks\Wise Turbo Checker => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2013-05-13] (WiseCleaner.COM)
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-01-18] (IObit)
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {6B7FC54F-AB46-4C0A-BB70-AC855322E160} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B39BB78F-77E1-4816-A75E-9ECC781229E1} - System32\Tasks\Driver Booster SkipUAC (hauptaccount) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2016-01-18] (IObit)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {CDDBBD48-0D3F-480D-8456-4181DB66F45F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D65DB895-0C22-4C88-AB59-BEE5AD5AA27F} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2016-01-13] (IObit)
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
Task: {FE8EB787-034F-4677-8391-7FCC25426EED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: C:\WINDOWS\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-03-02 19:19 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 19:19 - 2016-02-23 13:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-02 19:19 - 2016-02-23 10:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-03-02 19:19 - 2016-02-23 10:38 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-01-13 11:25 - 2016-01-05 03:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 11:25 - 2016-01-05 03:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-27 21:10 - 2016-01-16 07:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-27 21:10 - 2016-01-16 07:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2015-10-28 19:19 - 2015-09-07 05:33 - 00055688 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-10-28 19:19 - 2015-09-07 05:33 - 00104328 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2016-03-06 02:42 - 2015-12-23 18:17 - 00625440 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2016-03-15 16:50 - 2015-12-23 18:17 - 00899872 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\webres.dll
2016-03-15 16:50 - 2015-12-23 18:17 - 00188704 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\unrar.dll
2016-03-15 16:50 - 2015-12-23 18:17 - 00151840 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\zlibwapi.dll
2016-03-15 16:50 - 2015-12-23 18:17 - 00625440 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\ProductStatistics.dll
2016-03-31 10:49 - 2016-03-27 09:58 - 01675928 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.110\libglesv2.dll
2016-03-31 10:49 - 2016-03-27 09:58 - 00086168 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.110\libegl.dll
2016-03-06 02:42 - 2015-12-23 19:32 - 00355616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2016-03-06 02:42 - 2015-12-23 19:32 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2016-03-06 02:42 - 2015-12-23 19:32 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2016-03-15 16:50 - 2015-12-23 18:17 - 00355616 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madExcept_.bpl
2016-03-15 16:50 - 2015-12-23 18:17 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madBasic_.bpl
2016-03-15 16:50 - 2015-12-23 18:17 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\madDisAsm_.bpl
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00848536 _____ () C:\Program Files (x86)\Mozilla Thunderbird\js3250.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00161944 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00021656 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"

==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
HKU\S-1-5-21-2403081755-137120475-2182785957-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe

==================== Wiederherstellungspunkte =========================

24-03-2016 18:56:48 Windows Update
03-04-2016 15:49:10 Geplanter Prüfpunkt

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Renesas USB 3.0 eXtensible-Hostcontroller – 0.96 (Microsoft)
Description: USB-xHCI-kompatibler Hostcontroller
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Generischer USB-xHCI-Hostcontroller
Service: USBXHCI
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/12/2016 11:20:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x810
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5

Error: (04/12/2016 11:19:51 AM) (Source: ATIeRecord) (EventID: 16391) (User: )
Description: ATI EEU maximum number of session has been surpassed

Error: (04/11/2016 10:46:08 PM) (Source: ATIeRecord) (EventID: 16391) (User: )
Description: ATI EEU maximum number of session has been surpassed

Error: (04/11/2016 10:46:08 PM) (Source: ATIeRecord) (EventID: 16391) (User: )
Description: ATI EEU maximum number of session has been surpassed

Error: (04/11/2016 10:46:08 PM) (Source: ATIeRecord) (EventID: 16391) (User: )
Description: ATI EEU maximum number of session has been surpassed

Error: (04/11/2016 10:46:07 PM) (Source: ATIeRecord) (EventID: 16391) (User: )
Description: ATI EEU maximum number of session has been surpassed

Error: (04/11/2016 10:45:59 PM) (Source: ATIeRecord) (EventID: 16391) (User: )
Description: ATI EEU maximum number of session has been surpassed

Error: (04/11/2016 05:17:50 PM) (Source: ATIeRecord) (EventID: 16391) (User: )
Description: ATI EEU maximum number of session has been surpassed

Error: (04/11/2016 02:39:31 PM) (Source: ATIeRecord) (EventID: 16391) (User: )
Description: ATI EEU maximum number of session has been surpassed

Error: (04/11/2016 12:33:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x1430
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5


Systemfehler:
=============
Error: (04/12/2016 11:48:57 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("270") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/12/2016 11:18:25 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.

Error: (04/11/2016 10:45:59 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_a0e3a290" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/11/2016 10:45:53 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("270") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/11/2016 10:45:53 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("270") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/11/2016 10:45:53 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("270") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/11/2016 10:45:53 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("270") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/11/2016 10:45:53 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("270") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/11/2016 10:45:53 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("270") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/11/2016 05:17:16 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.


CodeIntegrity:
===================================
  Date: 2016-03-25 13:48:48.448
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 12:20:24.724
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-11 10:38:05.691
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-05 15:18:17.580
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\PROGRA~2\PDFCRE~1\PDFSpool.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\PDFCreator\PDFCreator.exe that did not meet the Microsoft signing level requirements.

  Date: 2016-03-03 22:35:31.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-12 10:22:01.825
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 06:29:22.290
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-10 20:49:59.601
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-05 19:59:09.119
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-01-08 21:53:17.642
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Speicherinformationen ===========================

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 84%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 615.21 MB
Summe virtueller Speicher: 10345.14 MB
Verfügbarer virtueller Speicher: 3338.23 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:104.53 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.69 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


Ikarius 13.04.2016 13:58

Antivir hat sich vorhin gemeldet=3 Funde
TR/CRYPT.ZPACK.pmam
TR/CRYPT.ZPACK.pmam
TR/CRYPT.ZPACK.edzz

befindet sich jetzt in Quarantäne. Anschließender Systemscan hat sonst nichts gefunden.
Hier der Report:
Code:


Free Antivirus
Erstellungsdatum der Reportdatei: Dienstag, 12. April 2016  14:13


Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  : Free
Seriennummer  : 0000149996-AVHOE-0000001
Plattform      : Windows 10 Home
Windowsversion : (plain)  [10.0.10586]
Boot Modus    : Normal gebootet
Benutzername  : hauptaccount
Computername  : hauptaccount-PC

Versionsinformationen:
build.dat      : 15.0.16.282    92460 Bytes  22.02.2016 16:45:00
AVSCAN.EXE    : 15.0.16.276  1235360 Bytes  13.03.2016 16:34:04
AVSCANRC.DLL  : 15.0.16.269    65256 Bytes  13.03.2016 16:34:04
LUKE.DLL      : 15.0.16.273    67840 Bytes  13.03.2016 16:34:23
AVSCPLR.DLL    : 15.0.16.280  130712 Bytes  13.03.2016 16:34:04
REPAIR.DLL    : 15.0.16.251  596760 Bytes  13.03.2016 16:34:02
repair.rdf    : 1.0.16.24    1542408 Bytes  12.04.2016 09:21:41
AVREG.DLL      : 15.0.16.273  350584 Bytes  13.03.2016 16:34:02
avlode.dll    : 15.0.16.276  721384 Bytes  13.03.2016 16:34:00
avlode.rdf    : 14.0.5.36      94056 Bytes  01.03.2016 18:46:05
XBV00007.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00008.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00009.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00010.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00011.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00012.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00013.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00014.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00015.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00016.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00017.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00018.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:49
XBV00019.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00020.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00021.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00022.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00023.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00024.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00025.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00026.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00027.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00028.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00029.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00030.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00031.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00032.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00033.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00034.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00035.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00036.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00037.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00038.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00039.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00040.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00041.VDF  : 8.12.37.66      2048 Bytes  17.12.2015 13:14:50
XBV00250.VDF  : 8.12.77.158    2048 Bytes  04.04.2016 22:26:13
XBV00251.VDF  : 8.12.77.158    2048 Bytes  04.04.2016 22:26:13
XBV00252.VDF  : 8.12.77.158    2048 Bytes  04.04.2016 22:26:13
XBV00253.VDF  : 8.12.77.158    2048 Bytes  04.04.2016 22:26:13
XBV00254.VDF  : 8.12.77.158    2048 Bytes  04.04.2016 22:26:13
XBV00255.VDF  : 8.12.77.158    2048 Bytes  04.04.2016 22:26:13
XBV00000.VDF  : 7.11.70.0  66736640 Bytes  04.04.2013 22:17:41
XBV00001.VDF  : 7.11.237.0  48041984 Bytes  02.06.2015 13:14:38
XBV00002.VDF  : 7.12.37.36  16452096 Bytes  17.12.2015 13:14:49
XBV00003.VDF  : 8.12.44.142  3948032 Bytes  09.01.2016 21:25:12
XBV00004.VDF  : 8.12.52.208  4036096 Bytes  02.02.2016 13:03:06
XBV00005.VDF  : 8.12.62.184  2779136 Bytes  26.02.2016 19:44:07
XBV00006.VDF  : 8.12.71.186  2191360 Bytes  19.03.2016 17:13:26
XBV00042.VDF  : 8.12.71.214    53248 Bytes  20.03.2016 13:34:56
XBV00043.VDF  : 8.12.71.242    6656 Bytes  20.03.2016 15:34:58
XBV00044.VDF  : 8.12.72.14    13312 Bytes  20.03.2016 15:34:58
XBV00045.VDF  : 8.12.72.90      2048 Bytes  20.03.2016 15:34:58
XBV00046.VDF  : 8.12.72.146    54272 Bytes  21.03.2016 12:25:59
XBV00047.VDF  : 8.12.72.174    10240 Bytes  21.03.2016 12:26:00
XBV00048.VDF  : 8.12.72.202    7680 Bytes  21.03.2016 12:26:00
XBV00049.VDF  : 8.12.72.204    22528 Bytes  21.03.2016 12:26:00
XBV00050.VDF  : 8.12.72.206    8704 Bytes  21.03.2016 12:26:00
XBV00051.VDF  : 8.12.72.210    17408 Bytes  21.03.2016 18:25:23
XBV00052.VDF  : 8.12.72.230    2048 Bytes  21.03.2016 18:25:23
XBV00053.VDF  : 8.12.72.250    26112 Bytes  21.03.2016 20:25:18
XBV00054.VDF  : 8.12.72.254    2048 Bytes  21.03.2016 20:25:18
XBV00055.VDF  : 8.12.73.18      9728 Bytes  21.03.2016 06:00:36
XBV00056.VDF  : 8.12.73.38      5120 Bytes  21.03.2016 06:00:36
XBV00057.VDF  : 8.12.73.58      8704 Bytes  21.03.2016 06:00:36
XBV00058.VDF  : 8.12.73.80    27136 Bytes  22.03.2016 07:59:34
XBV00059.VDF  : 8.12.73.82    14848 Bytes  22.03.2016 07:59:34
XBV00060.VDF  : 8.12.73.102    15872 Bytes  22.03.2016 09:59:31
XBV00061.VDF  : 8.12.73.120    10752 Bytes  22.03.2016 15:06:36
XBV00062.VDF  : 8.12.73.172    95232 Bytes  22.03.2016 15:06:36
XBV00063.VDF  : 8.12.73.190    11264 Bytes  22.03.2016 15:06:36
XBV00064.VDF  : 8.12.73.212    18432 Bytes  22.03.2016 19:06:40
XBV00065.VDF  : 8.12.73.232    9216 Bytes  22.03.2016 19:06:40
XBV00066.VDF  : 8.12.73.250    7680 Bytes  22.03.2016 19:06:40
XBV00067.VDF  : 8.12.74.12    12800 Bytes  22.03.2016 21:06:45
XBV00068.VDF  : 8.12.74.30      9728 Bytes  22.03.2016 07:19:32
XBV00069.VDF  : 8.12.74.32    12288 Bytes  22.03.2016 07:19:32
XBV00070.VDF  : 8.12.74.52    25600 Bytes  23.03.2016 07:19:32
XBV00071.VDF  : 8.12.74.68    15872 Bytes  23.03.2016 18:19:06
XBV00072.VDF  : 8.12.74.84    57856 Bytes  23.03.2016 18:19:07
XBV00073.VDF  : 8.12.74.100    2048 Bytes  23.03.2016 18:19:07
XBV00074.VDF  : 8.12.74.118    21504 Bytes  23.03.2016 18:19:07
XBV00075.VDF  : 8.12.74.120    9728 Bytes  23.03.2016 13:16:28
XBV00076.VDF  : 8.12.74.122    9728 Bytes  23.03.2016 13:16:28
XBV00077.VDF  : 8.12.74.124    10240 Bytes  23.03.2016 13:16:28
XBV00078.VDF  : 8.12.74.126    8704 Bytes  23.03.2016 13:16:28
XBV00079.VDF  : 8.12.74.144    39936 Bytes  24.03.2016 13:16:29
XBV00080.VDF  : 8.12.74.160    2048 Bytes  24.03.2016 13:16:29
XBV00081.VDF  : 8.12.74.176    19456 Bytes  24.03.2016 13:16:29
XBV00082.VDF  : 8.12.74.192    4096 Bytes  24.03.2016 13:16:29
XBV00083.VDF  : 8.12.74.208    14336 Bytes  24.03.2016 13:16:29
XBV00084.VDF  : 8.12.74.210    10240 Bytes  24.03.2016 13:16:29
XBV00085.VDF  : 8.12.74.212    16896 Bytes  24.03.2016 15:17:04
XBV00086.VDF  : 8.12.74.214    10752 Bytes  24.03.2016 15:17:04
XBV00087.VDF  : 8.12.74.216    8192 Bytes  24.03.2016 17:16:34
XBV00088.VDF  : 8.12.74.218    9728 Bytes  24.03.2016 21:16:37
XBV00089.VDF  : 8.12.74.220    2048 Bytes  24.03.2016 21:16:37
XBV00090.VDF  : 8.12.74.222    13312 Bytes  24.03.2016 21:16:37
XBV00091.VDF  : 8.12.74.224    9216 Bytes  24.03.2016 21:16:37
XBV00092.VDF  : 8.12.74.226    8704 Bytes  24.03.2016 23:16:40
XBV00093.VDF  : 8.12.74.228    6656 Bytes  24.03.2016 23:16:40
XBV00094.VDF  : 8.12.74.234    27136 Bytes  25.03.2016 12:46:42
XBV00095.VDF  : 8.12.74.236    2560 Bytes  25.03.2016 12:46:42
XBV00096.VDF  : 8.12.74.238    2560 Bytes  25.03.2016 12:46:42
XBV00097.VDF  : 8.12.74.240    14848 Bytes  25.03.2016 12:46:43
XBV00098.VDF  : 8.12.74.242    14848 Bytes  25.03.2016 12:46:43
XBV00099.VDF  : 8.12.74.244    18432 Bytes  25.03.2016 14:46:01
XBV00100.VDF  : 8.12.74.250    41472 Bytes  25.03.2016 16:46:01
XBV00101.VDF  : 8.12.74.252    6656 Bytes  25.03.2016 16:46:01
XBV00102.VDF  : 8.12.75.12    89600 Bytes  26.03.2016 11:13:57
XBV00103.VDF  : 8.12.75.26      2048 Bytes  26.03.2016 11:13:57
XBV00104.VDF  : 8.12.75.40    41472 Bytes  26.03.2016 17:13:56
XBV00105.VDF  : 8.12.75.54      2048 Bytes  26.03.2016 17:13:57
XBV00106.VDF  : 8.12.75.68    99840 Bytes  27.03.2016 12:27:39
XBV00107.VDF  : 8.12.75.94    20992 Bytes  27.03.2016 12:27:39
XBV00108.VDF  : 8.12.75.108    11776 Bytes  27.03.2016 12:27:39
XBV00109.VDF  : 8.12.75.122    12288 Bytes  27.03.2016 12:27:39
XBV00110.VDF  : 8.12.75.136    9728 Bytes  27.03.2016 14:27:12
XBV00111.VDF  : 8.12.75.138    99328 Bytes  28.03.2016 16:44:05
XBV00112.VDF  : 8.12.75.154    11776 Bytes  28.03.2016 16:44:05
XBV00113.VDF  : 8.12.75.168    10752 Bytes  28.03.2016 16:44:05
XBV00114.VDF  : 8.12.75.180    8192 Bytes  28.03.2016 16:44:06
XBV00115.VDF  : 8.12.75.192    29696 Bytes  28.03.2016 16:44:06
XBV00116.VDF  : 8.12.75.204    3072 Bytes  28.03.2016 16:44:06
XBV00117.VDF  : 8.12.75.220    2048 Bytes  28.03.2016 16:44:06
XBV00118.VDF  : 8.12.75.232    44032 Bytes  28.03.2016 16:44:06
XBV00119.VDF  : 8.12.75.244    14848 Bytes  28.03.2016 16:44:06
XBV00120.VDF  : 8.12.75.246    16384 Bytes  28.03.2016 18:44:01
XBV00121.VDF  : 8.12.75.248    29184 Bytes  28.03.2016 22:44:06
XBV00122.VDF  : 8.12.75.250    11264 Bytes  28.03.2016 22:44:06
XBV00123.VDF  : 8.12.75.254    2048 Bytes  28.03.2016 22:44:06
XBV00124.VDF  : 8.12.76.10    48128 Bytes  29.03.2016 15:41:07
XBV00125.VDF  : 8.12.76.22    10752 Bytes  29.03.2016 15:41:07
XBV00126.VDF  : 8.12.76.34    10752 Bytes  29.03.2016 15:41:08
XBV00127.VDF  : 8.12.76.46    32768 Bytes  29.03.2016 15:41:08
XBV00128.VDF  : 8.12.76.48    14848 Bytes  29.03.2016 15:41:08
XBV00129.VDF  : 8.12.76.50    28672 Bytes  29.03.2016 15:41:08
XBV00130.VDF  : 8.12.76.62      2048 Bytes  29.03.2016 15:41:08
XBV00131.VDF  : 8.12.76.64      2560 Bytes  29.03.2016 15:41:08
XBV00132.VDF  : 8.12.76.74    26112 Bytes  29.03.2016 15:41:08
XBV00133.VDF  : 8.12.76.84    24064 Bytes  29.03.2016 17:40:16
XBV00134.VDF  : 8.12.76.94    13312 Bytes  29.03.2016 17:40:16
XBV00135.VDF  : 8.12.76.104    2048 Bytes  29.03.2016 17:40:16
XBV00136.VDF  : 8.12.76.114    31744 Bytes  29.03.2016 21:40:24
XBV00137.VDF  : 8.12.76.116    2048 Bytes  29.03.2016 21:40:24
XBV00138.VDF  : 8.12.76.118    50688 Bytes  29.03.2016 23:40:30
XBV00139.VDF  : 8.12.76.124    54784 Bytes  30.03.2016 10:04:41
XBV00140.VDF  : 8.12.76.128    19456 Bytes  30.03.2016 10:04:41
XBV00141.VDF  : 8.12.76.130    19456 Bytes  30.03.2016 10:04:41
XBV00142.VDF  : 8.12.76.132    2048 Bytes  30.03.2016 10:04:41
XBV00143.VDF  : 8.12.76.136    61952 Bytes  30.03.2016 18:12:43
XBV00144.VDF  : 8.12.76.138    2048 Bytes  30.03.2016 18:12:44
XBV00145.VDF  : 8.12.76.148    22528 Bytes  30.03.2016 18:12:44
XBV00146.VDF  : 8.12.76.158    38400 Bytes  30.03.2016 18:12:44
XBV00147.VDF  : 8.12.76.168    17920 Bytes  30.03.2016 08:03:09
XBV00148.VDF  : 8.12.76.178    20480 Bytes  30.03.2016 08:03:09
XBV00149.VDF  : 8.12.76.180    2048 Bytes  30.03.2016 08:03:09
XBV00150.VDF  : 8.12.76.182    2048 Bytes  30.03.2016 08:03:09
XBV00151.VDF  : 8.12.76.186    66048 Bytes  31.03.2016 08:03:09
XBV00152.VDF  : 8.12.76.188    21504 Bytes  31.03.2016 08:03:09
XBV00153.VDF  : 8.12.76.190    20992 Bytes  31.03.2016 08:03:10
XBV00154.VDF  : 8.12.76.192    16896 Bytes  31.03.2016 10:02:22
XBV00155.VDF  : 8.12.76.202    29696 Bytes  31.03.2016 20:14:19
XBV00156.VDF  : 8.12.76.214    50176 Bytes  31.03.2016 20:14:19
XBV00157.VDF  : 8.12.76.216    2048 Bytes  31.03.2016 20:14:19
XBV00158.VDF  : 8.12.76.224    16896 Bytes  31.03.2016 22:14:18
XBV00159.VDF  : 8.12.76.232    16384 Bytes  31.03.2016 00:14:18
XBV00160.VDF  : 8.12.76.252    55808 Bytes  01.04.2016 13:52:00
XBV00161.VDF  : 8.12.77.4      20480 Bytes  01.04.2016 13:52:00
XBV00162.VDF  : 8.12.77.14    11264 Bytes  01.04.2016 13:52:00
XBV00163.VDF  : 8.12.77.22    13312 Bytes  01.04.2016 13:52:00
XBV00164.VDF  : 8.12.77.24    16896 Bytes  01.04.2016 13:52:00
XBV00165.VDF  : 8.12.77.26    14848 Bytes  01.04.2016 17:50:57
XBV00166.VDF  : 8.12.77.50      6656 Bytes  01.04.2016 17:50:57
XBV00167.VDF  : 8.12.77.158  441856 Bytes  04.04.2016 22:26:11
XBV00168.VDF  : 8.12.77.166    24064 Bytes  04.04.2016 22:26:11
XBV00169.VDF  : 8.12.77.174    23552 Bytes  04.04.2016 22:26:11
XBV00170.VDF  : 8.12.77.182    22528 Bytes  04.04.2016 22:26:11
XBV00171.VDF  : 8.12.77.184    2048 Bytes  04.04.2016 22:26:11
XBV00172.VDF  : 8.12.77.186    2048 Bytes  04.04.2016 22:26:11
XBV00173.VDF  : 8.12.77.188    3584 Bytes  04.04.2016 22:26:11
XBV00174.VDF  : 8.12.77.190    2048 Bytes  04.04.2016 22:26:11
XBV00175.VDF  : 8.12.77.194    5632 Bytes  05.04.2016 06:26:16
XBV00176.VDF  : 8.12.77.196    2048 Bytes  05.04.2016 06:26:16
XBV00177.VDF  : 8.12.77.198    2048 Bytes  05.04.2016 05:40:42
XBV00178.VDF  : 8.12.77.200    4608 Bytes  05.04.2016 05:40:42
XBV00179.VDF  : 8.12.77.202    4608 Bytes  05.04.2016 05:40:42
XBV00180.VDF  : 8.12.77.208    4608 Bytes  05.04.2016 05:40:42
XBV00181.VDF  : 8.12.77.210    2048 Bytes  05.04.2016 05:40:42
XBV00182.VDF  : 8.12.77.212    41984 Bytes  05.04.2016 05:40:43
XBV00183.VDF  : 8.12.77.214    10752 Bytes  05.04.2016 05:40:43
XBV00184.VDF  : 8.12.77.216    16896 Bytes  05.04.2016 05:40:43
XBV00185.VDF  : 8.12.77.218    2048 Bytes  05.04.2016 05:40:43
XBV00186.VDF  : 8.12.77.220    33280 Bytes  05.04.2016 05:40:43
XBV00187.VDF  : 8.12.77.222    14336 Bytes  05.04.2016 05:40:43
XBV00188.VDF  : 8.12.77.224    12800 Bytes  05.04.2016 05:40:43
XBV00189.VDF  : 8.12.77.226    13824 Bytes  05.04.2016 05:40:43
XBV00190.VDF  : 8.12.77.228    8704 Bytes  05.04.2016 05:40:43
XBV00191.VDF  : 8.12.77.232    61440 Bytes  06.04.2016 05:40:43
XBV00192.VDF  : 8.12.77.240    11776 Bytes  06.04.2016 07:38:57
XBV00193.VDF  : 8.12.77.246    16384 Bytes  06.04.2016 09:38:54
XBV00194.VDF  : 8.12.78.28      5120 Bytes  06.04.2016 13:39:07
XBV00195.VDF  : 8.12.78.56      2048 Bytes  06.04.2016 13:39:07
XBV00196.VDF  : 8.12.78.84      2048 Bytes  06.04.2016 13:39:07
XBV00197.VDF  : 8.12.78.112    53760 Bytes  06.04.2016 17:39:06
XBV00198.VDF  : 8.12.78.140    2048 Bytes  06.04.2016 17:39:06
XBV00199.VDF  : 8.12.78.168    18944 Bytes  06.04.2016 17:39:06
XBV00200.VDF  : 8.12.78.196    17408 Bytes  06.04.2016 21:39:08
XBV00201.VDF  : 8.12.78.198    10752 Bytes  06.04.2016 21:39:08
XBV00202.VDF  : 8.12.78.200    11264 Bytes  06.04.2016 21:39:08
XBV00203.VDF  : 8.12.78.202    14336 Bytes  06.04.2016 05:58:30
XBV00204.VDF  : 8.12.78.206    69120 Bytes  07.04.2016 05:58:30
XBV00205.VDF  : 8.12.78.208    2560 Bytes  07.04.2016 05:58:30
XBV00206.VDF  : 8.12.78.210    19968 Bytes  07.04.2016 07:58:13
XBV00207.VDF  : 8.12.78.212    25600 Bytes  07.04.2016 09:58:16
XBV00208.VDF  : 8.12.78.234    8192 Bytes  07.04.2016 09:58:16
XBV00209.VDF  : 8.12.79.2      41472 Bytes  07.04.2016 17:58:20
XBV00210.VDF  : 8.12.79.22      2048 Bytes  07.04.2016 17:58:20
XBV00211.VDF  : 8.12.79.42    19456 Bytes  07.04.2016 05:25:42
XBV00212.VDF  : 8.12.79.62    16384 Bytes  07.04.2016 05:25:42
XBV00213.VDF  : 8.12.79.66      2048 Bytes  07.04.2016 05:25:42
XBV00214.VDF  : 8.12.79.70    57344 Bytes  08.04.2016 05:25:42
XBV00215.VDF  : 8.12.79.72      5120 Bytes  08.04.2016 07:25:04
XBV00216.VDF  : 8.12.79.74    10240 Bytes  08.04.2016 07:25:05
XBV00217.VDF  : 8.12.79.76    14848 Bytes  08.04.2016 20:44:59
XBV00218.VDF  : 8.12.79.86    44544 Bytes  08.04.2016 20:44:59
XBV00219.VDF  : 8.12.79.88      2048 Bytes  08.04.2016 20:44:59
XBV00220.VDF  : 8.12.79.90    19968 Bytes  08.04.2016 20:44:59
XBV00221.VDF  : 8.12.79.92      2048 Bytes  08.04.2016 20:44:59
XBV00222.VDF  : 8.12.79.94    12288 Bytes  08.04.2016 20:44:59
XBV00223.VDF  : 8.12.79.96    11264 Bytes  08.04.2016 22:45:00
XBV00224.VDF  : 8.12.79.98      9216 Bytes  08.04.2016 22:45:00
XBV00225.VDF  : 8.12.79.140    82944 Bytes  09.04.2016 11:13:20
XBV00226.VDF  : 8.12.79.160    21504 Bytes  09.04.2016 11:13:20
XBV00227.VDF  : 8.12.79.180    27648 Bytes  09.04.2016 15:12:58
XBV00228.VDF  : 8.12.79.200    56320 Bytes  10.04.2016 08:25:13
XBV00229.VDF  : 8.12.79.202    3584 Bytes  10.04.2016 08:25:13
XBV00230.VDF  : 8.12.79.204    20480 Bytes  10.04.2016 12:24:04
XBV00231.VDF  : 8.12.79.206    50176 Bytes  10.04.2016 12:24:04
XBV00232.VDF  : 8.12.79.208    24064 Bytes  10.04.2016 14:24:12
XBV00233.VDF  : 8.12.79.210  138752 Bytes  11.04.2016 09:55:08
XBV00234.VDF  : 8.12.79.230    4608 Bytes  11.04.2016 09:55:08
XBV00235.VDF  : 8.12.79.248    24576 Bytes  11.04.2016 09:55:08
XBV00236.VDF  : 8.12.80.10    12800 Bytes  11.04.2016 09:55:08
XBV00237.VDF  : 8.12.80.28    26112 Bytes  11.04.2016 16:31:54
XBV00238.VDF  : 8.12.80.46    33792 Bytes  11.04.2016 16:31:54
XBV00239.VDF  : 8.12.80.48    47104 Bytes  11.04.2016 20:31:59
XBV00240.VDF  : 8.12.80.50      2560 Bytes  11.04.2016 20:31:59
XBV00241.VDF  : 8.12.80.52    12800 Bytes  11.04.2016 20:32:00
XBV00242.VDF  : 8.12.80.54    11776 Bytes  11.04.2016 20:32:00
XBV00243.VDF  : 8.12.80.56      9728 Bytes  11.04.2016 09:21:39
XBV00244.VDF  : 8.12.80.58      9728 Bytes  11.04.2016 09:21:39
XBV00245.VDF  : 8.12.80.62    43520 Bytes  12.04.2016 09:21:40
XBV00246.VDF  : 8.12.80.66    18432 Bytes  12.04.2016 09:21:40
XBV00247.VDF  : 8.12.80.68    10240 Bytes  12.04.2016 09:21:40
XBV00248.VDF  : 8.12.80.86      4608 Bytes  12.04.2016 09:21:40
XBV00249.VDF  : 8.12.80.102    7168 Bytes  12.04.2016 09:21:40
LOCAL000.VDF  : 8.12.80.102 149966848 Bytes  12.04.2016 09:22:02
Engineversion  : 8.3.38.18
AEBB.DLL      : 8.1.3.0        59296 Bytes  19.11.2015 14:39:32
AECORE.DLL    : 8.3.12.4      247720 Bytes  21.03.2016 12:25:57
AEDROID.DLL    : 8.4.3.358    2717608 Bytes  06.04.2016 05:40:42
AEEMU.DLL      : 8.1.3.8      404328 Bytes  18.03.2016 11:09:47
AEEXP.DLL      : 8.4.2.160    300968 Bytes  06.04.2016 05:40:40
AEGEN.DLL      : 8.1.8.80      530336 Bytes  11.04.2016 11:54:12
AEHELP.DLL    : 8.3.2.10      284584 Bytes  15.02.2016 11:42:12
AEHEUR.DLL    : 8.1.4.2246  10165104 Bytes  08.04.2016 09:25:06
AEMOBILE.DLL  : 8.1.8.10      301936 Bytes  26.11.2015 13:44:06
AEOFFICE.DLL  : 8.3.3.24      460712 Bytes  08.04.2016 09:25:06
AEPACK.DLL    : 8.4.2.14      805744 Bytes  31.03.2016 20:14:18
AERDL.DLL      : 8.2.1.42      813928 Bytes  18.03.2016 11:09:49
AESBX.DLL      : 8.2.21.4    1629032 Bytes  16.03.2016 11:21:22
AESCN.DLL      : 8.3.4.4      142456 Bytes  11.03.2016 11:47:05
AESCRIPT.DLL  : 8.3.0.92      587688 Bytes  11.04.2016 11:54:12
AEVDF.DLL      : 8.3.3.4      142184 Bytes  21.03.2016 12:25:59
AVWINLL.DLL    : 15.0.16.227    27680 Bytes  13.03.2016 16:33:56
AVPREF.DLL    : 15.0.16.227    53944 Bytes  13.03.2016 16:34:01
AVREP.DLL      : 15.0.16.227  223400 Bytes  13.03.2016 16:34:02
AVARKT.DLL    : 15.0.16.227  230080 Bytes  13.03.2016 16:33:57
AVEVTLOG.DLL  : 15.0.16.251  200192 Bytes  13.03.2016 16:33:59
SQLITE3.DLL    : 15.0.16.227  459752 Bytes  13.03.2016 16:34:26
AVSMTP.DLL    : 15.0.16.227    80200 Bytes  13.03.2016 16:34:04
NETNT.DLL      : 15.0.16.227    16880 Bytes  13.03.2016 16:34:23
CommonImageRc.dll: 15.0.16.222  4307832 Bytes  13.03.2016 16:33:56
CommonTextRc.dll: 15.0.16.222    68864 Bytes  13.03.2016 16:33:57

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Vollständige Prüfung
Konfigurationsdatei...................: C:\Program Files (x86)\Avira\AntiVir Desktop\sysscan.avp
Protokollierung.......................: standard
Primäre Aktion........................: Interaktiv
Sekundäre Aktion......................: Ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:, D:,
Durchsuche aktive Programme...........: ein
Laufende Programme erweitert..........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: ein
Integritätsprüfung von Systemdateien..: aus
Prüfe alle Dateien....................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: erweitert
Auszulassende Dateien.................:

Beginn des Suchlaufs: Dienstag, 12. April 2016  14:13

Der Suchlauf über die Bootsektoren wird begonnen:
Bootsektor 'HDD0(C:, D:)'
    [INFO]      Es wurde kein Virus gefunden!

Der Suchlauf nach versteckten Objekten wird begonnen.

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'svchost.exe' - '74' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '226' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '122' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '104' Modul(e) wurden durchsucht
Durchsuche Prozess 'ASCService.exe' - '66' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '70' Modul(e) wurden durchsucht
Durchsuche Prozess 'WUDFHost.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '104' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '96' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '83' Modul(e) wurden durchsucht
Durchsuche Prozess 'atiesrxx.exe' - '17' Modul(e) wurden durchsucht
Durchsuche Prozess 'CTAudSvc.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'spoolsv.exe' - '94' Modul(e) wurden durchsucht
Durchsuche Prozess 'AppleMobileDeviceService.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'mDNSResponder.exe' - '30' Modul(e) wurden durchsucht
Durchsuche Prozess 'WlanNetService.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'diskbsa.exe' - '52' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '84' Modul(e) wurden durchsucht
Durchsuche Prozess 'AdAppMgrSvc.exe' - '94' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbbservice.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'LiveUpdate.exe' - '56' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '48' Modul(e) wurden durchsucht
Durchsuche Prozess 'WinService.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'ss_conn_service.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'mqsvc.exe' - '68' Modul(e) wurden durchsucht
Durchsuche Prozess 'dashost.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'SMSvcHost.exe' - '30' Modul(e) wurden durchsucht
Durchsuche Prozess 'SMSvcHost.exe' - '29' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchIndexer.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'Avira.ServiceHost.exe' - '103' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '87' Modul(e) wurden durchsucht
Durchsuche Prozess 'IMFsrv.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'Connect.Service.ContentService.exe' - '64' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '132' Modul(e) wurden durchsucht
Durchsuche Prozess 'avshadow.exe' - '25' Modul(e) wurden durchsucht
Durchsuche Prozess 'dwm.exe' - '42' Modul(e) wurden durchsucht
Durchsuche Prozess 'sihost.exe' - '70' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskhostw.exe' - '74' Modul(e) wurden durchsucht
Durchsuche Prozess 'RuntimeBroker.exe' - '109' Modul(e) wurden durchsucht
Durchsuche Prozess 'Explorer.EXE' - '219' Modul(e) wurden durchsucht
Durchsuche Prozess 'ShellExperienceHost.exe' - '96' Modul(e) wurden durchsucht
Durchsuche Prozess 'RAVCpl64.exe' - '71' Modul(e) wurden durchsucht
Durchsuche Prozess 'MtdAcqu.exe' - '77' Modul(e) wurden durchsucht
Durchsuche Prozess 'netsession_win.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'netsession_win.exe' - '69' Modul(e) wurden durchsucht
Durchsuche Prozess 'SSScheduler.exe' - '44' Modul(e) wurden durchsucht
Durchsuche Prozess 'Ctxfihlp.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'nusb3mon.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'VolPanlu.exe' - '90' Modul(e) wurden durchsucht
Durchsuche Prozess 'WLanGUI.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '117' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpwuschd2.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'Avira.Systray.exe' - '66' Modul(e) wurden durchsucht
Durchsuche Prozess 'IMF.exe' - '92' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '138' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '79' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'UninstallMonitor.exe' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'IMFTips.exe' - '60' Modul(e) wurden durchsucht
Durchsuche Prozess 'InstallAgent.exe' - '58' Modul(e) wurden durchsucht
Durchsuche Prozess 'SoftwareUpdate.exe' - '107' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '72' Modul(e) wurden durchsucht
Durchsuche Prozess 'SkypeHost.exe' - '51' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '59' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'GoogleCrashHandler.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'GoogleCrashHandler64.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'thunderbird.exe' - '122' Modul(e) wurden durchsucht
Durchsuche Prozess 'dwwin.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'avcenter.exe' - '148' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '80' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '113' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'vssvc.exe' - '32' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchUI.exe' - '116' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbar-1.09.3.1001.exe' - '66' Modul(e) wurden durchsucht
Durchsuche Prozess 'cmd.exe' - '17' Modul(e) wurden durchsucht
Durchsuche Prozess 'conhost.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbar.exe' - '95' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskhostw.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'FRST64.exe' - '97' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'chrome.exe' - '55' Modul(e) wurden durchsucht
Durchsuche Prozess 'rundll32.exe' - '39' Modul(e) wurden durchsucht
Durchsuche Prozess 'Suo12_StartupManager.exe' - '87' Modul(e) wurden durchsucht
Durchsuche Prozess 'backgroundTaskHost.exe' - '48' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchProtocolHost.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchFilterHost.exe' - '22' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmiprvse.exe' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'TrustedInstaller.exe' - '19' Modul(e) wurden durchsucht
Durchsuche Prozess 'TiWorker.exe' - '41' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsass.exe' - '83' Modul(e) wurden durchsucht
Durchsuche Prozess 'WinLogon.exe' - '28' Modul(e) wurden durchsucht

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '6103' Dateien ).


Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\' <SYSTEM>
Beginne mit der Suche in 'D:\' <DATEN>


Ende des Suchlaufs: Dienstag, 12. April 2016  16:57
Benötigte Zeit:  2:44:07 Stunde(n)

Der Suchlauf wurde vollständig durchgeführt.

  68146 Verzeichnisse wurden überprüft
 1367215 Dateien wurden geprüft
      0 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      0 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
 1367215 Dateien ohne Befall
  21388 Archive wurden durchsucht
      0 Warnungen
      0 Hinweise
 1561920 Objekte wurden beim Rootkitscan durchsucht
      0 Versteckte Objekte wurden gefunden

Und wieder 3 neue Meldungen:
TR/CRYPT.ZPACK.ojow
TR/CRYPT.ZPACK.obmb
TR/CRYPT.ZPACK.gen2

cosinus 15.04.2016 08:15

Bitte Avira deinstallieren. Das Teil empfehlen wir schon seit Jahren aus mehreren Gründen nicht mehr. Ein Grund ist ne rel. hohe Fehlalarmquote, der zweite Hauptgrund ist, dass die immer noch mit ASK zusammenarbeiten (Avira Suchfunktion geht über ASK). Auch andere Freewareanbieter wie AVG, Avast oder Panda sprangen auf diesen Zug auf; so was ist bei Sicherheitssoftware einfach inakzeptabel. Vgl. Antivirensoftware: Schutz Für Ihre Dateien, Aber Auf Kosten Ihrer Privatsphäre? | Emsisoft Blog

Wenn wir hier durch sind, kannst du auf einen anderen Virenscanner umsteigen.

Gib Bescheid wenn Avira weg ist.

Ikarius 15.04.2016 09:28

Danke für deine Hilfe

Avira ist deinstalliert.

cosinus 15.04.2016 09:40

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Ikarius 15.04.2016 11:33

Erledigt 2 Funde. Beim zweiten Durchlauf wurde nichts gefunden.

Code:

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2016.04.15.02
  rootkit: v2016.04.09.01

Windows 10 x64 NTFS
Internet Explorer 11.212.10586.0
hauptaccount :: hauptaccount-PC [administrator]

15.04.2016 10:46:23
mbar-log-2016-04-15 (10-46-23).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 599905
Time elapsed: 36 minute(s), 57 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|influenceentrance (Backdoor.Andromeda) -> Data: C:\Users\hauptaccount\AppData\Local\Temp\Influence_pleasure\influence-categories.exe -> Delete on reboot. [fe20b3fcc1d81d1944ba9396d42e6f91]

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\hauptaccount\AppData\Local\Temp\Influence_pleasure\influence-categories.exe (Backdoor.Andromeda) -> Delete on reboot. [fe20b3fcc1d81d1944ba9396d42e6f91]

Physical Sectors Detected: 0
(No malicious items detected)

(end)


cosinus 15.04.2016 11:56

Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Ikarius 15.04.2016 13:55

Code:

# AdwCleaner v5.111 - Bericht erstellt am 15/04/2016 um 14:05:52
# Aktualisiert am 14/04/2016 von Xplode
# Datenbank : 2016-04-11.4 [Server]
# Betriebssystem : Windows 10 Home  (X64)
# Benutzername : hauptaccount - hauptaccount-PC
# Gestartet von : C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum

***** [ Dienste ] *****


***** [ Ordner ] *****

[-] Ordner gelöscht : C:\Program Files (x86)\MocaFlix
[-] Ordner gelöscht : C:\Program Files (x86)\myfree codec
[-] Ordner gelöscht : C:\ProgramData\Babylon
[-] Ordner gelöscht : C:\ProgramData\SaveAs
[-] Ordner gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Detective
[-] Ordner gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
[-] Ordner gelöscht : C:\Users\hauptaccount\AppData\Roaming\Babylon
[-] Ordner gelöscht : C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\ICQToolbarData

***** [ Dateien ] *****

[-] Datei gelöscht : C:\END
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d16fk4ms6rqz1v.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d22j4fzzszoii2.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d22j4fzzszoii2.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d23716qn9q7omq.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d31bfnnwekbny6.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d31bfnnwekbny6.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_dsms0mj1bbhn4.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_dsms0mj1bbhn4.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d1733r3id7jrw5.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d1733r3id7jrw5.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d3mwhxgzltpnyp.cloudfront.net_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d3mwhxgzltpnyp.cloudfront.net_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_primeshare.tv_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_primeshare.tv_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.veoh.com_0.localstorage-journal
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Goodgame Empire.lnk
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Goodgame Empire.lnk
[-] Datei gelöscht : C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\invalidprefs.js

***** [ DLLs ] *****


***** [ Verknüpfungen ] *****


***** [ Aufgabenplanung ] *****


***** [ Registrierungsdatenbank ] *****

[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0C1284BA-4F3A-41C6-94B5-77446F5948A9}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
[-] Schlüssel gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Wert gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
[-] Schlüssel gelöscht : HKCU\Software\BABSOLUTION
[-] Schlüssel gelöscht : HKCU\Software\IGearSettings
[-] Schlüssel gelöscht : HKCU\Software\Myfree Codec
[-] Schlüssel gelöscht : HKCU\Software\OCS
[-] Schlüssel gelöscht : HKCU\Software\AppDataLow\Software\lyrixeeker
[-] Schlüssel gelöscht : HKLM\SOFTWARE\ICQ\ICQToolbar
[-] Schlüssel gelöscht : HKLM\SOFTWARE\Myfree Codec
[-] Schlüssel gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
[-] Schlüssel gelöscht : HKU\.DEFAULT\Software\AVG Secure Search
[-] Schlüssel gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
[-] Schlüssel gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467

***** [ Internetbrowser ] *****

[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("aol_toolbar.default.homepage.check", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("aol_toolbar.default.search.check", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("browser.search.defaulturl", "hxxp://websearch.mocaflix.com/?l=1&q=");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.admin", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.aflt", "babsst");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.autoRvrt", "false");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.dfltLng", "de");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.excTlbr", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.id", "987affa8000000000000001f3f0bea1d");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.instlDay", "15953");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.instlRef", "sst");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.newTab", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.prdct", "delta");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.prtnrId", "delta");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.rvrt", "false");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.smplGrp", "none");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.tlbrId", "base");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.614:38:53");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta_i.babExt", "");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119357&tsp=4996");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.enabledItems", "{35e67f97-7787-40cf-897d-5c56a5625e15}:1.0,helperbar@helperbar.com:1.0,{BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.0,{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9,{2D[...]
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.helperbar.BackPageActive", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("extensions.helperbar.Visibility", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.allowSendURL", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.defSearchChange", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.engineVerified", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.geolastmodified", 1314439888);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.history", "firefox%201%20gb%20arbeitsspeicherreason%20dubstep%20refilleko%20fresh%20schlechter%20rappergarath%20bale%20interapfeltee%20pulverjim%20beam%20colawodka%20[...]
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.hpChange", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.icqgeo", 49);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.installTime", "1313785996");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.newtab_state", "0");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.numberOfSearches", 0);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.previousFFVersion", "6.0");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.suggestions", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.uninstStatSent", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.uniqueID", "130768707113076869971307788527783");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1314887405);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.userEngineApproved", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.userHpApproved", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.voucherWasShown", 0);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.xmlEnableHomePageDsGuard", true);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false);
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("icqtoolbar.xmlLanguage", "de");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?lang=$locale_id;&toolbar_version=$ITEM_VERSION;&crg=$cargo;");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*.*.facebook.com/.*.*.google.com/.*.*.google.co.in/.*.*.google.com.br/.*.*.google.es/.*.*.youtube.com/.*.*.yahoo.com/.*.[...]
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://isearch.avg.com?cid=%7B4b302b38-8a7e-460c-97ac-e0bd9e661a6a%7D&mid=5979fa0c89cf47d0ac7cd15679ef03ee-55c1fe746cf13bd231daebd5f8592[...]
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolbar_version=$ITEM_VERSION;&crg=$cargo;");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.scripts.2.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.scripts.3.domain-blacklist", ".*.google..*.*.bing..*.*.live..*.*.msn..*.*.yahoo..*.*.youtube.com.*.*ask.com.*.*.sweetim.com.*");
[-] [C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js] gelöscht : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?crg=3.1010000.10025&barid={BA6F0FDC-206E-11E2-B4EE-001F3F0BEA1D}");

*************************

:: "Tracing" Schlüssel gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [19079 Bytes] - [15/04/2016 14:05:52]
C:\AdwCleaner\AdwCleaner[S1].txt - [19083 Bytes] - [15/04/2016 14:01:09]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [19227 Bytes] ##########

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 10 Home x64
Ran by hauptaccount (Administrator) on 15.04.2016 at 14:14:40,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 344


Successfully deleted: C:\Users\hauptaccount\AppData\Roaming\iobit\driver booster (Folder)
Successfully deleted: C:\ProgramData\iobit\driver booster (Folder)
Successfully deleted: C:\ProgramData\pc drivers headquarters (Folder)
Successfully deleted: C:\ProgramData\productdata (Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{0007591A-9148-4593-9D0D-C128430D7DC4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{02013332-C2DE-499E-9913-88A873929B00} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{02270A0D-7567-4319-AE32-74C62E490944} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{0406212B-0658-482F-A3BC-A4C751DEB82C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{049DF039-B2FD-4EAE-8480-EC73226C3525} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{056F71C9-FEB8-40BE-984A-DC0F8BC55A80} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{057B02F2-0A38-4537-9920-54CD8A91AFCD} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{061F40F5-62B7-47B4-8D2D-202F35F4376A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{066D1B86-C9FB-466D-A365-27BEB6433EFC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{07B4D532-1421-4C13-82CE-77B53086D0C2} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{080F6D2A-E4B3-420F-A65C-329466DD5BE2} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{086EFD0C-1565-49F7-BA01-03710CED10F8} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{09301D17-6374-4155-94DB-0C964130DF90} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{099FF630-EE30-4009-B500-3E896E28347D} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{0A7486DE-BDA2-4545-827A-6705619B0E27} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{0AAF47E9-3A9B-4D9D-A82B-72D88CBC59AC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{0C5CCF4C-F11E-40FC-89F2-8F7E72D2145F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{12C3AEC5-681C-4D51-BCF3-14F624D05FC5} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{159A1583-96B5-440C-AB9C-0622A52C5CD1} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{15ABD6B4-D05C-4862-A943-269450A3D666} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{16236752-E1DE-4DA4-B3C3-E7D1D48EDB87} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{16FAAD12-5525-482B-BCB6-C527911983B2} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{17732C99-3200-40A5-9A44-796EC6899850} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{1957C126-C015-423C-9637-80D25A95F06F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{19BADA0A-0600-47D8-9788-02C729DE68C9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{19C9C96E-9375-4BD2-9D57-6786F1B8B1F5} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{1A7A05A3-0974-4A42-8D23-D326827E6C81} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{1C6B0F8E-5CC5-4624-8AF2-8AC8946DE58E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{1D37B25E-BEEF-4B6D-A606-018C2B1BDF1B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{1D72BA5D-6537-4ABE-A7C7-825F4B6100E9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{1F765FBA-034A-421A-BEB2-0810521DA98C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{21450900-3C9F-4457-8479-8CBC0B60DA28} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{24CEE257-4815-4260-8AAE-6C49B3FC45AB} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{24D33FB1-0C94-455D-997D-DD6F5B45EC52} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{261442E1-5733-413B-AC68-7C190AF62C67} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{272C62A6-9375-434B-881A-CF9DD0EDA89B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{273B00E7-9839-451C-92BC-C50565CEEA98} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{275CA307-E435-42B6-8BAD-53E90178D903} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{27C34FB4-1B69-460E-87D7-3B61DDF496C1} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{29A32DF5-043E-43BD-832A-4754E8C925AB} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{29CDD25C-25C0-403A-A1B5-4222F1B6525B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{2A4D8C52-012A-47D4-A455-5F95D97DEC60} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{2C7708C1-A2DA-4551-91FC-28B71772191E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{2C9BF027-B010-4B39-B4BD-6F0784C86071} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{2EC6A270-6CEA-4EFA-ADDC-1C6F86E1CEA0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{308F4006-89A6-4546-A636-943CCBB1CD8E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3154B260-E693-4667-B48A-44CADD468C23} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{31F15C46-DA5D-478A-8CD3-F900096357B0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{32031D2D-8B72-48BD-A5E4-07C6897CFC57} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{32A2B3F2-FEA7-4CF6-BD99-421F213C0D08} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{32BF1780-9D80-4062-AAA8-C42F9A1B9D6E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{33C30793-2BDF-454F-B974-F38630F34509} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{34615BC7-1A83-42CF-9555-6F42555A02F1} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{34DF6FE4-AFB0-468C-9580-DF94EF6692E6} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3597692A-D701-4A7C-9631-0E9A02C66F85} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{369683FD-9C61-4309-A584-6D1C0F4D39BC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{387DEECE-54CA-432F-B5B3-54C844C459BC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{38BBEA1A-1AF6-4075-8054-FF0A27F6248B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{39289E46-DFC2-417F-8474-F425AE7C7F23} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{39AA07BF-071A-427D-B4AB-D654AC974994} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{39BF1203-BF86-44C2-BF82-594EA045300D} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3A2CD03B-2C2C-42CE-88A1-EF55F1E60E0D} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3A385F57-CC8B-484D-9103-519E9E923F56} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3AE5DEBC-B39F-434D-9AEA-13808D9B3466} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3B27D324-86D4-4F21-9C55-34B7BBF9ABBB} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3B59C93C-8C7E-4EF8-AE81-1EE9949DCBB6} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3D95EE13-A3B4-4A16-BF2D-2BC4BAC0569E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3DC83643-2E8B-4911-AC9C-D5A22006E122} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3E5D039D-F2D4-4989-AE7A-07275398F5FA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3F26FFE4-3986-4E63-96D7-B2406E6A93C5} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{3F3EDE74-07DF-41DE-8FAA-13539AF507CC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{402980F2-FD91-4DD6-B93F-D928E0830A14} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{40E37A3C-D78A-4DEB-B55F-AD4846D12AC8} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{416D0B63-051A-4C08-816C-0B4D8414CCD0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4316C411-7FEA-411F-AF74-057B4ABCF05E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{434B21EE-B35E-47BF-AC2D-6304E94FFC1C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4360983E-B917-47B9-9AB2-3D3B18D783E9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{43B29C39-0E02-4A4E-BF32-73FDFF34B2D4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{44910A4B-6A3F-4BA0-ADF0-9597F68137FF} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{458E5FE2-3B8D-4FC6-BEFC-FCC7DEBC283B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{46AB4CD9-8031-459E-9F37-E0598FE933FA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4849ED54-C9E9-4818-B4CB-D52690046B93} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{48EBD5D1-98A3-483B-9295-4447E4B2D016} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{491E1CB3-5F25-4795-8C57-6A551CD470D7} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4946655E-B290-400A-9738-E23D8FD7C7C4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{497D44A4-0BBC-4640-9343-0667D68AE6CA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4A65DE55-12A9-4260-BABA-07BA0FC377DC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4AE4A592-A897-4B14-8D24-157A8EC8B48F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4B4F7586-53F0-4F0B-866B-BBEF5553C867} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4C2515EE-9AB5-4D90-974F-8811CE5D5124} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4E24DFA3-6A86-412C-A721-B7ADED1A7D0C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4E43E715-9C47-4730-8BC4-4B1BC149AEEA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4F026DB7-6076-408C-9E08-335BC80FEC23} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4F5DB07D-F0A8-4528-B8EA-6E222DC74F7A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{4FA66637-9841-4011-9C87-CD0B49556C1A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{50A82218-19F6-460E-B5FD-713CA6E9E011} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{50CEAB7B-289B-4F55-8C60-89FC391B7285} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{51960875-AE0E-4E58-BE0F-553B86827402} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{531A4D76-6755-455C-9887-9C4FEC128F3B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5354717D-BF75-4C99-B107-C10DCD50120B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{53D3DC67-8532-4BB0-8252-6DB09A8CA810} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{54F75816-7F78-4974-9F44-E52031A3E5CC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{554CE741-E6B2-4925-A9BE-6D9EBABB8928} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{55C270E4-0779-4ADC-BD17-01983ABD3D9C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{55D3C98B-AE52-41DD-BDFA-C3D5448D3346} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{56E96539-5331-459E-BAAF-5FFA6D65633B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{57302FFE-12E0-4AAE-BEE1-B64272BC3D91} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{57C32189-D066-4D97-9C03-57CFC8EEFD8A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{58F86E49-1D46-4F28-A93E-9D909A3B9380} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5A0F8A21-DDA2-4BB9-B0C6-D60F5435D01C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5A810A78-5B79-4FA0-86B4-A9D4C5B2C3DE} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5ADE4C80-B6E2-4297-9C5C-B8B51235C088} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5B961029-B6A9-4DE1-800D-44404DA7BE22} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5BB67138-E648-44F8-9383-A8146CD04ACE} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5E16A9DB-28A0-4404-BDC0-738B9B18A5B1} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5F68AAB4-32F2-444B-88C0-C45F1041631B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5F6B2ED2-D11D-4FDD-8241-8766C53EA090} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{5F7624DC-B3AA-48E5-B822-13E7D371544F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{61817B61-272D-48F5-9571-9A60ABF08E67} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{62EBA30E-8351-4C58-8CFD-B4214DBBE831} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{639987BD-E135-4F2E-9857-231CB5D2B1B5} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{63A7E860-4B50-47A6-BFF2-C4A2E89C56E4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{64AEB6EF-C400-4671-BAC6-B8FFF0DB004C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{65022B8E-889E-4275-9B2C-B2F3A002273F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{677F4A2B-51F1-483F-A148-46264484DF80} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{6925B10E-7870-470B-81EE-DE0364C2A097} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{695A35C0-16DF-4C07-8660-0EF831A48432} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{6B99A2F8-560A-4779-A3DF-EC67DD47B9AE} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{6C950791-827E-40A0-9F25-C319C3DC6BA7} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{6CE0C2D3-213B-4AD5-B24A-CEEDBB3741D5} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{6DD1A06E-42D3-45F7-9EB7-BE8A44649DC9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{6E13BD04-B2A6-4D23-A7C8-7169AB7BDB74} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{6E498E5D-D405-4C99-96CF-36ECA32D7E07} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{6FC9AC67-558E-42D1-8688-C37AB4610694} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{722EE48E-DEE3-4414-A6E5-1B58F1EBBB16} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{72D7C949-7004-45BB-9C44-E2C9BE2E347E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{72F65944-41C8-4F47-8432-D88E548476E4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{730E0FD0-30FC-4DBA-A946-D652EC39DEE6} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{73C2A516-D585-431A-A399-8CA17721C2AC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{741D50AF-E679-4F51-8DAF-DE7D38CA33D8} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{763B9BA3-715B-45AD-A211-A7FFF8E009D4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{763EC8F9-0D23-4A08-BBA6-13E13833661A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{774761E0-E363-43D6-9D4E-E3A7D7A3A395} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{7769D636-BBE2-486C-BF62-8BC77C106DE4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{779FC79A-AC19-42CA-91A9-D74833E337B0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{7ABFB076-AC40-4766-BE63-3B2ED460656D} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{7C5471CD-E3DA-4A68-A8F1-53160ACDAE1A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{7CD3DFD1-ABD3-46FB-A6B6-56BB918C76B0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{7CD522EC-DFDD-4FE9-9D7D-AA913D18E4DC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{7D15E79F-34AA-4EE8-A0D5-509D8F8C3CEB} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{7DF2535C-EE46-47D8-B186-09724E6F47D9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{8093160E-4490-44FA-88B9-BAC12A52A880} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{80D7C6D0-0F11-4471-B07F-F158A0FC9A22} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{81AD3536-F7A2-4C6E-92B3-A2E84903225B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{82B6AF75-385A-4857-8464-5074CC89C003} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{844453E9-F71F-4FB3-BA2B-36FA3012B692} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{84480753-524E-4536-ACBA-A53C8BFF6813} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{8754A3A9-FB0E-4B55-9A3A-9FB2EA94DA56} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{8758FEC7-185F-4FDC-AA45-58FC44FB0ECE} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{87D0CF94-A957-4E2A-9D64-94A609B160F0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{88F3B14C-3C41-43C0-B7A9-F662434ADB50} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{895B434C-3153-4517-BEF8-85DDEF762B23} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{898380EE-EC3B-473C-8533-59A3BA50BDAC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{8B487DD0-61A1-4608-B4B0-E99CA577E08D} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{8C1C7395-2B18-439F-B803-2AF5951E1AB9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{8C42C74E-3409-4D15-B13E-0A225629C558} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{8E00BF15-472E-4257-9495-7C7109A147A3} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{8F63E4CE-F4B1-4A59-95C6-ECEF7F596717} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{905DDFF9-5FCF-4B65-A5E1-DC3FCFE2ED03} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{91164D3B-8B34-42E1-8E8C-BBA80E243A08} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{925C61E6-7C7A-483D-AD9A-19B9F62938E3} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{94609B9B-ED0A-4A55-A419-B5B281500046} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{9482ADF1-B0DF-4FCD-A8C5-ABAAA904353E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{94F83DB9-5CE8-4A77-A6A9-165D6E6C6C52} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{955937DA-C21F-4F4D-BAC0-96379C71BE29} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{95AC21E7-9E70-445B-AA49-1A0182706378} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{96516283-B4CA-4E57-B904-B29A1905A918} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{97263FA9-B8FB-437A-848A-ADF77CF2AB5E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{98127512-48D6-4FF4-920A-BB218AD9A252} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{98C1DB8D-C96F-4FC4-87E4-4484B501C95F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{9960E3C4-6CF4-4B36-824D-1E395316125B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{99998C45-A52A-4FE0-B909-096294CBDBEA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{99E92BAC-37EB-42B5-8AFF-46B3BCDEC35E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{9ACA1755-9183-402E-A4B9-A431711813F9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{9B1F5F28-1200-4C06-B85C-0FA8FDC65F48} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{9CA2FFB0-3E1F-4784-9675-5CBA2E679ED0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{9F3B5658-9ABA-4211-98F8-268D0B2EB039} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A0DDF7C5-156D-431A-9BE4-989AF8B3E9AC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A0FDA378-230D-42F8-A96B-B765C6AB96CB} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A11AF913-5F0C-4849-AB41-4370BC2B8463} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A1353DC8-A940-4860-811B-9E9F77D054DA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A1BBE231-EC42-4EEE-9260-ABF4B66FAE67} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A22CD5B9-FBA2-44CF-BAD7-2870F128210F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A2461BCD-E8B0-47D7-BA34-FD75D02952FA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A2761993-9088-4C47-A11B-C71514C13478} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A3001112-8E73-407B-9FA6-255383BA592C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A317E360-5B71-41F3-B371-8A461641AE01} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A38CEC70-F324-40DD-8DB6-3FE3A6EDFEB2} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A39DFAF9-03DF-4E14-91B6-45DE23BD7E95} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A4B48989-1113-45CF-A6F1-70D1A64B5738} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A50BA8EB-8FE6-4F2A-986B-5476B99D0615} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A634D128-464F-4D07-A9F2-97F189CB903D} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A65F0331-674C-40DF-8852-C83D2DD9F5C9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A6F94B7D-605A-4D3E-AC49-FE3E388EDCCD} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A872CACE-8AC0-4861-8753-D945106C218A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A88A4B8D-8E33-4496-9B61-82FF7DE01EFA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{A9DC1ED8-6D35-416A-8BAA-750400CD0F26} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{AA178718-37DB-4A0E-B9C2-C749C643D872} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{AC47628D-B729-4D62-A60A-019F49736114} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{ACECE6CC-5796-44AB-84AE-C4992D654B71} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{AD3E77BA-8ABB-409E-AC37-90576E1AED1E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{AD5E112B-2E0F-412E-9788-E270C1725986} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{ADADF14A-7E7D-4A5E-9C44-AD94B9A9EDDC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{AE342100-5410-449E-ABD5-711E087053B9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{AF7E84B7-F4A0-41A3-8E2E-ABA732E2C04B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B116FE6E-4411-469F-83DB-29AD07150B01} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B13F6549-A362-40EE-92E7-9C92543A880F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B1A61479-0989-450C-B445-2AC1433A4C3B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B24BDEF9-2AC2-4EBD-A3CD-77F6A6378580} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B35EA61C-BA00-4E08-B809-89C2CB558993} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B4102F45-2376-4A92-9882-F21F2B437430} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B509C7A3-C5D2-4FF6-99D1-5B6D581A30E1} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B6051579-0D29-4720-B5DB-94E33B47EB56} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B6907DB7-0FA2-46EB-BC12-26A2141B87C2} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B72F4FAD-AE66-4E34-80A0-47B828519B55} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B7F7F487-6FA3-4324-9D93-DE1A7487FE73} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B840DAAA-A2BA-4E09-A39C-3E08400A448E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B8452ABD-3C3B-4F24-895F-97C955040D6E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B8660C03-BDB4-4132-BDE9-55FAAB82B823} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B970779A-2486-4C3F-B449-2D165A1C6D6A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B992E889-FD69-4975-B736-841AB1DC8070} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B9B998AC-D1F8-4C8F-BADE-0F4070C288C3} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{B9F63342-D662-4E49-B86B-E9CAD63B0796} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{BA41DAE0-9CD4-4F0B-80CC-0CF6827ED310} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{BAAFDA38-F596-4D41-80BE-FC57AC298275} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{BAB3406A-E30B-4876-9C92-CD1626275043} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{BACC864F-3422-4F33-96E7-BAA740EF1CF7} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{BB8C93C3-4262-420A-8624-7925AAB54E7E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{BC97F8DB-09F1-40D7-ADF7-B832C2A70A69} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{BEBE4574-ADCB-4311-BC21-82067AE2E8B0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{BFEC4C43-F706-4EE6-966C-4BC56195DD26} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C07783E3-30B3-4162-BD87-FDDE12EE4D06} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C0C3A657-AE36-4B71-83F6-7F5B8107D562} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C0EA8446-A1BD-4A5F-B5DA-0F45DEDA5722} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C251BCA7-BBDA-43C3-8F77-944BD4F3A6EF} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C262FDEA-C73B-4B4A-B11A-DBA50509A23E} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C287BDD1-E3AD-4FD8-99B0-6A23DE5A339A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C2A29B47-26D8-40E1-B526-7295B7199BC9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C34EB2F0-0A14-4D02-A745-0585D789B890} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C3BCA19F-E36D-4F28-8102-D4A4521B66AF} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C3D07313-6656-4F7D-8D72-C9EEB3428E3F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C472BA57-B8AA-4723-A295-EAE7198138C0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C50911F0-4AD9-4E0C-A398-CEF8852CE8C5} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C5BA9FA3-D3B9-4F09-A912-DC0AEBCEFCA0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C5D7831F-6886-49C4-AEFB-25B9DDBE842C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C80B9EA7-7A09-4D2F-92E6-D5173E1D0A1C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C84D2047-282F-4C20-B8B8-9B5F23FE3859} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C94AA6EF-643E-4A39-971D-24FB93814CE2} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{C960BA1E-211C-4AF4-8DFA-34426D03ABC0} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{CAE4C7E0-67AE-4894-8C42-BD0555D4A7F4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{CB172D51-A580-4859-B45F-37CDE74864B8} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{CB815D0D-D2EA-432C-A6EA-9E21226DA62F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{CC6764A1-3EAE-4F7D-89F2-BDED4D39AEF2} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{CCDB19FB-15CE-41EF-B9B7-25D5D0B8665F} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{CD018484-2A48-4D6F-97EE-E579A3A23A26} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D0846C34-B02A-490D-88CE-0412C406BFC3} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D0B564BD-7A74-4A50-B6E9-CB4238F784E1} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D0C4662D-B6C1-4CCF-AC05-70509D070C01} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D10B9BE3-3328-4032-80EC-B7D3E16E6253} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D28CE0DA-62DC-4DDA-9538-9C0BE0FA1097} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D38E546D-5A76-4DFF-B641-2FFE4932A065} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D44B9B3B-AEC9-4539-A7ED-7C3F1B55A620} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D4D3583A-38EB-48BA-A125-27ECB7A3A60C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D5011CF5-C18E-4330-A270-9BBDD1BA3A88} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D5D0155A-4374-484B-AF3F-61261C2E48F7} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D7EA274D-8536-4DD5-B6BF-E0012140CB90} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D8BF5148-7D9D-461B-B277-A9FDCF7B0FF4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D9854970-9DAD-4D69-ABD8-8AA649776DA2} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{D9C2E170-2372-4970-AB48-018C0CC25E37} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DA424C1B-2CBA-4066-826D-4E2113ED51B8} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DABBADA7-6F8E-4B18-B597-B32BA3E1C27C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DB294C6C-466D-4287-BA85-032681F7C954} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DBB0CBF9-B875-4A46-9F16-14B369A9950C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DC90759C-9E3C-4C64-80E9-6F69A637510D} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DD0E0E33-4C3B-4392-AFA4-8356D1803CDC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DE32DBB8-9587-4E84-BEF6-7AA32B27CCF1} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DEA00994-389D-45A3-B565-1053B270B822} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{DEF11BC7-EEDD-4C12-96F5-73955B00AB25} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E037D8FB-A698-4F0E-AD89-C776A7E46A33} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E091C630-8595-4994-ADB2-7FFEF621F0F6} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E1659BB5-4B62-40C8-B480-EBBD64900D47} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E2BEE288-B486-4F9F-96B9-B16775BA5959} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E3556DB9-3C88-4109-8D4B-23C4D705A9B7} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E5349766-51CA-48E7-A0EA-C1E00C5AF343} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E57A2340-8AEF-4DD0-AFA5-FD497FA6048D} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E593C3E5-9C52-489D-9798-14B365AFD4EC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E8123E13-1136-4256-A111-0F38340F3961} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E933DE1B-4514-4652-B8F3-D928C5F62C83} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{E9640ED4-36CC-44BA-BE8E-BBC5442A21AE} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{EB23EB0D-AC25-48A9-8C06-68BA0335C5E4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{EB871141-E06B-4651-A588-6BC8D2EA7062} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{EBFF8229-9907-443F-908E-0B4B15588C9B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{EC7F2A5C-54D7-4D90-8EB3-CCAB05F302E6} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{EE64DE2B-3FE5-4869-8E18-E5EA5E6A58BE} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{EE9B8F9F-6DEC-4ACD-8B18-9C7DF532BACA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{EF36BD90-D3BD-4109-B55B-B6591BF9680A} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{EFD3CE08-F734-4EB2-9F5A-E8CD000825EA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F09FC896-751D-4234-858E-67D0E76A6321} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F144236C-F230-4FB4-94AE-F577DDAAEAE6} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F1870CB4-B07D-40C3-99FF-568396160099} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F1B33E21-2983-4813-908B-43BAEFA88634} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F269F009-AAF0-422B-854F-3580E07341A5} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F2CFDDDB-4364-4934-85FD-02CD5F6BB2FD} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F35E2367-D082-4120-B536-83DC2BC4484C} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F36CD9DC-3F60-447C-BFB1-E986817F90A4} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F7E56D9D-28E6-4BC8-AE14-16508FBEF283} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{F826EF29-1B02-4C88-8A26-2DDEF14806FC} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{FA92CD23-0663-40A0-8B90-1B436B82A1E9} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{FACBFAF3-FCF2-4C28-87C7-8551AAC78E12} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{FC1217BE-E26C-4A32-8409-2CE0CAF663C6} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{FD029F47-5D57-4518-A394-1F465BCA2133} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{FE566EEC-481E-440B-9CA0-E7E8C3DC2CDA} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\{FFB1FCBA-73F3-46C8-BCCF-BA926B27BE1B} (Empty Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal (File)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage (File)
Successfully deleted: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal (File)
Successfully deleted: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de\searchplugins\mailcom-search.xml (File)
Successfully deleted: C:\Users\hauptaccount\AppData\Roaming\pdfforge (Folder)
Successfully deleted: C:\Users\hauptaccount\AppData\Roaming\productdata (Folder)
Successfully deleted: C:\WINDOWS\system32\Tasks\Driver Booster Scheduler (Task)
Successfully deleted: C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (hauptaccount) (Task)
Successfully deleted: C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_hauptaccount (Task)
Successfully deleted: C:\WINDOWS\system32\Tasks\Wise Turbo Checker (Task)
Successfully deleted: C:\WINDOWS\Tasks\Uninstaller_SkipUac_hauptaccount.job (Task)
Successfully deleted: C:\WINDOWS\Tasks\Wise Turbo Checker.job (Task)
Successfully deleted: C:\Program Files (x86)\iobit\driver booster (Folder)
Successfully deleted: C:\WINDOWS\prefetch\DRIVER_BOOSTER_SETUP_3.2.0.69-2D56DB56.pf (File)
Successfully deleted: C:\WINDOWS\prefetch\DRIVER_BOOSTER_SETUP_3.2.0.69-367708B5.pf (File)
Successfully deleted: C:\WINDOWS\prefetch\DRIVERBOOSTER.EXE-51D78DCC.pf (File)
Successfully deleted: C:\WINDOWS\prefetch\FREEBIGUPGRADE.EXE-FBD5A5A4.pf (File)

Deleted the following from C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\prefs.js
user_pref(extensions.50a80b9b3f4e0.scode, (function(){try{var d=[[\acebook\,\e4everything.co\,\3juices.s\,\safecart.com\,\securedshopgate.com\,\cleverbridge.com\
user_pref(extensions.unitedinternet.email.runonceNewUsersShown, true);
user_pref(sweetim.toolbar.RevertDialog.enable, false);
user_pref(sweetim.toolbar.UserSelectedSaveSettings, true);
user_pref(sweetim.toolbar.Visibility.VisibilityGuardLastUnHide, 0);
user_pref(sweetim.toolbar.Visibility.enable, true);
user_pref(sweetim.toolbar.Visibility.intervaldays, 7);
user_pref(sweetim.toolbar.cargo, 3.1010000.10025);
user_pref(sweetim.toolbar.cda.DisableOveride.enable, true);
user_pref(sweetim.toolbar.cda.HideOveride.enable, true);
user_pref(sweetim.toolbar.cda.RemoveOveride.enable, true);
user_pref(sweetim.toolbar.cda.returnValue, none);
user_pref(sweetim.toolbar.dialogs.0.enable, true);
user_pref(sweetim.toolbar.dialogs.0.handler, chrome://sim_toolbar_package/content/optionsdialog-handler.js);
user_pref(sweetim.toolbar.dialogs.0.height, 335);
user_pref(sweetim.toolbar.dialogs.0.id, id_options_dialog);
user_pref(sweetim.toolbar.dialogs.0.title, $string.config.label;);
user_pref(sweetim.toolbar.dialogs.0.width, 761);
user_pref(sweetim.toolbar.dialogs.1.enable, true);
user_pref(sweetim.toolbar.dialogs.1.handler, chrome://sim_toolbar_package/content/exampledialog-handler.js);
user_pref(sweetim.toolbar.dialogs.1.height, 300);
user_pref(sweetim.toolbar.dialogs.1.id, id_example_dialog);
user_pref(sweetim.toolbar.dialogs.1.title, Example (unit-test) dialog);
user_pref(sweetim.toolbar.dialogs.1.url, chrome://sim_toolbar_package/content/exampledialog.html);
user_pref(sweetim.toolbar.dialogs.1.width, 500);
user_pref(sweetim.toolbar.dialogs.2.enable, true);
user_pref(sweetim.toolbar.dialogs.2.handler, chrome://sim_toolbar_package/content/cdadialog-handler.js);
user_pref(sweetim.toolbar.dialogs.2.height, 150);
user_pref(sweetim.toolbar.dialogs.2.id, id_dialog_hide_disable_remove);
user_pref(sweetim.toolbar.dialogs.2.title, Option Dialog);
user_pref(sweetim.toolbar.dialogs.2.width, 530);
user_pref(sweetim.toolbar.highlight.colors, #FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0);
user_pref(sweetim.toolbar.keywordUrlGuard.enable, false);
user_pref(sweetim.toolbar.logger.ConsoleHandler.MinReportLevel, 7);
user_pref(sweetim.toolbar.logger.FileHandler.FileName, ff-toolbar.log);
user_pref(sweetim.toolbar.logger.FileHandler.MaxFileSize, 200000);
user_pref(sweetim.toolbar.logger.FileHandler.MinReportLevel, 7);
user_pref(sweetim.toolbar.mode.debug, false);
user_pref(sweetim.toolbar.newtab.created, true);
user_pref(sweetim.toolbar.newtab.enable, true);
user_pref(sweetim.toolbar.previous.browser.search.defaultenginename, );
user_pref(sweetim.toolbar.previous.browser.search.selectedEngine, );
user_pref(sweetim.toolbar.previous.keyword.URL, );
user_pref(sweetim.toolbar.scripts.0.addcontextdiv, true);
user_pref(sweetim.toolbar.scripts.0.callback, simVerification);
user_pref(sweetim.toolbar.scripts.0.domain-blacklist, );
user_pref(sweetim.toolbar.scripts.0.domain-whitelist, hxxp://(www.|apps.)?facebook\\.com.*);
user_pref(sweetim.toolbar.scripts.0.elementid, id_script_sim_fb);
user_pref(sweetim.toolbar.scripts.0.enable, false);
user_pref(sweetim.toolbar.scripts.0.id, id_script_fb);
user_pref(sweetim.toolbar.scripts.1.domain-blacklist, );
user_pref(sweetim.toolbar.scripts.2.addcontextdiv, true);
user_pref(sweetim.toolbar.scripts.2.callback, simVerification);
user_pref(sweetim.toolbar.scripts.2.domain-blacklist, );
user_pref(sweetim.toolbar.scripts.2.domain-whitelist, hxxps://(www.|apps.)?facebook\\.com.*);
user_pref(sweetim.toolbar.scripts.2.elementid, id_script_sim_fb);
user_pref(sweetim.toolbar.scripts.2.enable, false);
user_pref(sweetim.toolbar.scripts.2.id, id_script_fb_hxxpS);
user_pref(sweetim.toolbar.scripts.3.addcontextdiv, false);
user_pref(sweetim.toolbar.scripts.3.callback, );
user_pref(sweetim.toolbar.scripts.3.domain-whitelist, );
user_pref(sweetim.toolbar.scripts.3.elementid, id_predict_include_script);
user_pref(sweetim.toolbar.scripts.3.enable, false);
user_pref(sweetim.toolbar.scripts.3.id, id_script_prad);
user_pref(sweetim.toolbar.scripts.3.url, hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?si=3104&tid=chff1);
user_pref(sweetim.toolbar.search.external, <?xml version=\1.0\?><TOOLBAR><EXTERNAL_SEARCH engine=\hxxp://*google.*\ param=\q=\ /><EXTERNAL_SEARCH engine=\hxxp://sear
user_pref(sweetim.toolbar.search.history.capacity, 10);
user_pref(sweetim.toolbar.searchguard.UserRejectedGuard_DS, 0);
user_pref(sweetim.toolbar.searchguard.UserRejectedGuard_HP, 0);
user_pref(sweetim.toolbar.searchguard.enable, );
user_pref(sweetim.toolbar.searchguard.initialized_by_rc, true);
user_pref(sweetim.toolbar.simapp_id, {BA6F0FDC-206E-11E2-B4EE-001F3F0BEA1D});
user_pref(sweetim.toolbar.version, 1.9.0.0);



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.04.2016 at 14:17:14,89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


cosinus 15.04.2016 13:56

Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

http://www.trojaner-board.de/picture...&pictureid=611

Ikarius 15.04.2016 14:00

Jetzt warste sogar flotter als ich :D
Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (15-04-2016 14:35:34)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
() C:\Windows\SysWOW64\WinService.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe



==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [523144 2015-09-07] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [ReCycle Patch] => C:\Users\hauptaccount\Downloads\ReasonPatch(1).exe [184320 2016-02-18] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5361440 2016-02-26] (IObit)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chipaware] => C:\Users\hauptaccount\AppData\Local\Temp\Chip_cas\chip-concert.exe [166912 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [killingmidnight] => C:\Users\hauptaccount\AppData\Local\Temp\Killing-atomic\killing-inspection.exe [223744 2016-04-15] (Kerr-McGee company) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [kniteffect] => C:\Users\hauptaccount\AppData\Local\Temp\Knit-degree\knit_capture.exe [181248 2016-04-15] (NetZero APS) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe [205824 2016-04-13] (Walgreens Teams ) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [litigationattending] => C:\Users\hauptaccount\AppData\Local\Temp\Litigation-celebrity\litigationbrochure.exe [226296 2016-04-14] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [ltddirection] => C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe [242176 2016-04-14] (Rent-A-Wreck Soft) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [inrush-81] => C:\ProgramData\inrush-11\inrush-59.exe [797056 2016-04-15] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [influenceentrance] => C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe [191152 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [ltddirection] => C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe [242176 2016-04-14] (Rent-A-Wreck Soft) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe [205824 2016-04-13] (Walgreens Teams ) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [influenceentrance] => C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe [191152 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [kilobits-54] => C:\Users\hauptaccount\AppData\Roaming\kilobits-8\kilobits-58.exe [700416 2016-04-15] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-03-12] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\switcher-7.lnk [2016-04-15]
ShortcutTarget: switcher-7.lnk -> C:\Users\hauptaccount\AppData\Roaming\switcher-58\switcher-6.exe (IvoSoft)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 07 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\System32\winrnr.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SelectedSearchEngine,S:
FF Homepage: about:home
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome:
=======
CHR HomePage: Default -> hxxp://feed.helperbar.com/?publisher=QuickOC&dpid=QuickOC&co=DE&userid=35e67f97-7787-40cf-897d-5c56a5625e15&searchtype=hp&installDate=
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1136520 2015-09-07] (Autodesk Inc.)
R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [955168 2016-02-26] (IObit)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
R3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-15 14:35 - 2016-04-15 14:35 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument (2).txt
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:23 - 2016-04-15 14:23 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\kilobits-8
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 13:57 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-15 09:56 - 2016-04-15 09:56 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\switcher-58
2016-04-15 09:53 - 2016-04-15 09:53 - 00000000 ____D C:\ProgramData\hsupa-95
2016-04-15 07:38 - 2016-04-15 07:38 - 00000000 ____D C:\ProgramData\inrush-11
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-15 14:35 - 00029924 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 13:00 - 00092674 _____ C:\Users\hauptaccount\Desktop\Addition.txt
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-15 14:35 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:31 - 2016-04-12 12:31 - 02375168 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-03-24 16:09 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM(1).pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega
2016-03-22 08:49 - 2016-03-22 08:49 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-03-21 22:52 - 2016-03-28 00:40 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt
2016-03-21 22:52 - 2016-03-21 22:52 - 00000208 _____ C:\Users\hauptaccount\Desktop\c.txt
2016-03-21 17:49 - 2016-03-21 17:50 - 00000000 ____D C:\Users\hauptaccount\Desktop\CYBERGAUNER
2016-03-21 17:35 - 2016-03-21 17:35 - 01596260 _____ C:\Users\hauptaccount\Downloads\flyer.pdf
2016-03-21 14:27 - 2016-03-21 14:28 - 08186625 _____ C:\Users\hauptaccount\Downloads\wordpress-4.4.2-de_DE.zip
2016-03-19 16:25 - 2016-03-19 16:25 - 00000000 ____D C:\Users\hauptaccount\Desktop\Neuer Ordner
2016-03-16 14:41 - 2016-03-16 14:41 - 00180855 _____ C:\Users\hauptaccount\Desktop\Anmeldung.pdf
2016-03-16 14:40 - 2016-03-16 14:40 - 00067540 _____ C:\Users\hauptaccount\Desktop\Lebenslauf.pdf
2016-03-16 14:36 - 2016-03-16 14:36 - 00072497 _____ C:\Users\hauptaccount\Desktop\HBFSWI.pdf

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-15 14:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 14:15 - 2016-03-06 02:39 - 00000000 ____D C:\ProgramData\IObit
2016-04-15 14:15 - 2016-03-06 02:39 - 00000000 ____D C:\Program Files (x86)\IObit
2016-04-15 14:15 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-15 14:14 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-15 14:09 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-15 14:07 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-15 14:06 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-15 13:48 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-15 13:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-15 13:43 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 11:30 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-15 10:41 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-15 10:41 - 2011-11-27 22:19 - 00000000 ____D C:\ProgramData\Avira
2016-04-15 10:37 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-15 10:37 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-15 10:37 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-15 10:37 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 19:43 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-14 19:43 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-14 19:43 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-14 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-13 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-13 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 22:46 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-11 21:14 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 21:26 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-22 08:49 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-03-21 15:35 - 2011-01-17 18:08 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Paint.NET

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\hauptaccount\AppData\Local\Temp\Chip_cas\chip-concert.exe
C:\Users\hauptaccount\AppData\Local\Temp\Killing-atomic\killing-inspection.exe
C:\Users\hauptaccount\AppData\Local\Temp\Knit-degree\knit_capture.exe
C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe
C:\Users\hauptaccount\AppData\Local\Temp\Litigation-celebrity\litigationbrochure.exe
C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe
C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe


Einige Dateien in TEMP:
====================
C:\Users\hauptaccount\AppData\Local\Temp\avgnt.exe
C:\Users\hauptaccount\AppData\Local\Temp\libeay32.dll
C:\Users\hauptaccount\AppData\Local\Temp\msvcr120.dll
C:\Users\hauptaccount\AppData\Local\Temp\sqlite3.dll
C:\Users\hauptaccount\AppData\Local\Temp\ubiB78A.tmp.exe


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-11 12:08

==================== Ende von FRST.txt ============================


Ikarius 15.04.2016 14:01

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-15 14:36:01)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Enabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.5 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
IObit Malware Fighter 4 (HKLM-x32\...\IObit Malware Fighter_is1) (Version: 4.0 - IObit)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.2.1.126 - IObit)
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {0549C0DB-913F-4411-B577-6A5D9C5D6CEB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {06AD79CF-3049-4E43-A011-BABF6A39B4DF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {0FE5D209-B132-4972-B77D-AC0A78A3FF06} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {11DDFDAD-C35F-4461-90F9-16E92773139F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {15EE9EF4-3824-44CA-8DE2-6C81AD1785D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {242E14E3-E262-42F4-8B7B-A16CC962477C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {29CA4BA7-9156-431C-88C7-69741974F3CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {406C9318-4C8B-41DE-8D30-9294CF6DC20F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-01-18] (IObit)
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {6B7FC54F-AB46-4C0A-BB70-AC855322E160} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {CDDBBD48-0D3F-480D-8456-4181DB66F45F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FE8EB787-034F-4677-8391-7FCC25426EED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-04-13 14:13 - 2016-04-02 05:00 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 01675928 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libglesv2.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 00086168 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"

==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe

==================== Wiederherstellungspunkte =========================

24-03-2016 18:56:48 Windows Update
03-04-2016 15:49:10 Geplanter Prüfpunkt
12-04-2016 15:59:21 Geplanter Prüfpunkt
15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/15/2016 02:20:14 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/15/2016 02:15:02 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/15/2016 11:30:04 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/14/2016 05:48:07 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (04/14/2016 05:26:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm avscan.exe, Version 15.0.16.276 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1f08

Startzeit: 01d195846f8a0745

Beendigungszeit: 60000

Anwendungspfad: C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe

Berichts-ID: 15d47d51-0255-11e6-9bd6-001f3f0bea1d

Vollständiger Name des fehlerhaften Pakets:

Auf das fehlerhafte Paket bezogene Anwendungs-ID:

Error: (04/14/2016 05:11:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 48222797

Error: (04/14/2016 05:11:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 48222797

Error: (04/14/2016 05:11:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/14/2016 05:11:14 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 48221297

Error: (04/14/2016 05:11:14 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 48221297


Systemfehler:
=============
Error: (04/15/2016 02:19:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Autodesk Content Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/15/2016 02:19:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Autodesk Application Manager Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/15/2016 02:19:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "LiveUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/15/2016 02:17:52 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("255") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/15/2016 02:17:52 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("255") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/15/2016 02:17:52 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("255") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/15/2016 02:17:52 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("255") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/15/2016 02:17:52 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("255") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/15/2016 02:17:52 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("255") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.

Error: (04/15/2016 02:14:16 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT-AUTORITÄT)
Description: Ein neuer BITS-Auftrag konnte nicht erstellt werden. Die aktuelle Auftragsanzahl für den hauptaccount-PC\hauptaccount-Benutzer ("255") ist gleich oder größer als das durch die Gruppenrichtlinie angegebene Auftragslimit ("60"). Sie können das Problem beheben, indem Sie die BITS-Aufträge beenden oder abbrechen, für die kein Fortschritt festgestellt wurde, indem Sie sich den Fehler ansehen, und den BITS-Dienst anschließend neu starten. Falls der Fehler weiterhin angezeigt wird, bitten Sie den Administrator, die durch die Gruppenrichtlinie angegebenen Auftragslimits pro Benutzer und pro Computer zu erhöhen.


CodeIntegrity:
===================================
  Date: 2016-04-15 10:35:27.852
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-04-13 14:51:44.072
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-04-13 14:38:44.923
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-25 13:48:48.448
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-12 12:20:24.724
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-11 10:38:05.691
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-05 15:18:17.580
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\PROGRA~2\PDFCRE~1\PDFSpool.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\PDFCreator\PDFCreator.exe that did not meet the Microsoft signing level requirements.

  Date: 2016-03-03 22:35:31.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-12 10:22:01.825
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-11 06:29:22.290
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Speicherinformationen ===========================

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 44%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 2278.86 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 6333.6 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:102.79 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.69 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 15.04.2016 14:11

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    OptimizerPro
    IObit Malware Fighter 4
    IObit Uninstaller

  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 


Ikarius 15.04.2016 14:22

OptimizerPRO gibts dort nicht. Die andern beiden sind weg.

cosinus 15.04.2016 14:34

FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKLM-x32\...\Run: [ReCycle Patch] => C:\Users\hauptaccount\Downloads\ReasonPatch(1).exe [184320 2016-02-18] ()
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chipaware] => C:\Users\hauptaccount\AppData\Local\Temp\Chip_cas\chip-concert.exe [166912 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [killingmidnight] => C:\Users\hauptaccount\AppData\Local\Temp\Killing-atomic\killing-inspection.exe [223744 2016-04-15] (Kerr-McGee company) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [kniteffect] => C:\Users\hauptaccount\AppData\Local\Temp\Knit-degree\knit_capture.exe [181248 2016-04-15] (NetZero APS) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe [205824 2016-04-13] (Walgreens Teams ) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [litigationattending] => C:\Users\hauptaccount\AppData\Local\Temp\Litigation-celebrity\litigationbrochure.exe [226296 2016-04-14] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [ltddirection] => C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe [242176 2016-04-14] (Rent-A-Wreck Soft) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [inrush-81] => C:\ProgramData\inrush-11\inrush-59.exe [797056 2016-04-15] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [influenceentrance] => C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe [191152 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [ltddirection] => C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe [242176 2016-04-14] (Rent-A-Wreck Soft) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe [205824 2016-04-13] (Walgreens Teams ) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [influenceentrance] => C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe [191152 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [kilobits-54] => C:\Users\hauptaccount\AppData\Roaming\kilobits-8\kilobits-58.exe [700416 2016-04-15] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: []
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\switcher-7.lnk [2016-04-15]
ShortcutTarget: switcher-7.lnk -> C:\Users\hauptaccount\AppData\Roaming\switcher-58\switcher-6.exe (IvoSoft)
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 07 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\System32\winrnr.dll"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "type", 1
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
HR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
C:\Users\hauptaccount\AppData\Roaming\kilobits-8
C:\Users\hauptaccount\AppData\Roaming\switcher-58
C:\ProgramData\hsupa-95
C:\ProgramData\inrush-11
C:\ProgramData\Avira
C:\Users\hauptaccount\AppData\Roaming\IObit
C:\ProgramData\IObit
C:\Program Files (x86)\IObit
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
cmd: netsh winsock reset
removeproxy:
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Ikarius 15.04.2016 14:58

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-15 15:46:17) Run:1
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKLM-x32\...\Run: [ReCycle Patch] => C:\Users\hauptaccount\Downloads\ReasonPatch(1).exe [184320 2016-02-18] ()
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chipaware] => C:\Users\hauptaccount\AppData\Local\Temp\Chip_cas\chip-concert.exe [166912 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [killingmidnight] => C:\Users\hauptaccount\AppData\Local\Temp\Killing-atomic\killing-inspection.exe [223744 2016-04-15] (Kerr-McGee company) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [kniteffect] => C:\Users\hauptaccount\AppData\Local\Temp\Knit-degree\knit_capture.exe [181248 2016-04-15] (NetZero APS) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe [205824 2016-04-13] (Walgreens Teams ) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [litigationattending] => C:\Users\hauptaccount\AppData\Local\Temp\Litigation-celebrity\litigationbrochure.exe [226296 2016-04-14] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [ltddirection] => C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe [242176 2016-04-14] (Rent-A-Wreck Soft) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [inrush-81] => C:\ProgramData\inrush-11\inrush-59.exe [797056 2016-04-15] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [influenceentrance] => C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe [191152 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [ltddirection] => C:\Users\hauptaccount\AppData\Local\Temp\Ltd_principle\ltd_aye.exe [242176 2016-04-14] (Rent-A-Wreck Soft) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [manchesterbeastality] => C:\Users\hauptaccount\AppData\Local\Temp\Manchester-economics\manchester-lawyer.exe [205824 2016-04-13] (Walgreens Teams ) <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [influenceentrance] => C:\Users\hauptaccount\AppData\Local\Temp\Influence_biography\influence-burner.exe [191152 2016-04-15] () <===== ACHTUNG
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [kilobits-54] => C:\Users\hauptaccount\AppData\Roaming\kilobits-8\kilobits-58.exe [700416 2016-04-15] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Policies\Explorer: []
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\switcher-7.lnk [2016-04-15]
ShortcutTarget: switcher-7.lnk -> C:\Users\hauptaccount\AppData\Roaming\switcher-58\switcher-6.exe (IvoSoft)
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 07 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ACHTUNG: LibraryPath sollte sein "%SystemRoot%\System32\winrnr.dll"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "type", 1
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
HR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
C:\Users\hauptaccount\AppData\Roaming\kilobits-8
C:\Users\hauptaccount\AppData\Roaming\switcher-58
C:\ProgramData\hsupa-95
C:\ProgramData\inrush-11
C:\ProgramData\Avira
C:\Users\hauptaccount\AppData\Roaming\IObit
C:\ProgramData\IObit
C:\Program Files (x86)\IObit
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
cmd: netsh winsock reset
removeproxy:
emptytemp:
       
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ReCycle Patch => Wert erfolgreich entfernt
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 9 => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\chipaware => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\killingmidnight => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\kniteffect => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\manchesterbeastality => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\litigationattending => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\ltddirection => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\inrush-81 => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\influenceentrance => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ltddirection => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\manchesterbeastality => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\influenceentrance => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\kilobits-54 => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Wert erfolgreich entfernt
C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\switcher-7.lnk => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\switcher-58\switcher-6.exe => nicht gefunden.
Winsock: Catalog5 000000000001\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\system32\NLAapi.dll)
Winsock: Catalog5 000000000002\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\system32\napinsp.dll)
Winsock: Catalog5 000000000003\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\system32\pnrpnsp.dll)
Winsock: Catalog5 000000000004\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\system32\pnrpnsp.dll)
Winsock: Catalog5 000000000006\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\System32\mswsock.dll)
Winsock: Catalog5 000000000007\\LibraryPath => erfolgreich wiederhergestellt (%SystemRoot%\System32\winrnr.dll)
Firefox Proxy-Einstellungen wurden zurückgesetzt
FF NetworkProxy: "type", 1 => nicht gefunden
C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com => nicht gefunden.
HR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13] => Fehler: Kein automatisierter Fix für diesen Eintrag gefunden.
"C:\Users\hauptaccount\AppData\Roaming\kilobits-8" => nicht gefunden.
"C:\Users\hauptaccount\AppData\Roaming\switcher-58" => nicht gefunden.
"C:\ProgramData\hsupa-95" => nicht gefunden.
C:\ProgramData\inrush-11 => erfolgreich verschoben
C:\ProgramData\Avira => erfolgreich verschoben
"C:\Users\hauptaccount\AppData\Roaming\IObit" => nicht gefunden.

"C:\ProgramData\IObit" Ordner verschieben:

Konnte nicht verschoben werden "C:\ProgramData\IObit" => ist geplant bei Neustart verschoben zu werden.

C:\Program Files (x86)\IObit => erfolgreich verschoben

=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

15.04.2016  15:46    <DIR>          ..
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  15:46    <DIR>          .
15.04.2016  14:50    <DIR>          tdscdma-8
15.04.2016  14:23    <DIR>          kilobits-8
15.04.2016  14:20    <DIR>          IObit
15.04.2016  14:09    <DIR>          Wise Care 365
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
11.04.2016  21:14    <DIR>          Spotify
24.03.2016  16:09    <DIR>          vlc
22.03.2016  08:49    <DIR>          Dropbox
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
              0 Datei(en),              0 Bytes
              60 Verzeichnis(se), 110.443.196.416 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

15.04.2016  14:50    <DIR>          ..
15.04.2016  14:50    <DIR>          .
15.04.2016  14:50            1.030 tdscdma-00.lnk
              1 Datei(en),          1.030 Bytes
              2 Verzeichnis(se), 110.443.196.416 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

15.04.2016  15:46    <DIR>          ..
15.04.2016  15:46    <DIR>          .
15.04.2016  15:15    <DIR>          {BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:47    <DIR>          linear-0
15.04.2016  14:15    <DIR>          IObit
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
15.04.2016  10:41    <DIR>          Package Cache
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
30.03.2016  06:01    <DIR>          Origin
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:42    <DIR>          {FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11              133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
              2 Datei(en),            190 Bytes
              65 Verzeichnis(se), 110.443.192.320 Bytes frei

========= Ende von CMD: =========


=========  netsh winsock reset =========


Der Winsock-Katalog wurde zur�ckgesetzt.
Sie m�ssen den Computer neu starten, um den Vorgang abzuschlie�en.


========= Ende von CMD: =========


========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt


========= Ende von RemoveProxy: =========

EmptyTemp: => 6.4 GB temporäre Dateien entfernt.

Ergebnis der geplanten Datei-Verschiebungen (Start-Modus: Normal) (Datum&Uhrzeit: 2016-04-15 15:51:25)

C:\ProgramData\IObit => ist erfolgreich verschoben

==== Ende von Fixlog 15:51:26 ====


cosinus 15.04.2016 20:38

Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

http://www.trojaner-board.de/picture...&pictureid=611

Ikarius 16.04.2016 12:37

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (16-04-2016 13:31:38)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
() C:\Windows\SysWOW64\WinService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler64.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [523144 2015-09-07] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [doublers-63] => C:\ProgramData\doublers-9\doublers-80.exe [704688 2016-04-16] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [tempco-65] => C:\Users\hauptaccount\AppData\Roaming\tempco-5\tempco-23.exe [813056 2016-04-16] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jugfet-9.lnk [2016-04-16]
ShortcutTarget: jugfet-9.lnk -> C:\Users\hauptaccount\AppData\Roaming\jugfet-7\jugfet-9.exe (IvoSoft)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SelectedSearchEngine,S:
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome:
=======
CHR HomePage: Default -> hxxp://feed.helperbar.com/?publisher=QuickOC&dpid=QuickOC&co=DE&userid=35e67f97-7787-40cf-897d-5c56a5625e15&searchtype=hp&installDate=
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1136520 2015-09-07] (Autodesk Inc.)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
R3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-16 12:41 - 2016-04-16 12:41 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\jugfet-7
2016-04-16 12:38 - 2016-04-16 12:38 - 00000000 ____D C:\ProgramData\gravity-7
2016-04-16 12:24 - 2016-04-16 12:24 - 00000000 ____D C:\ProgramData\doublers-9
2016-04-16 01:23 - 2016-04-16 01:23 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\tempco-5
2016-04-16 00:55 - 2016-04-16 12:41 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\sinad-4
2016-04-15 15:46 - 2016-04-15 15:51 - 00018131 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:15 - 2016-04-15 15:15 - 00000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-16 00:55 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\tdscdma-8
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:35 - 2016-04-15 14:36 - 00023394 _____ C:\Users\hauptaccount\Desktop\er (V.txt
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-16 13:31 - 00027518 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-12 12:40 - 2016-04-16 01:05 - 00082415 _____ C:\Users\hauptaccount\Desktop\Addition.txt
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-16 13:31 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:31 - 2016-04-12 12:31 - 02375168 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-03-24 16:09 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM(1).pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega
2016-03-21 22:52 - 2016-03-28 00:40 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt
2016-03-21 22:52 - 2016-03-21 22:52 - 00000208 _____ C:\Users\hauptaccount\Desktop\c.txt
2016-03-21 17:49 - 2016-03-21 17:50 - 00000000 ____D C:\Users\hauptaccount\Desktop\CYBERGAUNER
2016-03-21 17:35 - 2016-03-21 17:35 - 01596260 _____ C:\Users\hauptaccount\Downloads\flyer.pdf
2016-03-21 14:27 - 2016-03-21 14:28 - 08186625 _____ C:\Users\hauptaccount\Downloads\wordpress-4.4.2-de_DE.zip
2016-03-19 16:25 - 2016-03-19 16:25 - 00000000 ____D C:\Users\hauptaccount\Desktop\Neuer Ordner


==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-16 12:48 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-16 12:48 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-16 12:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-16 12:29 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-16 02:07 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-16 02:07 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-16 02:07 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-15 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-15 23:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-15 20:48 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-15 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:51 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-15 15:50 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-15 15:49 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 11:30 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-15 10:41 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-15 10:37 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-15 10:37 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-15 10:37 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-15 10:37 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-14 01:45 - 2010-11-17 16:33 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 22:46 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-11 21:14 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 21:26 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-21 15:35 - 2011-01-17 18:08 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Paint.NET

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-11 12:08

==================== Ende von FRST.txt ============================


Ikarius 16.04.2016 12:38

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-16 13:32:37)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.5 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {0549C0DB-913F-4411-B577-6A5D9C5D6CEB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {06AD79CF-3049-4E43-A011-BABF6A39B4DF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {0FE5D209-B132-4972-B77D-AC0A78A3FF06} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {11DDFDAD-C35F-4461-90F9-16E92773139F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {15EE9EF4-3824-44CA-8DE2-6C81AD1785D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {242E14E3-E262-42F4-8B7B-A16CC962477C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {29CA4BA7-9156-431C-88C7-69741974F3CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {406C9318-4C8B-41DE-8D30-9294CF6DC20F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {6B7FC54F-AB46-4C0A-BB70-AC855322E160} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {CDDBBD48-0D3F-480D-8456-4181DB66F45F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FE8EB787-034F-4677-8391-7FCC25426EED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-10-28 19:19 - 2015-09-07 05:33 - 00055688 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-10-28 19:19 - 2015-09-07 05:33 - 00104328 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 01675928 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libglesv2.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 00086168 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe

==================== Wiederherstellungspunkte =========================

24-03-2016 18:56:48 Windows Update
03-04-2016 15:49:10 Geplanter Prüfpunkt
12-04-2016 15:59:21 Geplanter Prüfpunkt
15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Renesas USB 3.0 eXtensible-Hostcontroller – 0.96 (Microsoft)
Description: USB-xHCI-kompatibler Hostcontroller
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Generischer USB-xHCI-Hostcontroller
Service: USBXHCI
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/16/2016 12:24:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: drypack-45.exe, Version: 0.0.0.0, Zeitstempel: 0x55614f0d
Name des fehlerhaften Moduls: drypack-45.exe, Version: 0.0.0.0, Zeitstempel: 0x55614f0d
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000046d3
ID des fehlerhaften Prozesses: 0x1750
Startzeit der fehlerhaften Anwendung: 0xdrypack-45.exe0
Pfad der fehlerhaften Anwendung: drypack-45.exe1
Pfad des fehlerhaften Moduls: drypack-45.exe2
Berichtskennung: drypack-45.exe3
Vollständiger Name des fehlerhaften Pakets: drypack-45.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: drypack-45.exe5

Error: (04/16/2016 01:38:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: drypack-45.exe, Version: 0.0.0.0, Zeitstempel: 0x55614f0d
Name des fehlerhaften Moduls: drypack-45.exe, Version: 0.0.0.0, Zeitstempel: 0x55614f0d
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000046d3
ID des fehlerhaften Prozesses: 0x2808
Startzeit der fehlerhaften Anwendung: 0xdrypack-45.exe0
Pfad der fehlerhaften Anwendung: drypack-45.exe1
Pfad des fehlerhaften Moduls: drypack-45.exe2
Berichtskennung: drypack-45.exe3
Vollständiger Name des fehlerhaften Pakets: drypack-45.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: drypack-45.exe5

Error: (04/16/2016 01:22:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: vacuole-71.exe, Version: 9.1.1.0, Zeitstempel: 0x55a6d806
Name des fehlerhaften Moduls: vacuole-71.exe, Version: 9.1.1.0, Zeitstempel: 0x55a6d806
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000033a3
ID des fehlerhaften Prozesses: 0xf4c
Startzeit der fehlerhaften Anwendung: 0xvacuole-71.exe0
Pfad der fehlerhaften Anwendung: vacuole-71.exe1
Pfad des fehlerhaften Moduls: vacuole-71.exe2
Berichtskennung: vacuole-71.exe3
Vollständiger Name des fehlerhaften Pakets: vacuole-71.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: vacuole-71.exe5

Error: (04/15/2016 03:55:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x177c
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5

Error: (04/15/2016 02:20:14 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/15/2016 02:15:02 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/15/2016 11:30:04 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/14/2016 05:48:07 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (04/14/2016 05:26:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm avscan.exe, Version 15.0.16.276 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1f08

Startzeit: 01d195846f8a0745

Beendigungszeit: 60000

Anwendungspfad: C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe

Berichts-ID: 15d47d51-0255-11e6-9bd6-001f3f0bea1d

Vollständiger Name des fehlerhaften Pakets:

Auf das fehlerhafte Paket bezogene Anwendungs-ID:

Error: (04/14/2016 05:11:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 48222797


Systemfehler:
=============
Error: (04/16/2016 12:20:36 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.

Error: (04/16/2016 02:07:42 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_5e780" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/15/2016 03:50:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/15/2016 03:50:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/15/2016 03:50:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/15/2016 03:49:14 PM) (Source: DCOM) (EventID: 10010) (User: hauptaccount-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (04/15/2016 03:49:14 PM) (Source: DCOM) (EventID: 10010) (User: hauptaccount-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (04/15/2016 03:49:14 PM) (Source: DCOM) (EventID: 10010) (User: hauptaccount-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (04/15/2016 03:49:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_6793b" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/15/2016 03:18:32 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{3185A766-B338-11E4-A71E-12E3F512A338}{7006698D-2974-4091-A424-85DD0B909E23}NT-AUTORITÄTNetzwerkdienstS-1-5-20LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar


CodeIntegrity:
===================================
  Date: 2016-04-16 13:26:47.952
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:39.735
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.919
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.794
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.681
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.565
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.467
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.341
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.231
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-16 13:22:06.096
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen ===========================

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 53%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 1921.65 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 5688.25 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:106.37 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.69 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 17.04.2016 10:55

FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [doublers-63] => C:\ProgramData\doublers-9\doublers-80.exe [704688 2016-04-16] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [tempco-65] => C:\Users\hauptaccount\AppData\Roaming\tempco-5\tempco-23.exe [813056 2016-04-16] ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jugfet-9.lnk [2016-04-16]
ShortcutTarget: jugfet-9.lnk -> C:\Users\hauptaccount\AppData\Roaming\jugfet-7\jugfet-9.exe (IvoSoft)
CHR HomePage: Default -> hxxp://feed.helperbar.com/?publisher=QuickOC&dpid=QuickOC&co=DE&userid=35e67f97-7787-40cf-897d-5c56a5625e15&searchtype=hp&installDate=
CHR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
Task: {0549C0DB-913F-4411-B577-6A5D9C5D6CEB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {06AD79CF-3049-4E43-A011-BABF6A39B4DF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {0FE5D209-B132-4972-B77D-AC0A78A3FF06} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {11DDFDAD-C35F-4461-90F9-16E92773139F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {15EE9EF4-3824-44CA-8DE2-6C81AD1785D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {242E14E3-E262-42F4-8B7B-A16CC962477C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {29CA4BA7-9156-431C-88C7-69741974F3CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {406C9318-4C8B-41DE-8D30-9294CF6DC20F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {6B7FC54F-AB46-4C0A-BB70-AC855322E160} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {CDDBBD48-0D3F-480D-8456-4181DB66F45F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {FE8EB787-034F-4677-8391-7FCC25426EED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
C:\Users\hauptaccount\AppData\Roaming\jugfet-7
C:\ProgramData\gravity-7
C:\ProgramData\doublers-9
C:\Users\hauptaccount\AppData\Roaming\tempco-5
C:\Users\hauptaccount\AppData\Roaming\sinad-4
C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
C:\Users\hauptaccount\AppData\Roaming\tempco-5
C:\ProgramData\doublers-9
C:\Users\hauptaccount\AppData\Roaming\tdscdma-8
C:\Users\hauptaccount\AppData\Roaming\kilobits-8
C:\ProgramData\linear-0
C:\ProgramData\IObit
cmd: del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Ikarius 17.04.2016 16:10

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-17 17:03:08) Run:2
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [doublers-63] => C:\ProgramData\doublers-9\doublers-80.exe [704688 2016-04-16] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [tempco-65] => C:\Users\hauptaccount\AppData\Roaming\tempco-5\tempco-23.exe [813056 2016-04-16] ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jugfet-9.lnk [2016-04-16]
ShortcutTarget: jugfet-9.lnk -> C:\Users\hauptaccount\AppData\Roaming\jugfet-7\jugfet-9.exe (IvoSoft)
CHR HomePage: Default -> hxxp://feed.helperbar.com/?publisher=QuickOC&dpid=QuickOC&co=DE&userid=35e67f97-7787-40cf-897d-5c56a5625e15&searchtype=hp&installDate=
CHR Extension: (Avira Browserschutz) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-13]
Task: {0549C0DB-913F-4411-B577-6A5D9C5D6CEB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {06AD79CF-3049-4E43-A011-BABF6A39B4DF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {0FE5D209-B132-4972-B77D-AC0A78A3FF06} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {11DDFDAD-C35F-4461-90F9-16E92773139F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {15EE9EF4-3824-44CA-8DE2-6C81AD1785D0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {242E14E3-E262-42F4-8B7B-A16CC962477C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {29CA4BA7-9156-431C-88C7-69741974F3CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {406C9318-4C8B-41DE-8D30-9294CF6DC20F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {6B7FC54F-AB46-4C0A-BB70-AC855322E160} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {CDDBBD48-0D3F-480D-8456-4181DB66F45F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {FE8EB787-034F-4677-8391-7FCC25426EED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
C:\Users\hauptaccount\AppData\Roaming\jugfet-7
C:\ProgramData\gravity-7
C:\ProgramData\doublers-9
C:\Users\hauptaccount\AppData\Roaming\tempco-5
C:\Users\hauptaccount\AppData\Roaming\sinad-4
C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
C:\Users\hauptaccount\AppData\Roaming\tempco-5
C:\ProgramData\doublers-9
C:\Users\hauptaccount\AppData\Roaming\tdscdma-8
C:\Users\hauptaccount\AppData\Roaming\kilobits-8
C:\ProgramData\linear-0
C:\ProgramData\IObit
cmd: del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
       
*****************

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\doublers-63 => Wert erfolgreich entfernt
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\tempco-65 => Wert nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jugfet-9.lnk => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\jugfet-7\jugfet-9.exe => nicht gefunden.
Chrome HomePage => erfolgreich entfernt
C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0549C0DB-913F-4411-B577-6A5D9C5D6CEB}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0549C0DB-913F-4411-B577-6A5D9C5D6CEB}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06AD79CF-3049-4E43-A011-BABF6A39B4DF}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06AD79CF-3049-4E43-A011-BABF6A39B4DF}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0FE5D209-B132-4972-B77D-AC0A78A3FF06}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FE5D209-B132-4972-B77D-AC0A78A3FF06}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11DDFDAD-C35F-4461-90F9-16E92773139F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11DDFDAD-C35F-4461-90F9-16E92773139F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15EE9EF4-3824-44CA-8DE2-6C81AD1785D0}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15EE9EF4-3824-44CA-8DE2-6C81AD1785D0}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{242E14E3-E262-42F4-8B7B-A16CC962477C}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{242E14E3-E262-42F4-8B7B-A16CC962477C}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{29CA4BA7-9156-431C-88C7-69741974F3CE}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{29CA4BA7-9156-431C-88C7-69741974F3CE}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{406C9318-4C8B-41DE-8D30-9294CF6DC20F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{406C9318-4C8B-41DE-8D30-9294CF6DC20F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6B7FC54F-AB46-4C0A-BB70-AC855322E160}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6B7FC54F-AB46-4C0A-BB70-AC855322E160}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CDDBBD48-0D3F-480D-8456-4181DB66F45F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CDDBBD48-0D3F-480D-8456-4181DB66F45F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FE8EB787-034F-4677-8391-7FCC25426EED}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FE8EB787-034F-4677-8391-7FCC25426EED}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => Schlüssel erfolgreich entfernt
"C:\Users\hauptaccount\AppData\Roaming\jugfet-7" => nicht gefunden.
"C:\ProgramData\gravity-7" => nicht gefunden.
C:\ProgramData\doublers-9 => erfolgreich verschoben
"C:\Users\hauptaccount\AppData\Roaming\tempco-5" => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\sinad-4 => erfolgreich verschoben
C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98} => erfolgreich verschoben
C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705} => erfolgreich verschoben
"C:\Users\hauptaccount\AppData\Roaming\tempco-5" => nicht gefunden.
"C:\ProgramData\doublers-9" => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\tdscdma-8 => erfolgreich verschoben
"C:\Users\hauptaccount\AppData\Roaming\kilobits-8" => nicht gefunden.
"C:\ProgramData\linear-0" => nicht gefunden.
"C:\ProgramData\IObit" => nicht gefunden.

=========  del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q =========


========= Ende von CMD: =========


=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

17.04.2016  17:03    <DIR>          ..
17.04.2016  17:03    <DIR>          .
17.04.2016  16:56    <DIR>          Spotify
16.04.2016  18:21    <DIR>          quark-2
16.04.2016  15:45    <DIR>          amlcd-1
16.04.2016  12:48    <DIR>          Dropbox
15.04.2016  15:51    <DIR>          Wise Care 365
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  14:20    <DIR>          IObit
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
24.03.2016  16:09    <DIR>          vlc
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
              0 Datei(en),              0 Bytes
              60 Verzeichnis(se), 117.001.539.584 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

17.04.2016  17:03    <DIR>          ..
17.04.2016  17:03    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 117.001.539.584 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

17.04.2016  17:03    <DIR>          ..
17.04.2016  17:03    <DIR>          .
16.04.2016  15:54    <DIR>          Package Cache
16.04.2016  15:42    <DIR>          analog-85
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
30.03.2016  06:01    <DIR>          Origin
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11              133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
              2 Datei(en),            190 Bytes
              62 Verzeichnis(se), 117.001.535.488 Bytes frei

========= Ende von CMD: =========

EmptyTemp: => 499.8 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 17:03:26 ====


cosinus 17.04.2016 20:38

Und wieder neue Logs bitte.
Sollte sich heraustellen, dass da wieder neuer schiet drin ist, müssen wir die nächsten Fixen offline durchführen.

Ikarius 19.04.2016 18:00

Sorry hatte etwas gedauert. Seit dem letzten Fix öffnet sich beim hochfahren immer ein Auswahlfenster das irgendwelche Einstellungen ändern will. Mache mal ein Foto davon. Muss das immer abbrechen damit der PC startet.

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (19-04-2016 18:50:42)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
() C:\Windows\SysWOW64\WinService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Mozilla Messaging) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Rocksteady Studios Ltd.) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chloride-51] => C:\ProgramData\chloride-13\chloride-96.exe [695808 2016-04-19] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [hoist-3] => C:\Users\hauptaccount\AppData\Roaming\hoist-77\hoist-47.exe [882688 2016-04-19] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\amlcd-8.lnk [2016-04-19]
ShortcutTarget: amlcd-8.lnk -> C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe (IvoSoft)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SelectedSearchEngine,S:
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome:
=======
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.)
S2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
R3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-19 18:26 - 2016-04-19 18:26 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\amlcd-8
2016-04-19 18:24 - 2016-04-19 18:24 - 00000000 ____D C:\ProgramData\physics-6
2016-04-19 18:22 - 2016-04-19 18:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\hoist-77
2016-04-19 18:17 - 2016-04-19 18:17 - 00000000 ____D C:\ProgramData\chloride-13
2016-04-19 18:14 - 2016-04-19 18:14 - 00911540 _____ C:\WINDOWS\Minidump\041916-35562-01.dmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 18:13 - 2016-04-19 18:13 - 511780318 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 00:05 - 2016-04-19 00:05 - 00000000 _____ C:\Users\hauptaccount\Desktop\Danke.txt
2016-04-18 18:15 - 2016-04-18 18:16 - 00000000 ____D C:\Users\hauptaccount\Documents\Witcher 2
2016-04-18 18:15 - 2016-04-18 18:15 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\The Witcher 2
2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-15 15:46 - 2016-04-17 17:03 - 00017295 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:35 - 2016-04-15 14:36 - 00023394 _____ C:\Users\hauptaccount\Desktop\er (V.txt
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-19 18:51 - 00027909 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-12 12:40 - 2016-04-17 22:00 - 00083585 _____ C:\Users\hauptaccount\Desktop\Addition.txt
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-19 18:50 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:31 - 2016-04-12 12:31 - 02375168 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-03-24 16:09 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM (1).pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega
2016-03-21 22:52 - 2016-03-28 00:40 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt
2016-03-21 22:52 - 2016-03-21 22:52 - 00000208 _____ C:\Users\hauptaccount\Desktop\c.txt
2016-03-21 17:49 - 2016-03-21 17:50 - 00000000 ____D C:\Users\hauptaccount\Desktop\CYBERGAUNER
2016-03-21 17:35 - 2016-03-21 17:35 - 01596260 _____ C:\Users\hauptaccount\Downloads\flyer.pdf
2016-03-21 14:27 - 2016-03-21 14:28 - 08186625 _____ C:\Users\hauptaccount\Downloads\wordpress-4.4.2-de_DE.zip

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-19 18:48 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-19 18:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-19 18:43 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-19 18:34 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-19 18:19 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-19 18:15 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-19 18:15 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-19 18:14 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-19 05:18 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-19 05:18 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-19 05:18 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-19 02:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-19 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-18 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-18 18:16 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-18 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-17 17:03 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-17 17:03 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-17 16:56 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-16 15:54 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 10:37 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-15 10:37 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-15 10:37 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-15 10:37 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 01:45 - 2010-11-17 16:33 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-21 15:35 - 2011-01-17 18:08 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Paint.NET


==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-11 12:08

==================== Ende von FRST.txt ============================


Ikarius 19.04.2016 18:08

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
durchgeführt von hauptaccount (2016-04-19 18:52:33)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-04-13 14:13 - 2016-04-02 05:00 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2012-05-15 16:40 - 2015-04-27 16:07 - 00291944 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-10-28 19:19 - 2016-02-24 06:47 - 00110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2015-10-28 19:19 - 2016-02-24 06:48 - 00062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00848536 _____ () C:\Program Files (x86)\Mozilla Thunderbird\js3250.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00161944 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00021656 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 01675928 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libglesv2.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 00086168 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{FCA69E9E-5F9C-4017-BA34-56A0990113DA}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [{21E0F41D-D786-4B74-8F22-DD034830B1A5}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{7773E817-0D95-4EA8-BCB4-0A3B29108ADF}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{DC163F1E-AF2F-4676-AC19-C9E3051B493F}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{EAC7F226-CCDC-4A17-AA64-697F87B2838D}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{162168E4-1F32-4512-BDC3-BCEF7BE949AB}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe

==================== Wiederherstellungspunkte =========================

15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal
16-04-2016 15:54:01 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
18-04-2016 18:13:19 DirectX wurde installiert

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Renesas USB 3.0 eXtensible-Hostcontroller – 0.96 (Microsoft)
Description: USB-xHCI-kompatibler Hostcontroller
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Generischer USB-xHCI-Hostcontroller
Service: USBXHCI
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/18/2016 06:13:38 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.

System Error:
Zugriff verweigert
.

Error: (04/17/2016 05:03:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: hauptaccount-PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.


Systemfehler:
=============
Error: (04/19/2016 06:20:05 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: {B91D5831-B1BD-4608-8198-D72E155020F7}

Error: (04/19/2016 06:17:12 PM) (Source: DCOM) (EventID: 10016) (User: hauptaccount-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}hauptaccount-PChauptaccountS-1-5-21-2403081755-137120475-2182785957-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/19/2016 06:17:09 PM) (Source: DCOM) (EventID: 10016) (User: hauptaccount-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}hauptaccount-PChauptaccountS-1-5-21-2403081755-137120475-2182785957-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/19/2016 06:17:05 PM) (Source: DCOM) (EventID: 10016) (User: hauptaccount-PC)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}hauptaccount-PChauptaccountS-1-5-21-2403081755-137120475-2182785957-1001LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (04/19/2016 06:15:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Autodesk Content Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (04/19/2016 06:15:09 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Autodesk Content Service erreicht.

Error: (04/19/2016 06:14:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/19/2016 06:14:39 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/19/2016 06:14:33 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000009f (0x0000000000000003, 0xffffe0017e0a7050, 0xfffff801edda3ad0, 0xffffe0017d456bd0)C:\WINDOWS\MEMORY.DMPb814ed29-9d8c-4dee-93ab-4df859885abd

Error: (04/19/2016 06:14:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2


CodeIntegrity:
===================================
  Date: 2016-04-18 16:26:37.711
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:37.692
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:37.672
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:33.599
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:33.524
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:33.428
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:33.329
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:13.756
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:13.648
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-18 16:26:10.547
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen ===========================

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 55%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 1822.34 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 5326.81 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:108.12 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.66 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 19.04.2016 19:25

Es bringt nix, wir müssen das offline machen.

Lad dir FRST bitte neu runter. Danach ziehst du das Netzwerkkabel und trennst etwaige LAN-Verbindungen.

Die neuen FRST Logs und anschließenden Fixes müssen wir komplett OFFLINE machen. Es darf keine Verbindung zum Internet da sein.

Hast du einen zweiten Rechner und einen USB Stick parat? Wenn nicht muss ich mir was anderes überlegen.

Ikarius 19.04.2016 20:16

Habe alles parat. Können das auch gerne morgen machen wenn es heute schon zu spät ist. Richte mich ganz nach dir

cosinus 19.04.2016 22:28

Gut. Dann wieder einen FRST-Fix. Kopiere den Inhalt der CODE-Box aber in eine Textdatei auf einen Stick, diese dann auf den Desktop des Rechners kopieren, der gefixt werden muss. Und wie gesagt, lass den Rechner so lange offline, bis ich sage, dass du wieder einen Onlineversuch wagen kannst. Nach dem Fix auch bitte wieder neue FRST-Logs machen und posten. Wieder per Stick die Logs transportieren...


FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chloride-51] => C:\ProgramData\chloride-13\chloride-96.exe [695808 2016-04-19] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [hoist-3] => C:\Users\hauptaccount\AppData\Roaming\hoist-77\hoist-47.exe [882688 2016-04-19] ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\amlcd-8.lnk [2016-04-19]
ShortcutTarget: amlcd-8.lnk -> C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe (IvoSoft)
C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
C:\ProgramData\chloride-13
C:\ProgramData\SaveAs
C:\Users\hauptaccount\AppData\Roaming\hoist-77
C:\ProgramData\physics-6
cmd: del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Ikarius 20.04.2016 13:51

So alles erledigt wie du gesagt hast. PC ist noch offline.
Hier nun Fixlog,FRST und Addition:

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-20 14:29:55) Run:4
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [chloride-51] => C:\ProgramData\chloride-13\chloride-96.exe [695808 2016-04-19] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [hoist-3] => C:\Users\hauptaccount\AppData\Roaming\hoist-77\hoist-47.exe [882688 2016-04-19] ()
Startup: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\amlcd-8.lnk [2016-04-19]
ShortcutTarget: amlcd-8.lnk -> C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe (IvoSoft)
C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe
CHR HKLM-x32\...\Chrome\Extension: [mkpibfnlcehjomacedckkofbpakaefbh] - C:\ProgramData\SaveAs\mkpibfnlcehjomacedckkofbpakaefbh.crx <nicht gefunden>
C:\ProgramData\chloride-13
C:\ProgramData\SaveAs
C:\Users\hauptaccount\AppData\Roaming\hoist-77
C:\ProgramData\physics-6
cmd: del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
*****************


=========  dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

19.04.2016  22:29    <DIR>          ..
19.04.2016  22:29    <DIR>          .
19.04.2016  22:29            1.002 dslam-6.lnk
              1 Datei(en),          1.002 Bytes
              2 Verzeichnis(se), 116.685.664.256 Bytes frei

========= Ende von CMD: =========

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\chloride-51 => Wert nicht gefunden.
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\hoist-3 => Wert nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\amlcd-8.lnk => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe => nicht gefunden.
"C:\Users\hauptaccount\AppData\Roaming\amlcd-8\amlcd-38.exe" => nicht gefunden.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mkpibfnlcehjomacedckkofbpakaefbh => Schlüssel nicht gefunden.
"C:\ProgramData\chloride-13" => nicht gefunden.
"C:\ProgramData\SaveAs" => nicht gefunden.
"C:\Users\hauptaccount\AppData\Roaming\hoist-77" => nicht gefunden.
"C:\ProgramData\physics-6" => nicht gefunden.

=========  del "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.*" /q =========


========= Ende von CMD: =========


=========  dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 116.685.668.352 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

20.04.2016  14:27    <DIR>          ..
20.04.2016  14:27    <DIR>          .
20.04.2016  14:27    <DIR>          Wise Care 365
20.04.2016  14:11    <DIR>          ampacity-56
19.04.2016  22:29    <DIR>          dslam-3
17.04.2016  16:56    <DIR>          Spotify
16.04.2016  12:48    <DIR>          Dropbox
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  14:20    <DIR>          IObit
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
24.03.2016  16:09    <DIR>          vlc
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
              0 Datei(en),              0 Bytes
              60 Verzeichnis(se), 116.685.664.256 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 116.685.664.256 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

20.04.2016  14:27    <DIR>          ..
20.04.2016  14:27    <DIR>          .
20.04.2016  14:13    <DIR>          vacuole-6
20.04.2016  14:09    <DIR>          balanced-2
16.04.2016  15:54    <DIR>          Package Cache
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
30.03.2016  06:01    <DIR>          Origin
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11              133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
              2 Datei(en),            190 Bytes
              63 Verzeichnis(se), 116.685.660.160 Bytes frei

========= Ende von CMD: =========

EmptyTemp: => 23.2 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 14:30:14 ====

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (20-04-2016 14:38:24)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Windows\SysWOW64\WinService.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Spotify Ltd) C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [balanced-0] => C:\ProgramData\balanced-2\balanced-1.exe [784248 2016-04-20] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [ampacity-95] => C:\Users\hauptaccount\AppData\Roaming\ampacity-56\ampacity-57.exe [884736 2016-04-20] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SelectedSearchEngine,S:
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
S3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-20 14:38 - 2016-04-20 14:38 - 00026188 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-20 14:29 - 2016-04-20 14:37 - 00011183 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-20 14:13 - 2016-04-20 14:13 - 02375680 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-20 14:13 - 2016-04-20 14:13 - 00000000 ____D C:\ProgramData\vacuole-6
2016-04-20 14:11 - 2016-04-20 14:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ampacity-56
2016-04-20 14:09 - 2016-04-20 14:09 - 00000000 ____D C:\ProgramData\balanced-2
2016-04-19 22:29 - 2016-04-19 22:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\dslam-3
2016-04-19 20:49 - 2016-04-19 20:49 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00911540 _____ C:\WINDOWS\Minidump\041916-35562-01.dmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 18:13 - 2016-04-19 18:13 - 511780318 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 00:05 - 2016-04-19 00:05 - 00000000 _____ C:\Users\hauptaccount\Desktop\Danke.txt
2016-04-18 18:15 - 2016-04-18 18:16 - 00000000 ____D C:\Users\hauptaccount\Documents\Witcher 2
2016-04-18 18:15 - 2016-04-18 18:15 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\The Witcher 2
2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-20 14:38 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\verleihshop-ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-03-24 16:09 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM (1).pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega
2016-03-21 22:52 - 2016-03-28 00:40 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt
2016-03-21 22:52 - 2016-03-21 22:52 - 00000208 _____ C:\Users\hauptaccount\Desktop\c.txt
2016-03-21 17:49 - 2016-03-21 17:50 - 00000000 ____D C:\Users\hauptaccount\Desktop\CYBERGAUNER
2016-03-21 17:35 - 2016-03-21 17:35 - 01596260 _____ C:\Users\hauptaccount\Downloads\flyer.pdf
2016-03-21 14:27 - 2016-03-21 14:28 - 08186625 _____ C:\Users\hauptaccount\Downloads\wordpress-4.4.2-de_DE.zip

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-20 14:34 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-20 14:33 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-20 14:30 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-20 14:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-20 14:09 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-20 04:22 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-20 04:22 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 04:22 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 04:22 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 03:48 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-20 03:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-20 03:43 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-20 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-19 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-19 20:49 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-19 18:19 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-18 18:16 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-18 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-17 17:03 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-17 16:56 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-16 15:54 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 10:37 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-15 10:37 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-15 10:37 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 01:45 - 2010-11-17 16:33 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-21 15:35 - 2011-01-17 18:08 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Paint.NET


==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-11 12:08

==================== Ende von FRST.txt ============================


Ikarius 20.04.2016 13:52

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-20 14:39:44)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2012-05-15 16:40 - 2015-04-27 16:07 - 00291944 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-10-28 19:19 - 2016-02-24 06:48 - 00062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-10-28 19:19 - 2016-02-24 06:47 - 00110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: Datenträger ist nicht mit dem Internet verbunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{FCA69E9E-5F9C-4017-BA34-56A0990113DA}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [{21E0F41D-D786-4B74-8F22-DD034830B1A5}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{7773E817-0D95-4EA8-BCB4-0A3B29108ADF}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{DC163F1E-AF2F-4676-AC19-C9E3051B493F}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{EAC7F226-CCDC-4A17-AA64-697F87B2838D}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{162168E4-1F32-4512-BDC3-BCEF7BE949AB}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe

==================== Wiederherstellungspunkte =========================

15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal
16-04-2016 15:54:01 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
18-04-2016 18:13:19 DirectX wurde installiert

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/20/2016 02:28:07 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/20/2016 04:22:03 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: hauptaccount-PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:25:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x454
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5

Error: (04/19/2016 06:24:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: microsoftedgecp.exe, Version: 11.0.10586.20, Zeitstempel: 0x56540c35
Name des fehlerhaften Moduls: iertutil.dll, Version: 11.0.10586.122, Zeitstempel: 0x56cbfa23
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000000000007040
ID des fehlerhaften Prozesses: 0x2344
Startzeit der fehlerhaften Anwendung: 0xmicrosoftedgecp.exe0
Pfad der fehlerhaften Anwendung: microsoftedgecp.exe1
Pfad des fehlerhaften Moduls: microsoftedgecp.exe2
Berichtskennung: microsoftedgecp.exe3
Vollständiger Name des fehlerhaften Pakets: microsoftedgecp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: microsoftedgecp.exe5


Systemfehler:
=============
Error: (04/20/2016 02:33:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/20/2016 02:33:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/20/2016 02:33:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/20/2016 02:30:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_518d3" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/20/2016 02:25:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/20/2016 02:25:34 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/20/2016 02:25:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/20/2016 02:24:08 PM) (Source: DCOM) (EventID: 10010) (User: hauptaccount-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (04/20/2016 02:24:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_38696a6" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/20/2016 02:06:43 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.


CodeIntegrity:
===================================
  Date: 2016-04-20 14:38:51.950
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:38:51.930
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.350
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.335
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.277
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:15:12.978
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:15:12.962
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:15:12.926
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 01:12:28.021
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 01:12:28.005
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen ===========================

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 36%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 2613.93 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 6636.01 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:108.68 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.66 GB) NTFS
Drive e: (Elements) (Fixed) (Total:465.73 GB) (Free:445.48 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 465.7 GB) (Disk ID: 10770C69)
Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 20.04.2016 19:40

Zitat:

2016-04-20 14:13 - 2016-04-20 14:13 - 02375680 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-20 14:13 - 2016-04-20 14:13 - 00000000 ____D C:\ProgramData\vacuole-6
2016-04-20 14:11 - 2016-04-20 14:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ampacity-56
2016-04-20 14:09 - 2016-04-20 14:09 - 00000000 ____D C:\ProgramData\balanced-2
2016-04-19 22:29 - 2016-04-19 22:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\dslam-3
Und der Rechner war wirklich komplett offline? Ziemlich genau mit FRST kam da nämlich wieder neuer Scheixx rein... :(

Ikarius 21.04.2016 00:11

Ja ist immernoch komplett offline. Hab FRST neu geladen und den WLAN-Stick rausgezogen.

Also so wie ich das sehe wurde der neue Kram noch draufgeladen bevor ich mich vom Internet gelöst habe. Würde dann mal sagen das ich noch irgendwas auf dem PC habe das mir ständig neuen Mist runterläd. Vielleicht mal weiter danach suchen und dann nen neuen Fixlog wagen?

Ps: Dachte eigentlich wir schaffen das heute. Hab morgen den zweiten Rechner nicht und muss leider mit dem Internet verbinden.

cosinus 21.04.2016 09:57

Bitte immer noch komplett offline bleiben, Logs und Fixscripte wieder per Stick transportieren

FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [balanced-0] => C:\ProgramData\balanced-2\balanced-1.exe [784248 2016-04-20] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [ampacity-95] => C:\Users\hauptaccount\AppData\Roaming\ampacity-56\ampacity-57.exe [884736 2016-04-20] ()
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
C:\ProgramData\vacuole-6
C:\Users\hauptaccount\AppData\Roaming\ampacity-56
C:\ProgramData\balanced-2
C:\Users\hauptaccount\AppData\Roaming\dslam-3
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Ikarius 21.04.2016 22:35

Musste den Fix doppelt machen weil ich irgendwo nen Buchstaben reingehauen hab und er den Pfad dann nicht finden konnte. Logs sehen besser aus

Hier die Logs
Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-21 22:45:45) Run:6
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [balanced-0] => C:\ProgramData\balanced-2\balanced-1.exe [784248 2016-04-20] ()
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\RunOnce: [ampacity-95] => C:\Users\hauptaccount\AppData\Roaming\ampacity-56\ampacity-57.exe [884736 2016-04-20] ()
FF Extension: SaveAs - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com [2016-01-13] [ist nicht signiert]
FF Extension: Avira Browser Safety - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com [2016-01-30]
C:\ProgramData\vacuole-6
C:\Users\hauptaccount\AppData\Roaming\ampacity-56
C:\ProgramData\balanced-2
C:\Users\hauptaccount\AppData\Roaming\dslam-3
cmd: dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\"
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
       
*****************


=========  dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 116.378.759.168 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

21.04.2016  22:43    <DIR>          ..
21.04.2016  22:43    <DIR>          .
21.04.2016  22:43    <DIR>          Wise Care 365
21.04.2016  09:18    <DIR>          algebra-18
20.04.2016  19:24    <DIR>          vlc
19.04.2016  22:29    <DIR>          dslam-3
17.04.2016  16:56    <DIR>          Spotify
16.04.2016  12:48    <DIR>          Dropbox
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  14:20    <DIR>          IObit
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
              0 Datei(en),              0 Bytes
              60 Verzeichnis(se), 116.378.755.072 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 116.378.755.072 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

21.04.2016  22:43    <DIR>          ..
21.04.2016  22:43    <DIR>          .
21.04.2016  09:16    <DIR>          chans-19
16.04.2016  15:54    <DIR>          Package Cache
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
30.03.2016  06:01    <DIR>          Origin
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11              133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
              2 Datei(en),            190 Bytes
              62 Verzeichnis(se), 116.378.750.976 Bytes frei

========= Ende von CMD: =========

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\Run\\balanced-0 => Wert nicht gefunden.
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ampacity-95 => Wert nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\50a80b9b3f445@50a80b9b3f47e.com => erfolgreich verschoben
C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\Extensions\abs@avira.com => erfolgreich verschoben
"C:\ProgramData\vacuole-6" => nicht gefunden.
"C:\Users\hauptaccount\AppData\Roaming\ampacity-56" => nicht gefunden.
"C:\ProgramData\balanced-2" => nicht gefunden.
C:\Users\hauptaccount\AppData\Roaming\dslam-3 => erfolgreich verschoben

=========  dir /oge-d "C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 116.378.750.976 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

21.04.2016  22:45    <DIR>          ..
21.04.2016  22:45    <DIR>          .
21.04.2016  22:43    <DIR>          Wise Care 365
21.04.2016  09:18    <DIR>          algebra-18
20.04.2016  19:24    <DIR>          vlc
17.04.2016  16:56    <DIR>          Spotify
16.04.2016  12:48    <DIR>          Dropbox
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  14:20    <DIR>          IObit
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
              0 Datei(en),              0 Bytes
              59 Verzeichnis(se), 116.378.746.880 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 116.378.746.880 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

21.04.2016  22:43    <DIR>          ..
21.04.2016  22:43    <DIR>          .
21.04.2016  09:16    <DIR>          chans-19
16.04.2016  15:54    <DIR>          Package Cache
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
30.03.2016  06:01    <DIR>          Origin
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11              133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
              2 Datei(en),            190 Bytes
              62 Verzeichnis(se), 116.378.742.784 Bytes frei

========= Ende von CMD: =========

EmptyTemp: => 23.2 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 22:46:05 ====

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (21-04-2016 23:14:05)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
() C:\Windows\SysWOW64\WinService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
() C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SelectedSearchEngine,S:
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
S3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-21 23:11 - 2016-04-21 23:11 - 00018014 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-21 22:51 - 2016-04-21 22:52 - 00089945 _____ C:\Users\hauptaccount\Desktop\Addition.txt
2016-04-21 22:49 - 2016-04-21 23:14 - 00025377 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-20 14:13 - 2016-04-20 14:13 - 02375680 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-19 20:49 - 2016-04-19 20:49 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00911540 _____ C:\WINDOWS\Minidump\041916-35562-01.dmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 18:13 - 2016-04-19 18:13 - 511780318 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 00:05 - 2016-04-19 00:05 - 00000000 _____ C:\Users\hauptaccount\Desktop\Danke.txt
2016-04-18 18:15 - 2016-04-18 18:16 - 00000000 ____D C:\Users\hauptaccount\Documents\Witcher 2
2016-04-18 18:15 - 2016-04-18 18:15 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\The Witcher 2
2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-21 23:14 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-04-20 19:24 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM.pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf
2016-03-22 17:10 - 2016-03-22 17:10 - 00460191 _____ C:\Users\hauptaccount\Downloads\w4-post-list.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00415480 _____ C:\Users\hauptaccount\Downloads\omega.1.2.7.zip
2016-03-22 16:46 - 2016-03-22 16:46 - 00393973 _____ C:\Users\hauptaccount\Downloads\lifestyle.0.1.4.zip
2016-03-22 16:46 - 2015-12-11 07:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\lifestyle
2016-03-22 16:46 - 2015-10-10 05:32 - 00000000 ____D C:\Users\hauptaccount\Desktop\omega

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-21 23:13 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-21 23:13 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-21 23:12 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-21 23:09 - 2015-09-06 20:41 - 00000000 ____D C:\Users\hauptaccount\Desktop\Media
2016-04-21 22:54 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-21 22:54 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-21 22:54 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-21 22:54 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-21 22:49 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-21 22:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-21 22:44 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-21 22:38 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-21 20:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-21 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-21 09:16 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-21 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-20 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-20 14:09 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-20 04:22 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 04:22 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 04:22 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-18 18:16 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-17 17:03 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-17 16:56 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-16 15:54 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 01:45 - 2010-11-17 16:33 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-11 17:41 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-30 06:01 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-28 00:40 - 2016-03-21 22:52 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-21 09:23

==================== Ende von FRST.txt ============================


Ikarius 21.04.2016 22:36

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-21 23:16:14)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-17 20:13 - 2015-12-07 06:59 - 03081568 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll
2015-12-17 20:13 - 2015-12-07 06:57 - 02394976 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2010-11-19 19:58 - 2007-04-13 11:51 - 01261568 _____ () C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-10-28 19:19 - 2016-02-24 06:48 - 00062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-10-28 19:19 - 2016-02-24 06:47 - 00110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: Datenträger ist nicht mit dem Internet verbunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{FCA69E9E-5F9C-4017-BA34-56A0990113DA}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [{21E0F41D-D786-4B74-8F22-DD034830B1A5}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{7773E817-0D95-4EA8-BCB4-0A3B29108ADF}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{DC163F1E-AF2F-4676-AC19-C9E3051B493F}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{EAC7F226-CCDC-4A17-AA64-697F87B2838D}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{162168E4-1F32-4512-BDC3-BCEF7BE949AB}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe

==================== Wiederherstellungspunkte =========================

15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal
16-04-2016 15:54:01 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
18-04-2016 18:13:19 DirectX wurde installiert

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/21/2016 11:14:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x17ac
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5

Error: (04/21/2016 10:34:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: hauptaccount-PC)
Description: Bei der Aktivierung der App „windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (04/21/2016 08:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 05:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 02:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 11:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 08:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 05:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 02:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/20/2016 11:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s


Systemfehler:
=============
Error: (04/21/2016 11:13:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 11:13:09 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/21/2016 11:12:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 11:12:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_4afe5" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/21/2016 10:47:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 10:47:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/21/2016 10:47:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 10:46:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_3ecdd" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/21/2016 10:42:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 10:42:33 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058


CodeIntegrity:
===================================
  Date: 2016-04-21 09:36:27.318
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-21 09:36:27.302
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-21 09:36:27.269
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.084
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.071
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.037
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:38:51.950
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:38:51.930
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.350
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.335
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen ===========================

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 35%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 2625.8 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 6779.89 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:108.38 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.66 GB) NTFS
Drive e: (Elements) (Fixed) (Total:465.73 GB) (Free:445.48 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 465.7 GB) (Disk ID: 10770C69)
Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 22.04.2016 11:35

Zwei Verzeichnisse seh ich da immer noch :balla:
Bitte noch offline bleiben!

FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\hauptaccount\AppData\Roaming\algebra-18
C:\ProgramData\chans-19
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Ikarius 22.04.2016 12:44

Habs leider doppelt gemacht. Hoffentlich jetzt erledigt.
Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-22 13:28:52) Run:8
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
C:\Users\hauptaccount\AppData\Roaming\algebra-18
C:\ProgramData\chans-19
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%

*****************

"C:\Users\hauptaccount\AppData\Roaming\algebra-18" => nicht gefunden.
"C:\ProgramData\chans-19" => nicht gefunden.

=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

22.04.2016  09:39    <DIR>          Wise Care 365
21.04.2016  23:11    <DIR>          ..
21.04.2016  23:11    <DIR>          .
20.04.2016  19:24    <DIR>          vlc
17.04.2016  16:56    <DIR>          Spotify
16.04.2016  12:48    <DIR>          Dropbox
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  14:20    <DIR>          IObit
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
              0 Datei(en),              0 Bytes
              58 Verzeichnis(se), 115.995.553.792 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 115.995.549.696 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

22.04.2016  00:12    <DIR>          Origin
21.04.2016  23:11    <DIR>          ..
21.04.2016  23:11    <DIR>          .
16.04.2016  15:54    <DIR>          Package Cache
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11              133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
              2 Datei(en),            190 Bytes
              61 Verzeichnis(se), 115.995.549.696 Bytes frei

========= Ende von CMD: =========


==== Ende von Fixlog 13:28:52 ====

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (22-04-2016 13:32:05)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
() C:\Windows\SysWOW64\WinService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Mozilla Messaging) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SelectedSearchEngine,S:
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
S3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-22 13:28 - 2016-04-22 13:31 - 00007715 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-21 22:51 - 2016-04-21 23:17 - 00089359 _____ C:\Users\hauptaccount\Desktop\Addition.txt
2016-04-21 22:49 - 2016-04-22 13:32 - 00025667 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-20 14:13 - 2016-04-20 14:13 - 02375680 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-19 20:49 - 2016-04-19 20:49 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00911540 _____ C:\WINDOWS\Minidump\041916-35562-01.dmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 18:13 - 2016-04-19 18:13 - 511780318 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 00:05 - 2016-04-19 00:05 - 00000000 _____ C:\Users\hauptaccount\Desktop\Danke.txt
2016-04-18 18:15 - 2016-04-18 18:16 - 00000000 ____D C:\Users\hauptaccount\Documents\Witcher 2
2016-04-18 18:15 - 2016-04-18 18:15 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\The Witcher 2
2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-22 13:32 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-04-20 19:24 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM.pdf
2016-03-23 19:43 - 2016-03-23 19:43 - 00018702 _____ C:\Users\hauptaccount\Downloads\Ausschreibung.pdf

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-22 12:49 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-22 12:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-22 12:43 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-22 11:55 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-22 11:54 - 2016-03-12 14:07 - 00000000 ____D C:\Users\hauptaccount\Desktop\Telekom
2016-04-22 11:54 - 2016-03-07 20:06 - 00000000 ____D C:\Users\hauptaccount\Desktop\Fachinformatiker
2016-04-22 11:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-22 09:39 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-22 09:34 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-22 00:19 - 2015-12-13 14:39 - 00001447 _____ C:\Users\hauptaccount\Desktop\Dragon Age Origins.lnk
2016-04-22 00:12 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-04-21 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-21 23:12 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-21 23:09 - 2015-09-06 20:41 - 00000000 ____D C:\Users\hauptaccount\Desktop\Media
2016-04-21 22:54 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-21 22:54 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-21 22:54 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-21 22:54 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-21 22:41 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-21 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-21 09:16 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-21 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-20 14:09 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-20 04:22 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 04:22 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-20 04:22 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-18 18:16 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-17 17:03 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-17 16:56 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-16 15:54 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 01:45 - 2010-11-17 16:33 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-12 11:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-12 11:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-28 00:40 - 2016-03-21 22:52 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-21 09:23

==================== Ende von FRST.txt ============================


Ikarius 22.04.2016 12:45

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-22 13:33:08)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2014-12-08 12:10 - 2014-12-08 12:10 - 00102176 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-04-13 14:13 - 2016-04-02 05:00 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-03-03 23:46 - 2016-03-03 23:46 - 00016384 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2016-03-03 23:46 - 2016-03-03 23:46 - 16062976 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2016-03-03 23:46 - 2016-03-03 23:46 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-10-28 19:19 - 2016-02-24 06:48 - 00062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-10-28 19:19 - 2016-02-24 06:47 - 00110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00848536 _____ () C:\Program Files (x86)\Mozilla Thunderbird\js3250.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00161944 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00021656 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2016-03-05 16:47 - 2016-02-19 11:42 - 00074272 _____ () C:\Program Files (x86)\PDF24\zlib.dll
2016-03-05 16:47 - 2016-02-19 11:42 - 00052256 _____ () C:\Program Files (x86)\PDF24\OperationUI.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: Datenträger ist nicht mit dem Internet verbunden.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{FCA69E9E-5F9C-4017-BA34-56A0990113DA}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [{21E0F41D-D786-4B74-8F22-DD034830B1A5}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{7773E817-0D95-4EA8-BCB4-0A3B29108ADF}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{DC163F1E-AF2F-4676-AC19-C9E3051B493F}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{EAC7F226-CCDC-4A17-AA64-697F87B2838D}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{162168E4-1F32-4512-BDC3-BCEF7BE949AB}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe

==================== Wiederherstellungspunkte =========================

15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal
16-04-2016 15:54:01 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
18-04-2016 18:13:19 DirectX wurde installiert

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Renesas USB 3.0 eXtensible-Hostcontroller – 0.96 (Microsoft)
Description: USB-xHCI-kompatibler Hostcontroller
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Generischer USB-xHCI-Hostcontroller
Service: USBXHCI
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/22/2016 11:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/22/2016 10:57:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x13d4
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5

Error: (04/21/2016 11:28:07 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 11:14:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x17ac
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5

Error: (04/21/2016 10:34:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: hauptaccount-PC)
Description: Bei der Aktivierung der App „windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (04/21/2016 08:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 05:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 02:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 11:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 08:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s


Systemfehler:
=============
Error: (04/22/2016 09:34:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/22/2016 09:34:57 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/22/2016 09:34:33 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/22/2016 09:34:34 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎22.‎04.‎2016 um 01:52:59 unerwartet heruntergefahren.

Error: (04/21/2016 11:13:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 11:13:09 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/21/2016 11:12:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 11:12:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_4afe5" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/21/2016 10:47:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 10:47:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058


CodeIntegrity:
===================================
  Date: 2016-04-21 09:36:27.318
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-21 09:36:27.302
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-21 09:36:27.269
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.084
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.071
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.037
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:38:51.950
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:38:51.930
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.350
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.335
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen ===========================

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 49%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 2050.42 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 5919.09 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:108.03 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.66 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 22.04.2016 13:03

Das sieht besser aus. Gib dem Rechner mal wieder Netzwerk/Internet. Dann schauen wir mal ob die besagten Verzeichnisse sauber bleiben.

Ikarius 23.04.2016 11:36

Hab den Rechner jetzt nen ganzen Tag online. Schaut für mich sauber aus bis jetzt. Hier frische Logs:
Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
durchgeführt von hauptaccount (Administrator) auf hauptaccount-PC (23-04-2016 12:29:46)
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
() C:\Windows\SysWOW64\WinService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe
(Akamai Technologies, Inc.) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Mozilla Messaging) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.168_none_76587b40265ca57e\TiWorker.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-03-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [1904640 2009-03-20] (AVM Berlin)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk Inc.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [MtdAcqu] => C:\Program Files (x86)\Creative\MediaSource5\MtdAcqu.exe [278528 2009-04-29] (Creative Technology Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Akamai NetSession Interface] => C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Google Update] => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify Web Helper] => C:\Users\hauptaccount\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Dropbox Update] => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Run: [Spotify] => C:\Users\hauptaccount\AppData\Roaming\Spotify\Spotify.exe [6891120 2016-04-07] (Spotify Ltd)
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\MountPoints2: {544d41f9-c223-11e0-a29c-6c626d85ef2b} - "G:\pushinst.exe"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-04-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk [2016-03-06]
ShortcutTarget: NETGEAR WG111v2 Smart Wizard.lnk -> C:\Program Files (x86)\NETGEAR\WG111v2\WG111v2.exe ()

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{0992bbb5-df10-4fb2-843f-8d8fa381ae79}: [DhcpNameServer] 192.168.2.1 8.8.8.8
Tcpip\..\Interfaces\{137809a0-0526-4491-886b-b978ec8e9ae3}: [DhcpNameServer] 139.7.30.126 139.7.30.125
Tcpip\..\Interfaces\{17d66e61-a277-45c0-9893-3f72668e7123}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{52240e6b-bb48-4ab6-9d7f-28469705dd80}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{577C4EC8-3969-4285-A25E-65A571745195}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ff109b04-7c58-4bbc-93cf-9912bce3cc10}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => Keine Datei
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2403081755-137120475-2182785957-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://files.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default
FF DefaultSearchEngine,S:
FF SearchEngineOrder.1:
FF SearchEngineOrder.1,S:
FF SelectedSearchEngine,S:
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=3 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: @tools.google.com/Google Update;version=9 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2403081755-137120475-2182785957-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-25] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-10-28] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-15] (Apple Inc.)
FF Extension: WEB.DE MailCheck - C:\Users\hauptaccount\AppData\Roaming\Mozilla\Firefox\Profiles\q4vh3n1l.default\extensions\mailcheck@web.de [2016-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-10-12] [ist nicht signiert]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.bild.de/sport/startseite/sport/sport-home-15479124.bild.html"
CHR Plugin: (Native Client) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => Keine Datei
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\pdf.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\gcswf32.dll => Keine Datei
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => Keine Datei
CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => Keine Datei
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll => Keine Datei
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => Keine Datei
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll => Keine Datei
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll => Keine Datei
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => Keine Datei
CHR Profile: C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-03]
CHR Extension: (Google-Suche) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-03]
CHR Extension: (Stylish) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-04-06]
CHR Extension: (AdBlock) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-16]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Google Mail) - C:\Users\hauptaccount\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.)
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [368640 2009-03-20] (AVM Berlin) [Datei ist nicht signiert]
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-09-08] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-11-17] (Creative Labs) [Datei ist nicht signiert]
S3 Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [79360 2010-11-18] (Creative Labs) [Datei ist nicht signiert]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [Datei ist nicht signiert]
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2015-06-04] () [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-29] (Electronic Arts)
R2 SCM_Service; C:\Windows\SysWOW64\WinService.exe [180224 2007-07-17] () [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580232 2013-05-13] (WiseCleaner.com) [Datei ist nicht signiert]
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [X]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [13848 2016-03-06] (Advanced Micro Devices Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-01-10] (BitRaider)
R3 FWLANUSB; C:\Windows\system32\DRIVERS\fwlanusb.sys [460800 2009-03-20] (AVM GmbH)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-03-06] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [935168 2016-03-06] (Realtek                                            )
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-22 13:28 - 2016-04-22 13:33 - 00007763 _____ C:\Users\hauptaccount\Desktop\Fixlog.txt
2016-04-22 11:59 - 2016-04-22 12:19 - 00000000 ____D C:\Users\hauptaccount\Desktop\00A
2016-04-22 11:54 - 2016-04-22 11:55 - 00000000 ____D C:\Users\hauptaccount\Desktop\Bewerbung
2016-04-21 23:06 - 2016-04-21 23:10 - 00017981 _____ C:\Users\hauptaccount\Desktop\Fixlog2.txt
2016-04-21 22:51 - 2016-04-23 06:04 - 00090374 _____ C:\Users\hauptaccount\Desktop\Addition.txt
2016-04-21 22:49 - 2016-04-23 12:29 - 00026927 _____ C:\Users\hauptaccount\Desktop\FRST.txt
2016-04-20 14:13 - 2016-04-20 14:13 - 02375680 _____ (Farbar) C:\Users\hauptaccount\Desktop\FRST64.exe
2016-04-19 20:49 - 2016-04-19 20:49 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00911540 _____ C:\WINDOWS\Minidump\041916-35562-01.dmp
2016-04-19 18:14 - 2016-04-19 18:14 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 18:13 - 2016-04-19 18:13 - 511780318 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 00:05 - 2016-04-19 00:05 - 00000000 _____ C:\Users\hauptaccount\Desktop\Danke.txt
2016-04-18 18:15 - 2016-04-18 18:16 - 00000000 ____D C:\Users\hauptaccount\Documents\Witcher 2
2016-04-18 18:15 - 2016-04-18 18:15 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\The Witcher 2
2016-04-16 12:48 - 2016-04-16 12:48 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-15 15:46 - 2016-04-15 15:46 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\ProductData
2016-04-15 15:13 - 2016-04-15 15:13 - 00001303 _____ C:\Users\hauptaccount\Desktop\Revo Uninstaller.lnk
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-04-15 15:13 - 2016-04-15 15:13 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-04-15 15:12 - 2016-04-15 15:13 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\hauptaccount\Desktop\revosetup95.exe
2016-04-15 14:50 - 2016-04-15 14:50 - 00000000 ____D C:\ProgramData\ProductData
2016-04-15 14:28 - 2016-04-15 14:28 - 00019906 _____ C:\Users\hauptaccount\Desktop\AdwCleaner[C1].txt
2016-04-15 14:17 - 2016-04-15 14:28 - 00044106 _____ C:\Users\hauptaccount\Desktop\JRT.txt
2016-04-15 14:13 - 2016-04-15 14:14 - 01610352 _____ (Malwarebytes) C:\Users\hauptaccount\Desktop\JRT.exe
2016-04-15 13:57 - 2016-04-15 14:49 - 03677760 _____ C:\Users\hauptaccount\Downloads\AdwCleaner_5.111.exe
2016-04-15 13:55 - 2016-04-15 14:05 - 00000000 ____D C:\AdwCleaner
2016-04-15 13:38 - 2016-04-15 13:55 - 03677760 _____ C:\Users\hauptaccount\Desktop\AdwCleaner_5.111.exe
2016-04-15 10:42 - 2016-04-15 12:33 - 00000000 ____D C:\Users\hauptaccount\Desktop\mbar
2016-04-15 10:42 - 2016-04-15 10:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001 (1).exe
2016-04-14 00:11 - 2016-04-14 00:31 - 00000000 ____D C:\Users\hauptaccount\Desktop\test.4dbase
2016-04-13 18:02 - 2016-04-13 18:10 - 00000000 ____D C:\Users\hauptaccount\Desktop\myfirst4d.4dbase
2016-04-13 14:14 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 14:14 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 14:14 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 14:14 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 14:14 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 14:14 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 14:14 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 14:14 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 14:14 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 14:14 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 14:14 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 14:14 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 14:14 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 14:14 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 14:14 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 14:14 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 14:14 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 14:14 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 14:14 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 14:14 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 14:14 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 14:14 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 14:14 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 14:14 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 14:14 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 14:14 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 14:14 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 14:14 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 14:14 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 14:14 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 14:14 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 14:14 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 14:14 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 14:14 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 14:14 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 14:13 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 14:13 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 14:13 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 14:13 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 14:13 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 14:13 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 14:13 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 14:13 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 14:13 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 14:13 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 14:13 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 14:13 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 14:13 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 14:13 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 14:13 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 14:13 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 14:13 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 14:13 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 14:13 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 14:13 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 14:13 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 14:13 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 14:13 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 14:13 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 14:13 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 14:13 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 14:13 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 14:13 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 14:13 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 14:13 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 14:13 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 14:13 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 14:13 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 14:13 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 14:13 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 14:13 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 14:13 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 14:13 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 14:13 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 14:13 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 14:13 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 14:13 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 14:13 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 14:13 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 14:13 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 14:13 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 14:13 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 14:13 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 14:13 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 14:13 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 14:13 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 14:13 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 14:13 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 14:13 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 14:13 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 14:13 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 14:13 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 14:13 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 14:13 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 14:13 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 14:13 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 14:13 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 14:13 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 14:13 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 14:13 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 14:13 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 14:13 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 14:13 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 14:13 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 14:13 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 14:13 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 14:13 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 14:13 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 14:13 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 14:13 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 14:13 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 14:13 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 14:13 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 14:13 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 14:13 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 14:13 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 14:13 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 14:13 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 14:13 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 14:13 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 14:13 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 14:13 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 14:13 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 14:13 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 14:13 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 14:13 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 14:13 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 14:13 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 14:13 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 14:13 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 14:13 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 14:13 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 14:13 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 14:13 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 14:13 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 14:13 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 14:13 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 14:13 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 14:13 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 14:13 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 14:13 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 14:13 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 14:13 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 14:13 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 14:13 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-13 14:13 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 14:12 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 14:12 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 14:12 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 14:12 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 14:12 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 14:12 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 14:12 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 14:12 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 14:12 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 14:12 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 14:12 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 14:12 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 14:12 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 14:12 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 14:12 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 14:12 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 14:12 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 12:18 - 2016-04-13 12:18 - 00238405 _____ C:\Users\hauptaccount\Desktop\Koordinaten.pdf
2016-04-12 12:40 - 2016-04-13 14:01 - 00000000 ____D C:\ProgramData\ds
2016-04-12 12:40 - 2016-04-12 12:40 - 00000000 _____ C:\Users\hauptaccount\Desktop\Neues Textdokument.txt
2016-04-12 12:35 - 2016-04-12 12:39 - 00092098 _____ C:\Users\hauptaccount\Downloads\Addition.txt
2016-04-12 12:31 - 2016-04-23 12:29 - 00000000 ____D C:\FRST
2016-04-12 12:31 - 2016-04-12 12:39 - 00052813 _____ C:\Users\hauptaccount\Downloads\FRST.txt
2016-04-12 12:22 - 2016-04-15 14:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-12 12:18 - 2016-04-12 12:20 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hauptaccount\Downloads\mbar-1.09.3.1001.exe
2016-04-12 12:03 - 2016-04-14 00:11 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\4D
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\Users\hauptaccount\Library
2016-04-12 12:03 - 2016-04-12 12:03 - 00000000 ____D C:\ProgramData\4D
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\Users\Public\Desktop\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\4D v15.1 32-bit.lnk
2016-04-12 12:02 - 2016-04-12 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4D
2016-04-12 11:26 - 2016-04-12 11:32 - 124274392 _____ (Bitnami) C:\Users\hauptaccount\Downloads\xampp-win32-7.0.4-0-VC14-installer.exe
2016-04-12 11:24 - 2016-04-12 12:01 - 260798936 _____ (4D ) C:\Users\hauptaccount\Downloads\4D v15.1 Windows 32-bit.exe
2016-04-11 17:42 - 2016-04-11 17:42 - 00113399 _____ C:\Users\hauptaccount\Desktop\Formular.pdf
2016-04-11 12:36 - 2016-04-11 12:36 - 00208909 _____ C:\Users\hauptaccount\Desktop\sfv.pdf
2016-04-11 12:32 - 2016-04-11 12:32 - 00208909 _____ C:\Users\hauptaccount\Desktop\Altersnachweis.pdf
2016-04-09 09:38 - 2016-04-09 09:38 - 00000242 _____ C:\Users\hauptaccount\Desktop\asder.txt
2016-04-08 13:17 - 2016-04-08 13:17 - 00815056 _____ C:\Users\hauptaccount\Downloads\Preisliste.pdf
2016-04-07 10:13 - 2016-04-07 10:13 - 00448998 _____ C:\Users\hauptaccount\Desktop\ruecksendeaufkleber.pdf
2016-04-06 07:41 - 2016-04-06 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-04-01 16:48 - 2016-04-01 16:48 - 00000101 _____ C:\Users\hauptaccount\Downloads\tune_in_dsl.asx
2016-03-30 21:15 - 2016-03-30 21:15 - 00316410 _____ C:\Users\hauptaccount\Downloads\Anwendungsentwicklung_2016.pdf
2016-03-24 20:27 - 2016-03-24 20:27 - 00050853 _____ C:\Users\hauptaccount\Downloads\praesentation.pdf
2016-03-24 15:48 - 2016-04-20 19:24 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\vlc
2016-03-24 15:48 - 2016-03-24 15:48 - 00000922 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 15:48 - 2016-03-24 15:48 - 00000000 ____D C:\Program Files\VideoLAN
2016-03-24 15:46 - 2016-03-24 15:46 - 01474568 _____ C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
2016-03-24 15:35 - 2016-03-24 15:35 - 01474568 _____ C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
2016-03-24 15:10 - 2016-03-24 15:11 - 07228590 _____ C:\Users\hauptaccount\Downloads\3527710205_SQLDumm.pdf
2016-03-24 15:08 - 2016-03-24 16:24 - 232950240 _____ C:\Users\hauptaccount\Downloads\Webdesign Packet.rar
2016-03-24 15:03 - 2016-03-24 15:03 - 01631434 _____ C:\Users\hauptaccount\Downloads\PRISM.pdf

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-04-23 12:30 - 2015-09-07 02:02 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BB333740-AAB3-4674-80B2-1F99A47FC46F}
2016-04-23 08:19 - 2010-11-17 20:19 - 00061852 _____ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-23 08:19 - 2010-11-17 20:19 - 00000820 _____ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-23 08:19 - 2010-11-17 19:04 - 00061852 _____ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00421102}.rfx
2016-04-23 07:48 - 2011-09-07 16:31 - 00001144 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-23 07:46 - 2013-02-22 18:42 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-23 07:43 - 2015-06-22 18:04 - 00001228 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-23 06:50 - 2015-08-12 16:27 - 00002489 _____ C:\Users\hauptaccount\Desktop\Google Chrome.lnk
2016-04-23 06:50 - 2011-09-07 16:31 - 00002497 _____ C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-22 18:02 - 2015-12-12 05:55 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-22 18:02 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-22 18:02 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-22 18:02 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-22 14:28 - 2012-05-26 02:18 - 00001142 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job
2016-04-22 14:06 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-22 11:55 - 2016-03-09 09:11 - 00000000 ____D C:\Users\hauptaccount\Desktop\BMW
2016-04-22 11:54 - 2016-03-12 14:07 - 00000000 ____D C:\Users\hauptaccount\Desktop\Telekom
2016-04-22 11:54 - 2016-03-07 20:06 - 00000000 ____D C:\Users\hauptaccount\Desktop\Fachinformatiker
2016-04-22 09:57 - 2010-11-17 16:33 - 00453288 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-22 09:39 - 2013-05-19 15:12 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Wise Care 365
2016-04-22 09:34 - 2015-12-12 06:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-22 00:19 - 2015-12-13 14:39 - 00001447 _____ C:\Users\hauptaccount\Desktop\Dragon Age Origins.lnk
2016-04-22 00:12 - 2015-04-02 22:30 - 00000000 ____D C:\ProgramData\Origin
2016-04-21 23:48 - 2015-02-07 21:22 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job
2016-04-21 23:12 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-04-21 23:09 - 2015-09-06 20:41 - 00000000 ____D C:\Users\hauptaccount\Desktop\Media
2016-04-21 22:41 - 2015-12-12 05:55 - 00000000 ____D C:\Users\hauptaccount
2016-04-21 16:43 - 2015-06-22 18:04 - 00001176 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-21 02:28 - 2012-05-26 02:18 - 00001120 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job
2016-04-18 18:16 - 2015-05-02 12:20 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-17 17:03 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Spotify
2016-04-17 16:56 - 2015-04-09 15:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Spotify
2016-04-16 15:54 - 2014-08-05 23:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-16 12:48 - 2011-08-28 21:19 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Dropbox
2016-04-15 16:05 - 2016-03-06 02:42 - 00000260 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job
2016-04-15 15:46 - 2012-05-30 22:01 - 00000000 ____D C:\Users\hauptaccount\AppData\LocalLow\Temp
2016-04-15 15:16 - 2015-10-30 08:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-04-15 14:20 - 2016-03-06 02:39 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\IObit
2016-04-15 11:54 - 2016-03-06 02:33 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-15 11:54 - 2016-03-06 02:33 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-15 11:31 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-04-15 10:29 - 2013-03-19 21:22 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Avira
2016-04-15 08:25 - 2015-11-15 22:53 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\CodeBlocks
2016-04-15 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-13 14:49 - 2015-12-12 05:49 - 00371792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 14:46 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 14:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-13 14:25 - 2013-08-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 14:16 - 2010-11-17 17:30 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Apple Computer
2016-04-12 12:03 - 2010-11-20 20:10 - 00000000 ____D C:\Users\hauptaccount\AppData\Local\Apple Computer
2016-04-10 16:53 - 2015-05-02 12:29 - 00000000 ____D C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-04-08 09:46 - 2013-02-22 18:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-06 07:41 - 2015-11-17 16:43 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-04-06 07:41 - 2015-08-05 14:59 - 00002015 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-29 21:55 - 2015-04-02 22:30 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-28 00:40 - 2016-03-21 22:52 - 00000145 _____ C:\Users\hauptaccount\Desktop\plan.txt

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2011-01-30 22:41 - 2013-03-30 23:26 - 0004608 _____ () C:\Users\hauptaccount\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-19 22:42 - 2016-01-31 20:58 - 0000600 _____ () C:\Users\hauptaccount\AppData\Local\PUTTY.RND
2015-01-01 17:36 - 2015-01-01 17:36 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-12 05:52 - 2015-12-12 05:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2010-11-26 17:05 - 2010-11-26 17:05 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-10-28 19:11 - 2015-10-28 19:11 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-04-21 09:23

==================== Ende von FRST.txt ============================


Ikarius 23.04.2016 11:37

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-23 12:30:33)
Gestartet von C:\Users\hauptaccount\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-12 04:36:43)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2403081755-137120475-2182785957-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2403081755-137120475-2182785957-503 - Limited - Disabled)
Gast (S-1-5-21-2403081755-137120475-2182785957-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2403081755-137120475-2182785957-1002 - Limited - Enabled)
Neu (S-1-5-21-2403081755-137120475-2182785957-1003 - Limited - Enabled) => C:\Users\Neu
hauptaccount (S-1-5-21-2403081755-137120475-2182785957-1001 - Administrator - Enabled) => C:\Users\hauptaccount

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

4D v15.1 32-bit (HKLM-x32\...\{060AED6F-A53C-004D-1500-A0000181373}_is1) (Version: 15.1.192.845 - 4D)
7-Zip 15.10 beta (x64) (HKLM\...\7-Zip) (Version: 15.10 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Akamai NetSession Interface (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version:  - Frictional Games)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Application Insights Tools for Visual Studio 2015 (x32 Version: 3.3 - Microsoft Corporation) Hidden
Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.00 - Ubisoft)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.01 - Ubisoft)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
Assassin's Creed Revelations 1.02 (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.02 - Ubisoft)
Assassin's Creed(R) III v1.02 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.02 - Ubisoft)
AutoCAD 2016 (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack - Deutsch (German) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 - English (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Language Pack - Deutsch (German) (Version: 20.0.46.0 - Autodesk) Hidden
AutoCAD Mechanical 2016 Private (Version: 20.0.46.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD Mechanical 2016 - Deutsch (German) (HKLM\...\AutoCAD Mechanical 2016 - Deutsch (German)) (Version: 20.0.46.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version:  - AVM Berlin)
Azure AD Authentication Connected Service (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{5AD205E9-E80E-4F4B-88A5-C6B5CC12BBE4}) (Version: 2.48.0 - Kovid Goyal)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CodeBlocks (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
CopyTrans Control Center deinstallieren (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\CopyTrans Suite) (Version: 3.003 - WindSolutions)
Creative 3DMIDI Player (HKLM-x32\...\3DMIDI) (Version: 1.11 - Creative Technology Limited)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.41 - Creative Technology Limited)
Creative Audio-Systemsteuerung (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Konsole Starter (HKLM-x32\...\Console Launcher) (Version: 2.61 - Creative Technology Limited)
Creative Media Toolbox 6 (HKLM-x32\...\{F1A14CB2-A048-45A6-AFDA-3571296E1D76}) (Version: 6.02 - Creative Technology Limited)
Creative Media Toolbox 6 (Shared Components) (HKLM-x32\...\Uninstaller_B4736000_Creative Media Toolbox 6) (Version: 2.80.12 - Creative Labs)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.26 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.02 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM-x32\...\WaveStudio 7) (Version: 7.12 - Creative Technology Limited)
Creative-Diagnose (HKLM-x32\...\Diagnostics 4_5) (Version: 5.11 - Creative Technology Limited)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Steam App 214340) (Version:  - Daedalic Entertainment)
Devenv-Ressourcen für Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version:  - Codemasters Racing Studio)
DiskBoss 5.7.14 (HKLM-x32\...\DiskBoss) (Version: 5.7.14 - Flexense Computing Systems Ltd.)
Dolby Digital Live Pack (HKLM-x32\...\Dolby Digital Live Pack) (Version: 3.00 - Creative Technology Limited)
Dotfuscator and Analytics Community Edition 5.18.1 (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition Language Pack 5.18.1 de-DE (x32 Version: 5.18.1.2898 - PreEmptive Solutions) Hidden
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dragon Age™ II (HKLM-x32\...\{4D565319-8B91-41CB-961C-0DDC86101AC5}) (Version: 1.04.8524.0 - Electronic Arts)
Driver Booster 3.2 (HKLM-x32\...\Driver Booster_is1) (Version: 3.2 - IObit)
Dropbox (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
DTS Connect Pack (HKLM-x32\...\DTS Connect Pack) (Version: 1.00 - Creative Technology Limited)
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
Entity Framework 6.1.3 Tools  for Visual Studio 2015 (HKLM-x32\...\{1A8A9739-BAD7-491F-B5B9-A79A2B965422}) (Version: 14.0.40302.0 - Microsoft Corporation)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Erforderliche Komponenten für SSDT  (HKLM-x32\...\{2466E484-9D86-416B-9C88-AA533F15AF1C}) (Version: 12.0.2000.8 - Microsoft Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FileZilla Client 3.10.1.1 (HKLM-x32\...\FileZilla Client) (Version: 3.10.1.1 - Tim Kosse)
Fotostory 3 für Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Gemeinsam genutzte Microsoft Azure-Komponenten für Visual Studio 2015 Sprachpaket (DEU) - v1.5 (x32 Version: 1.5.30619.1602 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Google Chrome) (Version: 50.0.2661.87 - Google Inc.)
GRID 2 (HKLM-x32\...\Steam App 44350) (Version:  - Codemasters Racing)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (HKLM\...\{61ADDE9C-3AE6-46FC-9127-DFFF637AED03}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Hilfe (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iBackup Extractor (HKLM-x32\...\{DCD902B5-EA90-4C56-8D7A-474C3F0348AB}) (Version: 2.19 - Wide Angle Software)
IIS 10.0 Express (HKLM\...\{5984D8DA-C1AF-4284-9C88-D7150425B315}) (Version: 10.0.1734 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation)
Lego Harry Potter (HKLM-x32\...\Steam App 21130) (Version:  - TT Games)
LEGO Harry Potter: Years 5-7 (HKLM-x32\...\Steam App 204120) (Version:  - Traveller's Tales )
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
MAGIX Foto & Grafik Designer 6 SE (HKLM-x32\...\MAGIX_{591B29D8-4A37-4202-9F74-3B43A45EC036}) (Version: 6.1.3.24817 - MAGIX AG)
MAGIX Foto & Grafik Designer 6 SE (Version: 6.1.3.24817 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{C7411D97-EF5E-46B2-8B49-E408A344DF82}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Mass Effect™ 2 (HKLM-x32\...\{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}) (Version: 1.2.1604.0 - Electronic Arts)
Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.309.1 - McAfee, Inc.)
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (Deutsch) (HKLM-x32\...\{CBD7095F-7211-43FD-9FE7-FB08D753AF79}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (Deutsch) (HKLM-x32\...\{EE8BD24B-75E1-4BBF-86B9-91FE16ADE71C}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Help Viewer 2.2 Sprachpaket - DEU (HKLM-x32\...\Microsoft Help Viewer 2.2 Sprachpaket - DEU) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{F09DEB00-9F41-4BC9-BA81-9F131B12B3D5}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{8E4BA1E5-54E8-41F0-919B-CD875B83CFCE}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 DEU  (HKLM\...\{98225B15-ECF5-4645-B5AC-F8C5E869A5D5}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - DEU (14.0.50616.0) (HKLM-x32\...\{FA604873-01A0-4834-AF87-418534E465BB}) (Version: 14.0.50616.0 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects  (HKLM-x32\...\{4F4CB3E2-9D2F-465A-854B-8276B02F4E7D}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Management Objects (x64) (HKLM\...\{03CB711D-679E-46ED-851B-C568418CF914}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 Transact-SQL ScriptDom  (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server*2014 T-SQL Language Service  (HKLM-x32\...\{06BE8B71-46C6-434B-869E-85C58EF3120A}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 (HKLM-x32\...\{5c2b89b0-08cc-492f-b086-21e4d6ae7be4}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{63967E7E-5D53-42FA-A7B2-DC50FB0F976F}) (Version: 12.0.2402.11 - Microsoft Corporation)
Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM-x32\...\{2ADB6B9D-83C6-494E-B8AE-E815956A4670}) (Version: 12.0.2402.11 - Microsoft Corporation)
Mit C# erstellte geräteübergreifende Hybrid-Apps - Vorlagen - DEU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.22.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 43.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 de)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
Mozilla Thunderbird (3.1.20) (HKLM-x32\...\Mozilla Thunderbird (3.1.20)) (Version: 3.1.20 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version:  - NCsoft)
Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts)
NETGEAR WG111v2 wireless USB 2.0 adapter (HKLM-x32\...\{4102037D-E8E0-48E0-B203-E521D194FB71}) (Version: 1.0.0.133 - NETGEAR)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.2 (HKLM-x32\...\{8D1E61D1-1395-4E97-997F-D002DB3A5074}) (Version: 3.2.9502 - OpenOffice.org)
OptimizerPro (HKLM\...\{941F7321-8A87-1826-FACD-C2A54FFC51D7}) (Version: 1.0 - PC Utilities Pro) <==== ACHTUNG
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Paint.NET v3.5.6 (HKLM\...\{639673E9-D53F-44F4-A046-485C8A6ADA16}) (Version: 3.56.0 - dotPDN LLC)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM-x32\...\{D5409B11-EF28-37A1-AE7A-6051A5BAD923}) (Version: 4.5.50932 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 RC für Windows Store-Apps (Deutsch) (x32 Version: 4.5.21005 - Microsoft Corporation) Hidden
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM-x32\...\{3F514FDC-F0F2-3B99-86D6-F7B3A2679B39}) (Version: 4.5.51209 - Microsoft Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6 (Deutsch) (HKLM-x32\...\{7227EFF8-BC26-44D4-B91D-969A82DBDF4A}) (Version: 4.6.00081 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PreEmptive Analytics Client German Language Pack (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15072.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.)
Secure Global Desktop Client (HKLM-x32\...\{7D497CBD-B714-4B8D-821E-7CC5E508E02A}) (Version: 5.20.911 - Oracle)
Similarity 64-bit 1.9.2 (HKLM\...\{02F06E82-CCC3-4F71-ADC6-A65338E4A9DF}) (Version: 1.9.1941 - GAR Software)
SketchUp-Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Sound Blaster X-Fi (HKLM-x32\...\{20288888-A7AF-4B24-8AEB-398D20CD563C}) (Version: 1.0 - Creative Technology Limited)
SoundFont-Bank-Manager (HKLM-x32\...\SFBM) (Version: 3.21 - Creative Technology Limited)
Spotify (HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\Spotify) (Version: 1.0.26.132.ga4e3ccee - Spotify AB)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Studie zur Verbesserung von HP Deskjet 3050A J611 series Produkten (HKLM\...\{EF27865C-E636-47C4-8B35-CE8A88045681}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Explorer for Microsoft Visual Studio 2015 (x32 Version: 14.0.23102 - Microsoft Corporation) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM\...\Steam App 20920) (Version:  - CD PROJEKT RED)
TypeScript Power Tool (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.6.3.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 (HKLM-x32\...\{da31aa25-410a-4c1b-9ec0-114dd8dff786}) (Version: 1.6.23313.0 - Microsoft Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft)
Verfügbare Autodesk-Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WCF Data Services 5.6.4 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 DEU Language Pack (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{04991C5B-9ABF-48F7-AB39-48051DBBD48E}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{0F7BC65C-AB86-4BA1-A3A5-63539C2BD78B}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{44B7A29C-EAEA-4527-B0B0-297E61EFEE3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{641094DE-35F7-4CAC-AFF1-C39AABA22E43}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{6E2A9D17-D1DA-43E9-94E6-C513D3315891}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\hauptaccount\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{91520053-F024-4E94-B185-C80D25E0F985}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A00B0751-378A-4254-8689-8BA2DD25283F}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\Acadm\AmgAdc.arx (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{A5DC4F3D-CB7E-46DF-A1DE-51421A94232C}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{C532F3AD-EFAD-41C0-8864-0093FF43D06A}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{DD7A3651-067D-4AC2-AB5B-EB851BA9486C}\InprocServer32 -> AcmPEXCtrl.ocx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\de-DE\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{EFE2B983-6FB7-463C-AFF2-E513228567F7}\InprocServer32 -> g3vPartAuthEnviron.arx => Keine Datei
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FD4044AD-1CA6-4dd3-814D-B2ECB0431853}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acadm\AcmPmDb32.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2403081755-137120475-2182785957-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\hauptaccount\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Keine Datei

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03A51DBB-B18A-4DDB-8045-6E1D42336C1E} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {186B4E04-021D-41B7-9CC4-713F57802CA0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {18C70101-D2FE-4B47-84BE-79ADFD49C40F} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {1C75545C-FD6F-457A-8253-86675D242756} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {1D10BBA1-2DF5-4D33-9C64-6CA941FBD1C2} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {1FB48E67-16E3-4E96-ABEC-9C37C753FB6C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {28A42D0A-E9C1-4081-A642-5730D2A3C82A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {34BBF02F-29B2-42BC-A655-EAF0C4FAFA6A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {386458E0-9863-4FE5-B0DC-B47BE55145D5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {3900C47C-FD33-4A8F-A899-2C7B73074F06} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {3E42D75C-378E-4791-853F-C75EFAE4F484} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {47C0E378-7AE7-413D-B914-6067F67633D3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {4D5AEFB6-A90D-42BB-9F24-142B706232B6} - System32\Tasks\{AAF64877-10CC-4BDF-82C7-1D99D4B25587} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered
Task: {53CDC819-67F0-48B6-9DEB-3BC7F3C500E4} - System32\Tasks\ASC9_SkipUac_hauptaccount => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {5F951B56-139F-42AC-8078-09AD87312212} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6428A06A-F80F-4C00-8ADB-93AC758FA8C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {718E1B6C-5CB8-41A5-B90B-B2C719A7E1E8} - System32\Tasks\{BCCEA788-C4BE-4449-AF0B-9FAB75E7E020} => pcalua.exe -a C:\Users\hauptaccount\Downloads\DH2_PC_FNL_0603_28899_DEMO.sfx.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {795D2129-8945-47E4-AF4E-B273A4F499D7} - System32\Tasks\{B75F860E-EFCD-45E2-A73D-5C220B0463BF} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe" -d "C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations"
Task: {834904DB-19AC-4DD4-BA23-E5C5AE6918F1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {95D69F5D-48F9-4F6E-96C3-5176C924697D} - System32\Tasks\{1D938612-5C95-4CF2-80C3-F4E3AD615340} => Firefox.exe hxxp://ui.skype.com/ui/0/5.3.0.120/en/abandoninstall?page=tsMain&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {AB93911F-97CD-4077-B905-6B8EC2D7A961} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {ADE2EF5F-BC9E-4D97-81E4-3442FAFE26AB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {AEDFD6E0-B909-40D5-B8E0-5558A19CD985} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {B24384C1-BDF6-43B2-BDF1-4CBCBFC8E45A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {B3B9B45D-6CF7-477C-9AB2-616ECB85F3D2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {BF24F28C-52BA-4A90-9F6D-E135240538DE} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BFDDA990-819F-4DCF-9C0E-66862D59EEC7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {C21655AE-0130-44F3-A748-3FFFDDEE1C98} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {C29362A6-3450-466E-B25A-D248715775CE} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {CA9097AE-4AC5-4B0A-ADD0-B28045D90A3D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221 => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {CAF3054E-4C3A-4EAB-A534-4CAAAB52E36D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D3900B3C-5207-4563-BCA7-A7FAC859A740} - System32\Tasks\{97473157-E47E-4B5D-9451-7AB55F27EF85} => C:\Program Files (x86)\Skype\\Phone\Skype.exe
Task: {D3A20EEE-FE63-43A2-99A3-FBFBC41A38BD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D6686F56-F7C4-421D-9789-1A00278B2686} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DDA7E1C9-33C2-4BCA-BAC7-45B7E493CCE0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {E7AC035B-AA27-4620-908B-AC2CAB2F8722} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-06] (Facebook Inc.)
Task: {E7D0CF71-23D9-4C58-B509-61D593019E91} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {EB077062-A2EB-4AD6-85B8-C86DF2C1D481} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F22AE5CC-FD1E-4CA7-8278-52EE2AA081F8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {FF583589-4D1E-4DAF-8B1D-EC469E5457AB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_hauptaccount.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cf898be2613db8.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cfecf1dfe084ae.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1cffee7ae4e687e.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001Core1d0430b5a4eb221.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2403081755-137120475-2182785957-1001UA.job => C:\Users\hauptaccount\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ScanToPCActivationApp.exe_{4C925BC2-1153-4BE0-AB3B-38995AC5C3A4}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\Toolbox.exe_{6CE2FC06-7111-4252-A4D4-441E475827D9}.job => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\Toolbox.exe
Task: C:\WINDOWS\Tasks\Updater scan.job => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\hauptaccount\Desktop\Programme\CrossLoop Connect.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\hauptaccount\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\hauptaccount\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2011-11-30 22:58 - 2005-03-12 02:07 - 00087040 _____ () C:\WINDOWS\System32\pdfcmnnt.dll
2015-01-09 12:21 - 2013-07-23 05:47 - 00239696 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2010-11-19 19:58 - 2007-07-17 16:48 - 00180224 _____ () C:\Windows\SysWOW64\WinService.exe
2015-06-04 11:49 - 2015-06-04 11:49 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 14:14 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2014-12-08 12:10 - 2014-12-08 12:10 - 00102176 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-17 20:13 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 14:12 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-03-03 23:46 - 2016-03-03 23:46 - 00016384 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2016-03-03 23:46 - 2016-03-03 23:46 - 16062976 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2016-03-03 23:46 - 2016-03-03 23:46 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2016-04-13 14:13 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 14:13 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 14:14 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 14:14 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-06-04 11:38 - 2015-06-04 11:38 - 00729088 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2015-06-04 11:41 - 2015-06-04 11:41 - 02797568 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2015-10-28 19:19 - 2016-02-24 06:48 - 00062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2015-10-28 19:19 - 2016-02-24 06:47 - 00110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2016-01-21 22:10 - 2016-01-21 22:12 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 22:10 - 2016-01-21 22:13 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00848536 _____ () C:\Program Files (x86)\Mozilla Thunderbird\js3250.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00161944 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2010-12-11 15:10 - 2012-05-23 16:07 - 00021656 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2016-03-05 16:47 - 2016-02-19 11:42 - 00074272 _____ () C:\Program Files (x86)\PDF24\zlib.dll
2016-03-05 16:47 - 2016-02-19 11:42 - 00052256 _____ () C:\Program Files (x86)\PDF24\OperationUI.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 01675928 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libglesv2.dll
2016-04-12 11:50 - 2016-04-06 12:04 - 00086168 _____ () C:\Users\hauptaccount\AppData\Local\Google\Chrome\Application\49.0.2623.112\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2403081755-137120475-2182785957-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\hauptaccount\Desktop\daisy_ridley_rey_star_wars_the_force_awakens-wide.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\Run: => "EvtMgr6"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2403081755-137120475-2182785957-1001\...\StartupApproved\Run: => "Advanced SystemCare 9"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{AD51DE6B-C9B1-4164-BD60-3BC25F8854EE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{49DB6479-C1E9-4357-B017-9EAEDA546A0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DiRT Showdown\showdown.exe
FirewallRules: [{F07E737F-2F5E-4F45-9E4B-DDCE5A08E043}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{360A3889-E9A3-47E3-9034-266514FE8EDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe
FirewallRules: [{12A932E9-FEC7-4D61-841E-D69D86F51B17}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{4BD0096B-6043-4F25-A3BD-E27DD60BB2B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\VisionaireConfigurationTool.exe
FirewallRules: [{CA01DBEC-95C8-4D7E-B9F2-ADB4F5C068CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{56A7AD21-A81E-4D14-8695-0248DF9A6492}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Deponia\deponia.exe
FirewallRules: [{69455898-9405-4C0B-B9D0-9D41DCC3C6FF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{6E411998-E361-43E1-8978-401F8DD55529}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Batman Arkham City GOTY\Binaries\Win32\BatmanAC.exe
FirewallRules: [{675FCFBC-FAAB-4CF1-80CB-DE2CAF55007D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BDA4219E-0113-47A4-9D66-94719F839B1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7E521AAC-CB5D-4D91-BCB8-5FFA8BEFE093}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{96E65796-2633-473A-888F-0F1880191EC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{E982F48C-3AF9-4B16-A3E4-F2C9A5431EB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{839BE1B0-8235-4107-BC21-4AED0D10B420}] => (Allow) LPort=50248
FirewallRules: [{C52EC5E8-CFF4-415C-A847-E7355FC71A9D}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{5FC29469-D7D9-41C3-9814-165FC997B11A}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [UDP Query User{614B5953-0181-4C6A-AFD6-59C7A40F7C31}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [TCP Query User{F999B071-BFBC-4A32-B63B-F43BFF6AA63E}C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe] => (Block) C:\program files (x86)\origin games\mass effect 2\binaries\me2game.exe
FirewallRules: [{532988F8-6F04-40CE-B576-5A4ACBDF8C41}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{A3466CFA-F7BA-4E4B-ADCD-10AA28A0CF50}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{0E835A39-D5D0-4D8E-B6B3-695496B0AAB5}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{BDEACF4E-3E36-4915-99F5-289CCBF4DBD2}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{D6DDBAD3-0787-42E7-B04F-2C95E6922A50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{F9DD10AA-8A9C-40C5-BEA9-308D712EB33D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cities_Skylines\Cities.exe
FirewallRules: [{3D624A89-212E-4F64-93DD-21AFCB0D310F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{E472E570-5F43-4494-A868-A768B0CDF448}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{44288BF3-4B30-43A0-B22D-0584BA343FB0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{C053525F-534C-40F0-8EFF-BDD52C98F58E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [UDP Query User{F2A02945-3C87-4A65-9519-C2E3FDA21D69}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [TCP Query User{9A2DA13D-5C55-4220-86B0-655DC052234B}C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe] => (Block) C:\program files (x86)\cheat engine 6.2\cheatengine-x86_64.exe
FirewallRules: [UDP Query User{0DA53FAF-5FF3-4A4C-ADE4-3CE42E45B674}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [TCP Query User{BD108F92-4F3F-4647-872F-6199EDBB143D}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{B4E48650-9605-446F-A11D-982E8964520D}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [TCP Query User{F4EA0057-A5BA-4AD7-A48C-1AA16619514E}C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe
FirewallRules: [UDP Query User{1A13509F-EDCB-4E3B-95F6-2B185E790C1B}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [TCP Query User{E9F19CD3-5007-4B52-AEBA-5DAE7CEEFB92}C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed revelations\acrsp.exe
FirewallRules: [{AE044514-BF2B-4C11-B5D9-C4A48956C34D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E62B65E3-C979-4629-9D8C-2CE34F1A8A12}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9378C159-0A6C-4FD1-A56F-65ED79004D55}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F41A0F4D-735E-4E53-B43D-515F9ADCCA39}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9E65F92F-0D72-4ACE-961A-1D7A9DDD5BD8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{097BC5B3-4A03-4C2E-9778-31B7992D38C0}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{6FBD0E8E-CE42-43A6-9389-881F01CBF253}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{3A020471-6038-42BC-AB77-F183D124F3A8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{DAF070DE-780B-43B1-975F-80A62FED1AC9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{CCDB9E56-AF6F-4887-AD49-3B751FEDBA49}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [UDP Query User{0E6499F4-F843-4944-BFEB-2F3C59AC3730}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [TCP Query User{BC9236F3-AF5A-4FFF-A1B7-A7BD53EB1CF9}C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed ii\assassinscreediigame.exe
FirewallRules: [{D37C5E27-4523-4B6B-A012-E18B65E2DB9C}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{958E4195-DFAD-468F-8900-EB9D7E235818}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{E55EF19B-F5C9-418F-A57D-3EEDFCCC6932}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CC54A3FC-38DF-42A7-97C0-2A991FDEF662}] => (Allow) C:\Users\hauptaccount\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{B7352A49-6E07-4B4D-9F7F-6753AA9E3AB1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{20D2BA0C-44A7-409F-93D8-F287A5CA3B64}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82E0A447-525E-4955-9336-C586C9C84340}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{B18D973E-608F-4BDC-B124-34567C34D795}] => (Allow) C:\Users\hauptaccount\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6405B705-EB5C-4C5D-BEA2-0A578ECEE16B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D1FA242D-4612-489F-B71C-5F9B2EDBA3C1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{83CCBC3B-8F18-4C1C-B149-8523F5566A91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0CD7078E-3C76-488A-AAC2-1839DA9545B0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4046F377-D4A6-4F1B-A5C8-AAF903540B79}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3B07E24E-09B1-4AAF-8AD7-F2EFF3B324EC}] => (Allow) LPort=2869
FirewallRules: [{479F733C-EB64-44C7-B365-C7DB6B94AAC4}] => (Allow) LPort=1900
FirewallRules: [{F84F3077-AFDA-4684-8345-E8F7E7CEC96F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4455DB16-8815-464A-BE0B-3F57D0034526}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [{1D482CDE-03FC-4142-9B6A-B6898A4AD7C2}] => (Allow) C:\Users\hauptaccount\AppData\Local\Akamai\netsession_win.exe
FirewallRules: [TCP Query User{B12FBA4D-5F72-480E-BA90-47870E0E29C0}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{3F3F3F75-2587-49E6-89CF-C630002330B7}C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\hauptaccount\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{2B97F9A5-C451-4A3F-993E-4555E2729280}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{E0090928-BA78-4861-B8F4-1FB1A5C89FDD}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{1FD7A7E7-C9CF-4864-8685-53D1EC51054B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{BC73F2B6-A954-4EB2-A328-8F3689C564AB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{8C134532-D818-4294-9D7D-D4AE29073352}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B10045F7-B708-4D89-B075-03493191F636}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0BAAA2FD-8F7B-426B-9A53-143D4E68AB17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{0EF72D8D-B35C-4E0E-9F63-8EAA8F2A17A0}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4139F53C-0553-46F6-8555-1F85641B3BDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BDC71C71-A44E-4722-B942-58E26CBD913E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{1F213E3C-9180-4E5B-9320-CF03AE9654C2}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6E894F65-5052-424D-BD18-0C961591C56F}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{BE2172DF-C839-4097-B4D3-969333253024}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{DCFFD869-596F-4E20-924A-8534ED8B0AD1}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{EF3F86B6-1C59-4F62-A77A-E7BE239C2D66}] => (Allow) C:\Users\hauptaccount\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{59675A51-8474-4E23-AB0E-191842866167}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C92BEA7E-E2A5-449B-B5F1-F9F5E4489B75}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF746806-3649-4100-8936-3DC7DE333833}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{73F8BA67-9244-42D3-820E-151FF87D5B2E}C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\hauptaccount\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0E400365-4B70-48B9-88A8-E9246CFF8BD3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8A5F7ED2-5328-4291-9674-0FDFA07A893E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9C0CCB30-EB8C-4941-B6BB-447677EDC842}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{29FFA2F3-3A36-441C-8687-E10B73CE3A40}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{A1F74D6B-E533-4DBE-A12A-3FAF7147D9AC}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [UDP Query User{6BA9E72D-D8EF-4236-9074-AA7C0CCF0226}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe
FirewallRules: [TCP Query User{9EF2952B-1F1A-4FD0-ACD7-C3DEB718018A}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{1E5A065F-C2BD-446F-9D7E-414CAC337277}C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\hauptaccount\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{0BC83941-D4F1-4591-AA56-A896795DD98E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{ACF5136F-4561-45A4-975C-E444F0B99CBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{0E32A8EF-58D1-4086-A63E-1EA05615DFBC}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{13942FCD-94F7-4DD8-ACE0-B6CF88F9E7A0}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{20DCB5F4-6617-4175-AE31-E25B634AD5F1}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{20738B73-7521-4D28-9F77-7DD10B6D8123}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age II\bin_ship\DragonAge2.exe
FirewallRules: [{4BDFE6DF-F24A-413A-8106-961466A0C7FB}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{8F3992F9-4AD4-4CB6-9051-307F2E6982C8}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe
FirewallRules: [{9B701854-975D-4E33-A2F6-4BB4DF52F527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{5A05369A-B524-4927-BC70-6C130A5CB29D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter\LEGOHarryPotter.exe
FirewallRules: [{FAC8E091-142C-4B94-9BB6-BD681ECEA8AE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{E77A0E3C-3392-4D6C-8FA8-E8B2CCD5C3E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO Harry Potter Years 5-7\harry2.exe
FirewallRules: [{FCA69E9E-5F9C-4017-BA34-56A0990113DA}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [{21E0F41D-D786-4B74-8F22-DD034830B1A5}] => (Allow) D:\SteamLibrary\steamapps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{7773E817-0D95-4EA8-BCB4-0A3B29108ADF}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{DC163F1E-AF2F-4676-AC19-C9E3051B493F}D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{EAC7F226-CCDC-4A17-AA64-697F87B2838D}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{162168E4-1F32-4512-BDC3-BCEF7BE949AB}] => (Block) D:\steamlibrary\steamapps\common\the witcher 2\bin\witcher2.exe

==================== Wiederherstellungspunkte =========================

15-04-2016 11:29:49 Malwarebytes Anti-Rootkit Restore Point
15-04-2016 14:14:46 JRT Pre-Junkware Removal
15-04-2016 14:20:14 JRT Pre-Junkware Removal
16-04-2016 15:54:01 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
18-04-2016 18:13:19 DirectX wurde installiert

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Renesas USB 3.0 eXtensible-Hostcontroller – 0.96 (Microsoft)
Description: USB-xHCI-kompatibler Hostcontroller
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Generischer USB-xHCI-Hostcontroller
Service: USBXHCI
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (04/22/2016 11:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/22/2016 10:57:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x13d4
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5

Error: (04/21/2016 11:28:07 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 11:14:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WG111v2.exe, Version: 1.0.0.169, Zeitstempel: 0x461ef040
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 10.0.10586.162, Zeitstempel: 0x56cd55ab
Ausnahmecode: 0xc00000fd
Fehleroffset: 0x000a26e9
ID des fehlerhaften Prozesses: 0x17ac
Startzeit der fehlerhaften Anwendung: 0xWG111v2.exe0
Pfad der fehlerhaften Anwendung: WG111v2.exe1
Pfad des fehlerhaften Moduls: WG111v2.exe2
Berichtskennung: WG111v2.exe3
Vollständiger Name des fehlerhaften Pakets: WG111v2.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WG111v2.exe5

Error: (04/21/2016 10:34:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: hauptaccount-PC)
Description: Bei der Aktivierung der App „windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (04/21/2016 08:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 05:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 02:28:05 PM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 11:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s

Error: (04/21/2016 08:28:05 AM) (Source: Google Update) (EventID: 20) (User: hauptaccount-PC)
Description: Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http s


Systemfehler:
=============
Error: (04/23/2016 12:26:32 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.

Error: (04/23/2016 05:59:50 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.

Error: (04/22/2016 05:58:46 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Für den Miniport "AVM FRITZ!WLAN USB Stick v1.1, {17D66E61-A277-45C0-9893-3F72668E7123}" ist das Ereignis "74" aufgetreten.

Error: (04/22/2016 09:34:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/22/2016 09:34:57 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/22/2016 09:34:33 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/22/2016 09:34:34 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎22.‎04.‎2016 um 01:52:59 unerwartet heruntergefahren.

Error: (04/21/2016 11:13:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "LiveUpdateSvc" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (04/21/2016 11:13:09 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058

Error: (04/21/2016 11:12:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AdvancedSystemCareService9" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2


CodeIntegrity:
===================================
  Date: 2016-04-21 09:36:27.318
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-21 09:36:27.302
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-21 09:36:27.269
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.084
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.071
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 15:40:33.037
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:38:51.950
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:38:51.930
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.350
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-04-20 14:37:48.335
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen ===========================

Prozessor: AMD Phenom(tm) II X6 1090T Processor
Prozentuale Nutzung des RAM: 64%
Installierter physikalischer RAM: 4095.18 MB
Verfügbarer physikalischer RAM: 1458.93 MB
Summe virtueller Speicher: 8191.18 MB
Verfügbarer virtueller Speicher: 4674.82 MB

==================== Laufwerke ================================

Drive c: (SYSTEM) (Fixed) (Total:487.74 GB) (Free:107.91 GB) NTFS
Drive d: (DATEN) (Fixed) (Total:443.23 GB) (Free:377.66 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B08A3AF5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=487.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 23.04.2016 20:05

Lass uns nochmal nachschauen...Rechner ruhig online lassen

FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Ikarius 23.04.2016 20:32

Gerne doch:
Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-23 21:26:42) Run:9
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
cmd: dir /oge-d %APPDATA%
cmd: dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
cmd: dir /oge-d %PROGRAMDATA%
emptytemp:
*****************


=========  dir /oge-d %APPDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming

22.04.2016  09:39    <DIR>          Wise Care 365
21.04.2016  23:11    <DIR>          ..
21.04.2016  23:11    <DIR>          .
20.04.2016  19:24    <DIR>          vlc
17.04.2016  16:56    <DIR>          Spotify
16.04.2016  12:48    <DIR>          Dropbox
15.04.2016  15:46    <DIR>          ProductData
15.04.2016  14:20    <DIR>          IObit
15.04.2016  10:29    <DIR>          Avira
15.04.2016  08:25    <DIR>          CodeBlocks
14.04.2016  00:11    <DIR>          4D
12.04.2016  12:03    <DIR>          Apple Computer
05.03.2016  07:59    <DIR>          WB Games
18.02.2016  12:30    <DIR>          calibre
18.02.2016  11:56    <DIR>          Propellerhead Software
01.02.2016  01:37    <DIR>          FileZilla
25.11.2015  17:36    <DIR>          DS4Windows
11.11.2015  17:45    <DIR>          NuGet
03.11.2015  22:24    <DIR>          Sun
28.10.2015  20:38    <DIR>          Autodesk
11.10.2015  09:42    <DIR>          Notepad++
08.09.2015  23:56    <DIR>          Ubisoft
06.08.2015  16:32    <DIR>          Origin
02.08.2015  17:14    <DIR>          Samsung
24.06.2015  23:07    <DIR>          Similarity
03.04.2015  16:29    <DIR>          Daminion Software
21.03.2015  06:01    <DIR>          HpUpdate
12.03.2015  00:59    <DIR>          iMobie
11.03.2015  23:54    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          Abelssoft
10.02.2015  19:04    <DIR>          DesktopIconGoodgame
08.07.2014  20:32    <DIR>          Canneverbe Limited
03.01.2014  18:14    <DIR>          Summitsoft
21.11.2013  20:40    <DIR>          ICQ
25.10.2013  17:31    <DIR>          LolClient
23.10.2013  12:42    <DIR>          Riot Games
03.12.2012  13:55    <DIR>          MAGIX
26.10.2012  17:25    <DIR>          Creative
16.09.2012  13:07    <DIR>          Skype
16.08.2012  10:13    <DIR>          Logitech
16.08.2012  10:09    <DIR>          Leadertech
16.08.2012  10:06    <DIR>          Logishrd
15.05.2012  16:40    <DIR>          PunkBuster
30.08.2011  16:34    <DIR>          skypePM
21.06.2011  22:43    <DIR>          Miranda
21.12.2010  13:16    <DIR>          Anvil Studio
11.12.2010  15:10    <DIR>          Thunderbird
20.11.2010  17:01    <DIR>          WinRAR
19.11.2010  23:55    <DIR>          Teeworlds
19.11.2010  21:52    <DIR>          Mozilla
19.11.2010  19:57    <DIR>          InstallShield
18.11.2010  10:26    <DIR>          Auslogics
17.11.2010  21:05    <DIR>          Macromedia
17.11.2010  21:05    <DIR>          Adobe
17.11.2010  16:16    <DIR>          Identities
14.07.2009  20:18    <DIR>          Media Center Programs
29.09.2015  21:07    <DIR>          .mono
17.11.2010  21:10    <DIR>          OpenOffice.org
              0 Datei(en),              0 Bytes
              58 Verzeichnis(se), 115.527.012.352 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup" =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\Users\hauptaccount\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

20.04.2016  14:29    <DIR>          ..
20.04.2016  14:29    <DIR>          .
              0 Datei(en),              0 Bytes
              2 Verzeichnis(se), 115.527.012.352 Bytes frei

========= Ende von CMD: =========


=========  dir /oge-d %PROGRAMDATA% =========

 Datentr�ger in Laufwerk C: ist SYSTEM
 Volumeseriennummer: 987A-FFA8

 Verzeichnis von C:\ProgramData

22.04.2016  00:12    <DIR>          Origin
21.04.2016  23:11    <DIR>          ..
21.04.2016  23:11    <DIR>          .
16.04.2016  15:54    <DIR>          Package Cache
15.04.2016  14:50    <DIR>          ProductData
15.04.2016  14:07    <DIR>          Malwarebytes' Anti-Malware (portable)
13.04.2016  14:01    <DIR>          ds
12.04.2016  12:03    <DIR>          4D
06.03.2016  03:18    <DIR>          ICQ
06.03.2016  02:33    <DIR>          Malwarebytes
23.01.2016  13:41    <DIR>          Oracle
12.12.2015  06:37    <DIR>          Microsoft
12.12.2015  06:03    <DIR>          USOPrivate
08.12.2015  08:30    <DIR>          Codemasters
11.11.2015  17:39    <DIR>          VsTelemetry
11.11.2015  17:26    <DIR>          PreEmptive Solutions
11.11.2015  17:24    <DIR>          Microsoft DNX
11.11.2015  17:20    <DIR>          NuGet
05.11.2015  09:30    <DIR>          EA Logs
30.10.2015  09:24    <DIR>          SoftwareDistribution
30.10.2015  09:24    <DIR>          Comms
28.10.2015  20:39    <DIR>          Autodesk
28.10.2015  20:38    <DIR>          FLEXnet
12.10.2015  19:11    <DIR>          Logishrd
11.10.2015  01:08    <DIR>          Electronic Arts
09.09.2015  22:04    <DIR>          BlueStacksSetup
08.09.2015  23:07    <DIR>          BitRaider
06.09.2015  20:18    <DIR>          Wondershare
13.08.2015  05:58    <DIR>          Creative
12.08.2015  16:17    <DIR>          Microsoft OneDrive
05.08.2015  14:59    <DIR>          McAfee Security Scan
05.08.2015  14:59    <DIR>          McAfee
02.08.2015  17:20    <DIR>          Samsung
10.07.2015  14:22    <DIR>          USOShared
24.06.2015  22:41    <DIR>          MAGIX
22.06.2015  18:04    <DIR>          Dropbox
11.03.2015  23:52    <DIR>          WindSolutions
10.02.2015  19:04    <DIR>          XDMessagingv4
09.01.2015  12:21    <DIR>          MobileBrServ
01.01.2015  17:38    <DIR>          HP Photo Creations
01.01.2015  17:38    <DIR>          Visan
01.01.2015  17:36    <DIR>          HP
08.12.2014  19:13    <DIR>          Skype
21.09.2014  18:00    <DIR>          34BE82C4-E596-4e99-A191-52C6199EBF69
24.07.2014  15:36    <DIR>          Ubisoft
08.07.2014  20:32    <DIR>          Canneverbe Limited
15.05.2014  21:26    <DIR>          Apple
20.09.2013  22:18    <DIR>          Mozilla
22.02.2013  18:43    <DIR>          Adobe
13.11.2012  00:12    <DIR>          TEMP
12.11.2012  23:58    <DIR>          InstallMate
27.11.2011  22:15    <DIR>          Norton
27.11.2011  22:14    <DIR>          NortonInstaller
29.01.2011  15:25    <DIR>          EA Core
23.11.2010  17:22    <DIR>          Propellerhead Software
20.11.2010  20:09    <DIR>          {93E26451-CD9A-43A5-A2FA-C42392EA4001}
20.11.2010  20:09    <DIR>          Apple Computer
17.11.2010  20:20    <DIR>          Creative Labs
17.11.2010  16:20    <DIR>          Downloaded Installations
12.12.2015  06:20    <DIR>          regid.1991-06.com.microsoft
29.09.2015  21:07    <DIR>          .mono
28.10.2015  19:11              133 Microsoft.SqlServer.Compact.351.64.bc
01.01.2015  17:36                57 Ament.ini
              2 Datei(en),            190 Bytes
              61 Verzeichnis(se), 115.527.008.256 Bytes frei

========= Ende von CMD: =========


EmptyTemp: => 425.5 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 21:26:46 ====


cosinus 23.04.2016 20:48

Jo, die Ordner sind weg.

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    Advanced SystemCare 9
    Driver Booster 3.2
    OptimizerPro

  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 


Ikarius 23.04.2016 23:52

Bei Advanced Systemcare 9 & Driver Booster kam ne Fehlermeldung:
Zitat:

Uninstall ist fehlgeschlagen. Vermutlich ungültiger deinstall Befehl
Ging aber trotzdem weiter und ist nicht mehr in der Liste.

Den Optimizer wollten wir beim letzten mal auch schon deinstallieren. Ist wie gesagt nicht in der Liste von Programmen dabei. Habe lediglich einen Dual Core Optimizer von AMD.

____



Ist alles deinstalliert.

cosinus 23.04.2016 23:55

Okay, dann Kontrollscans mit (1) MBAM, (2) ESET und (3) SecurityCheck bitte:


1. Schritt: MBAM

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




2. Schritt: ESET

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




3. Schritt: SecurityCheck

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

Ikarius 24.04.2016 01:49

ESET hat bereits ordentlich was gefunden. Läuft wohl noch ne Weile.

Hab aber grad noch ne Frage bevor ich nacher was falsch mache:
Soll ich einfach nach dem Scan auf "Fertig stellen" klicken oder noch ein Häkchen bei "Anwendung nach dem schließen deinstallieren"?.

cosinus 24.04.2016 01:56

Nein nicht deinstallieren. Erst das Log posten!

Ikarius 24.04.2016 14:26

Mbam:
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlaufdatum: 24.04.2016
Suchlaufzeit: 01:12
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2016.04.23.07
Rootkit-Datenbank: v2016.04.17.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: hauptaccount

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 563391
Abgelaufene Zeit: 30 Min., 31 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)

ESET:
Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c4fe09c516a8cd4aa529f58c7823ee4c
# end=init
# utc_time=2016-04-23 11:47:42
# local_time=2016-04-24 01:47:42 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 29211
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c4fe09c516a8cd4aa529f58c7823ee4c
# end=updated
# utc_time=2016-04-23 11:52:48
# local_time=2016-04-24 01:52:48 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c4fe09c516a8cd4aa529f58c7823ee4c
# engine=29211
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-04-24 03:36:49
# local_time=2016-04-24 05:36:49 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 28972 15283152 0 0
# scanned=429833
# found=22
# cleaned=0
# scan_time=13440
sh=D9CB66BC174AA8C14FA392C881FCA6316EE53EA6 ft=1 fh=4c00abfccb0215a7 vn="Win32/SProtector evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\FileQuarantine\C\Program Files (x86)\MocaFlix\sprotector.dll.vir"
sh=9E39D08C19754DB61FB823EB8ADD2BEB11CC98B1 ft=1 fh=98a23b470688132e vn="Variante von Win32/Kryptik.EVEO Trojaner" ac=I fn="C:\FRST\Quarantine\C\ProgramData\chans-19\chans-96.exe"
sh=3DD5664E54546C34B4651DF4F0549D5DBD2A50EA ft=1 fh=f4b9b54d378bf9b2 vn="Win32/TrojanDownloader.Nymaim.BA Trojaner" ac=I fn="C:\FRST\Quarantine\C\ProgramData\doublers-9\doublers-80.exe"
sh=B1F85966B904A103406715D43A5F1657AC2D2A75 ft=1 fh=5d69f54225bcad20 vn="Variante von Win32/Kryptik.EUNZ Trojaner" ac=I fn="C:\FRST\Quarantine\C\ProgramData\inrush-11\inrush-59.exe"
sh=98003172BE836501A926E64A2E56E0246C2277B3 ft=1 fh=9dca8c7d06cfa87a vn="Variante von Win32/Kryptik.EVCW Trojaner" ac=I fn="C:\FRST\Quarantine\C\ProgramData\vacuole-6\vacuole-67.exe"
sh=7625BC21C6AA8711A3A8CBB0A0EBA23F14E095B7 ft=1 fh=6fe3a6699c8ac129 vn="Variante von Win32/Kryptik.EVDP Trojaner" ac=I fn="C:\FRST\Quarantine\C\Users\hauptaccount\AppData\Roaming\algebra-18\algebra-42.exe"
sh=3D09B4A1E2E55E7D1DF62B739D434F3F4E51DB90 ft=1 fh=31688d33c108b3f2 vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe"
sh=740982CE3B3E4BD08C1CBD5FC8CFEB982F1D4E05 ft=1 fh=af8c0585c052e303 vn="Win32/InstalleRex.T evtl. unerwünschte Anwendung" ac=I fn="C:\ProgramData\InstallMate\{B44B67B9-0442-DC77-3E9C-4C606FA8454F}\_Setupx.dll"
sh=740982CE3B3E4BD08C1CBD5FC8CFEB982F1D4E05 ft=1 fh=af8c0585c052e303 vn="Win32/InstalleRex.T evtl. unerwünschte Anwendung" ac=I fn="C:\ProgramData\InstallMate\{B70D1A55-B486-C8D7-2A3C-FCA46CEE38A3}\_Setupx.dll"
sh=740982CE3B3E4BD08C1CBD5FC8CFEB982F1D4E05 ft=1 fh=af8c0585c052e303 vn="Win32/InstalleRex.T evtl. unerwünschte Anwendung" ac=I fn="C:\Users\All Users\InstallMate\{B44B67B9-0442-DC77-3E9C-4C606FA8454F}\_Setupx.dll"
sh=740982CE3B3E4BD08C1CBD5FC8CFEB982F1D4E05 ft=1 fh=af8c0585c052e303 vn="Win32/InstalleRex.T evtl. unerwünschte Anwendung" ac=I fn="C:\Users\All Users\InstallMate\{B70D1A55-B486-C8D7-2A3C-FCA46CEE38A3}\_Setupx.dll"
sh=02EA925F19B987C4FC172CFDF758EC13AFF1213A ft=1 fh=8b1f6af275ead1f7 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\DiskBoss - CHIP-Installer.exe"
sh=907C3464CF610CA0FA8E7D360E701632783727F5 ft=1 fh=c825b1e2ee207fee vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\Driver Booster Free - CHIP-Installer.exe"
sh=247BD367EDEEE742DB499D8088836577A2C94751 ft=1 fh=e38baf9ce82baf22 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe"
sh=FDF0D876BA612B8405BD1F5ADF1B2C637ABA5BA3 ft=1 fh=f9ff4de306b31b4c vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\Notepad - CHIP-Installer.exe"
sh=85F5A836AFB4D8B623AE5CB6D2F0ABBE0EFDD971 ft=1 fh=9cc14e1290294e71 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\PDF24 Creator - CHIP-Installer.exe"
sh=1B4B730E7030F0B07C53A69581F4F23559F77D0B ft=1 fh=ed8a579d85881a0c vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\Similarity - CHIP-Installer.exe"
sh=26B0FC2191AFBF3CADA3F40F73B905E73D9475CC ft=1 fh=7fbda55880fb6355 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\VisiPics - CHIP-Installer.exe"
sh=24E923AEE9CE85831042496A35965326DC8518DD ft=1 fh=faf118d812de2c2c vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe"
sh=B1CCA35E0999EA13CE896B39C2BDC49DABE244EE ft=1 fh=67af611ad71b7699 vn="Variante von Win32/Soft32Downloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\counter strike setup.exe"
sh=0AE9300B0DBC9742E94B6902CFD80D0163A12649 ft=1 fh=e9bf74aaacb00e35 vn="Variante von Win32/Verti.J evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\MediaPlayerClassic_RocketFuelInstaller.exe"
sh=5CBA7EFE3E263B4FAF1B87250AEB371002E5FDB9 ft=1 fh=e9ce6b84d33199cc vn="Variante von Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\SoftonicDownloader_fuer_logo-design-studio.exe"

SecurityCheck:
Code:

Results of screen317's Security Check version 1.009 
  x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
Windows Defender 
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Microsoft VisualStudio JavaScript Project System
 Java 8 Update 71 
 Microsoft VisualStudio JavaScript Language Service
 Java version 32-bit out of Date!
 Adobe Flash Player        21.0.0.213 
 Adobe Reader 9 Adobe Reader out of Date!
 Mozilla Firefox (43.0.1)
 Mozilla Thunderbird (3.1.20) Thunderbird out of Date! 
 Google Chrome (49.0.2623.112)
 Google Chrome (50.0.2661.87)
 Google Chrome (SetupMetrics.pma..)
````````Process Check: objlist.exe by Laurent```````` 
 Windows Defender MSMpEng.exe
 ESET ESET Online Scanner OnlineScannerApp.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````


cosinus 24.04.2016 20:00

Zitat:

C:\Users\hauptaccount\Downloads\DiskBoss - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Driver Booster Free - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Notepad - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\PDF24 Creator - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Similarity - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\VisiPics - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\SoftonicDownloader_fuer_logo-design-studio.exe
Dieser scheiß von chip und softonic wird auch niemals ein Ende finden :balla:

Von chip lädst du in Zukunft besser nix mehr. Die verarschen ihre Kunden aus reiner Profitgier. Siehe auch http://www.trojaner-board.de/168364-...mpfehlung.html und CHIP-Installer - was ist das? - Anleitungen

Und softonic ist schon noch länger als Junkwareschleuder bekannt...


FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Program Files (x86)\PDFCreator\Toolbar\
C:\ProgramData\InstallMate
C:\Users\All Users\InstallMate
C:\Users\hauptaccount\Downloads\DiskBoss - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Driver Booster Free - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Notepad - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\PDF24 Creator - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Similarity - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\VisiPics - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\counter strike setup.exe
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\MediaPlayerClassic_RocketFuelInstaller.exe
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\SoftonicDownloader_fuer_logo-design-studio.exe
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Ikarius 24.04.2016 20:30

Zitat:

Dieser scheiß von chip und softonic wird auch niemals ein Ende finden
Jetzt weiß ich natürlich das Chip böse ist. Aber jemand der sich nicht mit Adware und co. auskennt vertraut dem größten Online-Magazin für Technik in Deutschland nunmal.
Kannst ja ne Aufklärungskampagne außerhalb des Forums starten :p

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016
durchgeführt von hauptaccount (2016-04-24 21:13:54) Run:10
Gestartet von C:\Users\hauptaccount\Desktop
Geladene Profile: hauptaccount & DefaultAppPool (Verfügbare Profile: hauptaccount & Neu & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
C:\Program Files (x86)\PDFCreator\Toolbar\
C:\ProgramData\InstallMate
C:\Users\All Users\InstallMate
C:\Users\hauptaccount\Downloads\DiskBoss - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Driver Booster Free - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Notepad - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\PDF24 Creator - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Similarity - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\VisiPics - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\counter strike setup.exe
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\MediaPlayerClassic_RocketFuelInstaller.exe
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\SoftonicDownloader_fuer_logo-design-studio.exe
emptytemp:
*****************

C:\Program Files (x86)\PDFCreator\Toolbar => erfolgreich verschoben
C:\ProgramData\InstallMate => erfolgreich verschoben
C:\Users\All Users\InstallMate => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\DiskBoss - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\Driver Booster Free - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\MySQL - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\Notepad - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\PDF24 Creator - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\Similarity - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\VisiPics - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\VLC media player 64 Bit - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\counter strike setup.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\MediaPlayerClassic_RocketFuelInstaller.exe => erfolgreich verschoben
C:\Users\hauptaccount\Downloads\Temporärer Ordner ka\SoftonicDownloader_fuer_logo-design-studio.exe => erfolgreich verschoben
EmptyTemp: => 396.1 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 21:14:16 ====


cosinus 24.04.2016 20:55

Zitat:

Adobe Reader 9 Adobe Reader out of Date!
Adobe Flash Player 21.0.0.213
Java 8 Update 71
Google Chrome (49.0.2623.112)
Mozilla Firefox (43.0.1)
Mozilla Thunderbird (3.1.20) Thunderbird out of Date!

Also hier musst du auch dringend was tun.

Adobe Reader deinstallieren. Verwende PDF-X-Change Viewer als bessere Alternative, oftmals reicht aber auch der interne PDF-Betrachter, der im Firefox integriert ist, völlig aus!

Ich würde auch unbedingt Java und wenn es geht den Flash Player weghauen! :kloppen:

Java spielt kaum noch eine Rolle. Fast nirgendwo werden mehr Java-Applets eingesetzt. Und was Adobe mit seinem Flash Player veranstaltet, ist irgendwo zwischen Frechheit und Inkompetenz einzustufen. In dem Teil werden ständig neue dicke Sicherheitslücken gefunden => Der Liebling aller Cyber-Kriminellen: Flash | heise Security


Wieso ist Google Chrome 49 installiert? Bitte prüfen.

Und wenn du schon Chrome UND Firefox drauf hast, dann auch regelmäßig Updates einspielen. Firefox 43 muss auch schon mehrere Wochen überfällig sein.

Mozilla Thunderbird in Version 3.1.20??? :eek: :balla: Umgehend deinstallieren.

Ikarius 24.04.2016 21:30

Versuche es mal ohne Java und Flash.

Hab jetzt nur noch Chrome und Thunderbird in der neusten Version drauf.
Schmeiße jetzt mal alles runter was ich nicht brauche/benutze.

cosinus 24.04.2016 21:32

Dann wären wir durch! :daumenhoc

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...:dankeschoen:und/oder das Forum mit einer kleinen Spende http://www.trojaner-board.de/extra/spende.png unterstützen. :applaus:

Abschließend müssen wir noch ein paar Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern.

http://deeprybka.trojaner-board.de/b...cleanupneu.png
Cleanup:
(Die Reihenfolge ist hier entscheidend)

Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken.

Falls Combofix verwendet wurde:
http://deeprybka.trojaner-board.de/b.../combofix2.pngCombofix deinstallieren
  • Wichtig: Bitte Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke bitte die http://deeprybka.trojaner-board.de/b...ne/revo/w7.png + R Taste und schreibe Combofix /Uninstall in das Ausführen-Fenster.
  • Klicke auf OK.
    Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert.
  • Nun die eben deaktivierten Programme wieder aktivieren.

Alle Logs gepostet? Dann lade Dir bitte http://filepony.de/icon/tiny/delfix.pngDelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.

Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.

http://deeprybka.trojaner-board.de/b...ast/schild.png
Absicherung:
Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen:

Browser
Java
Flash-Player
PDF-Reader

Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.
Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.

Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.

Verwende ein einziges der folgenden Antivirusprogramme mit Echtzeitscanner und stets aktueller Signaturendatenbank:

   
 

Microsoft Security Essentials (MSE) ist ab Windows 8 fest eingebaut, wenn du also Windows 8, 8.1 oder 10 und dich für MSE entschieden hast, brauchst du nicht extra MSE zu installieren. Bei Windows 7 muss es aber manuell installiert oder über die Windows Updates als optionales Update bezogen werden. Selbstverständlich ist ein legales/aktiviertes Windows Voraussetzung dafür.

Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und/oder mit dem ESET Online Scanner scannen.

Optional:

http://filepony.de/icon/noscript.png NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. NoScript kann gerade bei technisch nicht allzu versierten Nutzern beim Surfen zum Nervfaktor werden; ob das Tool geeignet ist, muss jeder selbst mal ausprobieren und dann für sich entscheiden. Alternativen zu NoScript (wenn um das das Verhindern von Usertracking und Werbung auf Webseiten) geht wären da Ghostery oder uBlock. Ghostery ist eine sehr bekannte Erweiterung, die aber auch in Kritik geraten ist, vgl. dazu bitte diesen Thread => Ghostery schleift Werbung durch

http://filepony.de/icon/malwarebytes_anti_exploit.pngMalwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.


Lade Software von einem sauberen Portal wie http://filepony.de/images/microbanner.gif.
Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwcleaner .


Abschließend noch ein paar grundsätzliche Bemerkungen:
Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

Ikarius 24.04.2016 21:57

Alles klar sind durch mein Guter :bussi:


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131