buchinet | 18.11.2014 13:16 | FRST (SERVER102) - hier ist die logonui auch mit einer leeren datei ersetzt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-11-2014
Ran by Administrator (administrator) on KORTS001LKO on 18-11-2014 12:36:09
Running from C:\Users\Administrator\Desktop
Loaded Profiles: kloiberc & pfuntnerv & kraftj & preinreicht & schmutzc & idingera & wiedermannj & buscht & freymuellerm & zwiebm & mantlerl & schmutzs & poikc & fahrbacha & ledererb & osmanovica & penischa & schwarzotta & kandlerh & lutzj & fellnerr & schoenweilerd & ullreiche & lahnerj & lehnerh & wkoze1 & wkoze2 & webze1 & wwoze1 & Risdata & kraftjo & wkoze3 & wkoze4 & buchgraberp & stinglt & brandstetterh & holzmanne & blehap & riedln & laptopnx63251 & radlf & breitse & waschulinf & trth2 & derossie & bartalr & sallmaiera & labp & trzeit & trebv & mdtaskcont & binderm & frankd & meisslc & Administrator (Available profiles: ehrentrautw & kloiberc & pfuntnerv & sommera & kraftj & maisserm & preinreicht & goestld & schmutzc & idingera & klausl & wiedermannj & buscht & freymuellerm & zwiebm & mantlerl & schmutzs & poikc & fahrbacha & ledererb & goestlm & osmanovica & penischa & schwarzotta & kandlerh & lutzj & fellnerr & wernardp & pernoldh & schoenweilerd & ullreiche & lahnerj & lehnerh & wkoze1 & wkoze2 & webze1 & wwoze1 & motiondata & Risdata & webze2 & kraftjo & beerhj & wkoze3 & antls & motiondata2 & schmoellerla & wkoze4 & buchgraberp & theilm & stinglt & wittmannh & wwoetl1 & brandstetterh & holzmanne & wwoetl2 & wwoetl3 & blehap & riedln & wktablet & musels & motiondata1 & motiondata3 & motiondata4 & laptopnx63251 & lenovoEB & ebwkjd & lunzerc & koro & MOTIONDATA5 & radlf & breitse & hasukic & strell & waschulinf & trth2 & trth1 & derossie & bartalr & sallmaiera & labp & trzeit & trebv & mayerm & Test & mdtaskcont & binderm & frankd & meisslc & ellinger & Test3 & test4 & Administrator & Classic .NET AppPool)
Platform: Windows Server 2008 R2 Enterprise Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(Symantec Corporation) C:\Program Files\Symantec\Backup Exec\RAWS\bedbg.exe
(HP) C:\Windows\AppCompat\hpagent.exe
(KSR EDV Ing. Buero GmbH) D:\Eurotax\Licence Server\KSR Licence Server Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7Debug\mdm.exe
(Motiondata Software GmbH) C:\Program Files (x86)\MOTIONDATA Software GmbH\MD_OpelGarantieSetup\OpelGarantie.exe
() C:\Program Files (x86)\MOTIONDATA\MD Task Controller\MD_Task_Controller_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
(Symantec Corporation) C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
() C:\Program Files (x86)\Mesensky\EBV 4.0\Client\client.startup.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_11_4_402_265_ActiveX.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
(Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD Configurator\Service\MOTIONDATA Configurator Service.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
() C:\PTW525\pt525.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
() C:\Program Files (x86)\Mesensky\EBV 4.0\Server\server.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
() C:\Program Files (x86)\Mesensky\EBV 4.0\Client\client.startup.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\ssonsvr.exe
(Microsoft Corporation) C:\Windows\System32\rdpclip.exe
(VMware, Inc.) C:\Program Files\VMware\VMware Tools\VMwareTray.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\concentr.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Citrix Systems, Inc.) C:\Program Files\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\Plugins\MD_RLH_Rohgewinnjournal\MD_RLH_Rohgewinnjournal.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\EXCEL.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(MOTIONDATA Software GmbH) C:\Program Files (x86)\MOTIONDATA\MD_PGM\MData.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\EXCEL.EXE
(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [VMware Tools] => C:\Program Files\VMware\VMware Tools\VMwareTray.exe [60016 2011-06-07] (VMware, Inc.)
HKLM\...\Run: [VMware User Process] => C:\Program Files\VMware\VMware Tools\vmtoolsd.exe [65648 2011-06-07] (VMware, Inc.)
HKLM\...\Run: [Seagull Drivers] => ssdal_nc.exe startup
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1617704 2014-10-14] (Sophos Limited)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Programme\Citrix\ICA Client\concentr.exe [309184 2012-03-28] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM\...\Policies\Explorer: [ShowSuperHidden] 1
HKU\S-1-5-21-3877106004-1846325829-2574108814-1123\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe [690888 2012-09-05] (Adobe Systems Incorporated)
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [217160 2014-05-20] (Sophos Limited)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll [275352 2014-05-20] (Sophos Limited)
Lsa: [Notification Packages] scecli rassfm
Startup: C:\Users\wkoze1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AufGenExec.lnk
ShortcutTarget: AufGenExec.lnk -> C:\Program Files (x86)\MOTIONDATA\GH-Import\AufGenExec.exe (No File)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1003] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1003] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1004] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1004] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1006] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1006] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1008] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1010] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1010] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1011] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1011] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1013] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1013] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1014] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1014] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1017] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1017] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1018] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1019] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1020] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1020] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1021] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1021] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1022] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1024] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1024] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1025] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1025] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1026] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1026] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1027] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1027] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1028] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1028] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1029] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1029] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1033] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1034] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1034] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1035] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1036] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1036] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1037] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1038] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1038] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1039] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1039] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1040] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1040] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1044] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1044] => proxy.intranet.ri-solution.com:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1046] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1046] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1058] => 10.246.140.120:8080
ProxyEnable: [S-1-5-21-3877106004-1846325829-2574108814-1108] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-1108] => proxy.intranet.ri-solution.com:8080
ProxyServer: [S-1-5-21-3877106004-1846325829-2574108814-500] => proxy.intranet.ri-solution.com:8080
HKU\S-1-5-21-3877106004-1846325829-2574108814-1003\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKU\S-1-5-21-3877106004-1846325829-2574108814-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x43C4A5EB5CB0CE01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKU\S-1-5-21-3877106004-1846325829-2574108814-1006\Software\Microsoft\Internet Explorer\Main,Start Page = https://servicebox.peugeot.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1010\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3877106004-1846325829-2574108814-1011\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1011\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2065ED52A032CD01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1011\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1013\Software\Microsoft\Internet Explorer\Main,Start Page = https://servicebox.peugeot.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1014\Software\Microsoft\Internet Explorer\Main,Start Page = https://servicebox.peugeot.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1017\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3877106004-1846325829-2574108814-1018\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKU\S-1-5-21-3877106004-1846325829-2574108814-1019\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKU\S-1-5-21-3877106004-1846325829-2574108814-1020\Software\Microsoft\Internet Explorer\Main,Start Page = https://servicebox.peugeot.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1021\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3877106004-1846325829-2574108814-1022\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1022\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC59413BF3DCACE01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1022\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1024\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1024\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x40B33749C4FCCF01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1024\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1026\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1026\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEADAF7315803CD01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1026\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1026\Software\Microsoft\Internet Explorer\Main,Start Page = https://connect.peugeot.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1027\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKU\S-1-5-21-3877106004-1846325829-2574108814-1027\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1027\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD4E4E164FD1CCF01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1027\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1036\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3877106004-1846325829-2574108814-1039\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1039\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3D000C35ECB0CD01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1039\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1044\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3877106004-1846325829-2574108814-1044\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1044\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x175EAC96B986CE01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1044\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1046\Software\Microsoft\Internet Explorer\Main,Start Page = https://servicebox.peugeot.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1058\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKU\S-1-5-21-3877106004-1846325829-2574108814-1058\Software\Microsoft\Internet Explorer\Main,Start Page = res://iesetup.dll/SoftAdmin.htm
HKU\S-1-5-21-3877106004-1846325829-2574108814-1063\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1063\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKU\S-1-5-21-3877106004-1846325829-2574108814-1063\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1063\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x092496912A26CF01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1068\Software\Microsoft\Internet Explorer\Main,Start Page = https://servicebox.peugeot.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1069\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1098\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1101\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1102\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1102\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1102\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x08CFFE719A75CF01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1102\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1103\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1106\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1108\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.at.msn.com/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1108\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4C443AF763A6CF01
HKU\S-1-5-21-3877106004-1846325829-2574108814-1108\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
HKU\S-1-5-21-3877106004-1846325829-2574108814-1115\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1121\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1122\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-1123\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
HKU\S-1-5-21-3877106004-1846325829-2574108814-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\S-1-5-21-3877106004-1846325829-2574108814-1019 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3877106004-1846325829-2574108814-1024 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3877106004-1846325829-2574108814-1028 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3877106004-1846325829-2574108814-1034 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3877106004-1846325829-2574108814-1035 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3877106004-1846325829-2574108814-1038 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3877106004-1846325829-2574108814-1040 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3877106004-1846325829-2574108814-1065 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: CGMFragment Class -> {0695F52A-89A2-4246-81B5-AFAD2D3B865F} -> C:\Program Files (x86)\Ematek\MetaWeb\MetaBHO.dll ()
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: WebCGMHlprObj Class -> {56B38F40-4E70-11d4-A076-0080AD86BA2F} -> C:\Windows\SysWOW64\cgmopenbho.dll (CGM Open Consortium, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {41795ECB-411A-4F38-A1ED-0F34E8892BF7} https://central.gmbpi.com/P3WebClient/P3Loader.cab
DPF: HKLM-x32 {5554DCB0-700B-498D-9B58-4E40E5814405} hxxp://korsq001lko/Reports_Korneuburg/Reserved.ReportViewerWebControl.axd?ReportSession=nb0g3xbjjwb5k0frbk4yjkiq&Culture=3079&CultureOverrides=False&UICulture=7&UICultureOverrides=False&ReportStack=1&ControlID=e004a3312fcf4d9a9f499eda253b715a&OpType=PrintCab&Arch=X86
DPF: HKLM-x32 {947EFED6-BCFD-4FBC-8B89-6B7251D7DA6E} https://central.gmbpi.com/MetisWebClient/WebClientLoader.cab
Handler-x32: http - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Programme\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Hosts: 23.209.155.144 tis2web.service.gm.com
Tcpip\..\Interfaces\{F4D37EF6-B129-4586-83FA-B668CF7CB49C}: [NameServer] 10.250.0.90,10.1.5.142
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3877106004-1846325829-2574108814-1022: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ledererb\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 BackupExecAgentAccelerator; C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe [1994096 2012-01-23] (Symantec Corporation)
S3 BackupExecVSSProvider; C:\Program Files\Symantec\Backup Exec\RAWS\VSS Provider\bevssprovider.exe [148336 2012-01-20] (Symantec Corporation)
R2 bedbg; C:\Program Files\Symantec\Backup Exec\RAWS\bedbg.exe [353648 2012-01-12] (Symantec Corporation)
S4 BrUnvPrnPortPCL; C:\Windows\system32\\BRUNVPRNPC64.EXE [60928 2012-10-31] () [File not signed]
R2 CqLMgServs; C:\Windows\AppCompat\hpagent.exe [4764160 2014-06-19] (HP) [File not signed]
R2 EBVServer; C:\Program Files (x86)\Mesensky\EBV 4.0\Server\server.exe [28672 2014-06-26] () [File not signed]
S3 FCRegSvc; C:\Windows\system32\FCRegSvc.dll [25600 2009-07-14] (Microsoft Corporation)
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-21] (Microsoft Corporation)
R2 KSR_Licence-Server; D:\Eurotax\Licence Server\KSR Licence Server Service.exe [442368 2010-06-16] (KSR EDV Ing. Buero GmbH) [File not signed]
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe [270336 2001-02-23] (Microsoft Corporation) [File not signed]
R2 MOTIONDATA Configurator Service; C:\Program Files (x86)\MOTIONDATA\MD Configurator\Service\MOTIONDATA Configurator Service.exe [12800 2014-05-12] (MOTIONDATA Software GmbH) [File not signed]
R2 Motiondata Opel Garantieservice; C:\Program Files (x86)\MOTIONDATA Software GmbH\MD_OpelGarantieSetup\OpelGarantie.exe [9728 2014-04-14] (Motiondata Software GmbH) [File not signed]
R2 MOTIONDATA Task Controller; C:\Program Files (x86)\MOTIONDATA\MD Task Controller\MD_Task_Controller_Service.exe [116000 2014-07-03] ()
R2 MsDtsServer100; C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [210784 2011-04-23] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2012-07-31] (Hewlett-Packard) [File not signed]
S3 PDVFSService; C:\Program Files\Symantec\Backup Exec\RAWS\PDVFSService.exe [301720 2012-03-30] ()
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2012-07-31] (Hewlett-Packard) [File not signed]
S3 RSoPProv; C:\Windows\system32\RSoPProv.exe [91648 2009-07-14] (Microsoft Corporation)
S3 sacsvr; C:\Windows\system32\sacsvr.dll [14848 2009-07-14] (Microsoft Corporation)
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [288552 2014-05-20] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [208168 2014-10-14] (Sophos Limited)
R2 Sophos Agent; C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe [289856 2012-09-17] (Sophos Limited)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [341800 2014-10-14] (Sophos Limited)
R2 Sophos Message Router; C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe [818240 2012-09-17] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [341800 2014-10-14] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3262248 2014-10-14] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2065704 2014-10-14] (Sophos Limited)
R2 TermServLicensing; C:\Windows\System32\lserver.dll [694784 2010-11-21] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
S3 WMSVC; C:\Windows\system32\inetsrv\wmsvc.exe [10752 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 ioatdma; C:\Windows\System32\Drivers\qd260x64.sys [35328 2009-06-10] (Intel Corporation)
R1 PDVFSDriver; C:\Windows\System32\drivers\pdfsd.sys [79480 2012-03-30] (Symantec Corporation)
S4 PDVFSNP; No ImagePath
S0 sacdrv; C:\Windows\System32\DRIVERS\sacdrv.sys [96320 2009-07-14] (Microsoft Corporation)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [158976 2014-05-20] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2014-05-20] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2014-05-20] (Sophos Limited)
R3 VirtFile; C:\Windows\System32\DRIVERS\VirtFile.sys [114296 2011-10-25] (Symantec Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
NETSVC: sacsvr -> C:\Windows\system32\sacsvr.dll (Microsoft Corporation)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-18 12:36 - 2014-11-18 12:36 - 00072503 _____ () C:\Users\Administrator\Desktop\FRST.txt
2014-11-18 12:36 - 2014-11-18 12:36 - 00000000 ____D () C:\FRST
2014-11-18 12:35 - 2014-11-18 12:28 - 02117120 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe
2014-11-18 10:13 - 2014-11-18 10:59 - 00000000 ____D () C:\Users\fahrbacha\AppData\Local\Temp\55
2014-11-18 09:29 - 2014-11-18 09:33 - 00060661 _____ () C:\Users\frankd\Desktop\Depot_20141118_092352.xlsx
2014-11-18 09:14 - 2014-11-18 09:14 - 00000000 ____D () C:\Users\penischa\AppData\Local\Temp\54
2014-11-18 09:07 - 2014-11-18 09:18 - 00000000 ____D () C:\Users\stinglt\AppData\Local\Temp\53
2014-11-18 08:57 - 2014-11-18 12:01 - 00000000 ____D () C:\Users\freymuellerm\AppData\Local\Temp\52
2014-11-18 08:41 - 2014-11-18 08:41 - 00018084 _____ () C:\Users\Administrator\AppData\Local\Temp\dd_wcf_CA_smci_20141118_074136_458.txt
2014-11-18 08:41 - 2014-11-18 08:41 - 00010408 _____ () C:\Users\Administrator\AppData\Local\Temp\RGI197D.tmp
2014-11-18 08:41 - 2014-11-18 08:41 - 00008938 _____ () C:\Users\Administrator\AppData\Local\Temp\RGI197D.tmp-tmp
2014-11-18 08:41 - 2014-11-18 08:41 - 00007732 _____ () C:\Users\Administrator\AppData\Local\Temp\ASPNETSetup_00010.log
2014-11-18 08:41 - 2014-11-18 08:41 - 00006120 _____ () C:\Users\Administrator\AppData\Local\Temp\ASPNETSetup_00011.log
2014-11-18 08:41 - 2014-11-18 08:41 - 00002734 _____ () C:\Users\Administrator\AppData\Local\Temp\dd_wcf_CA_smci_20141118_074138_658.txt
2014-11-18 08:29 - 2014-11-18 10:03 - 00000000 ____D () C:\Users\preinreicht\AppData\Local\Temp\51
2014-11-18 08:28 - 2014-11-18 08:28 - 00010408 _____ () C:\Users\Administrator\AppData\Local\Temp\RGI55B1.tmp
2014-11-18 08:28 - 2014-11-18 08:28 - 00008938 _____ () C:\Users\Administrator\AppData\Local\Temp\RGI55B1.tmp-tmp
2014-11-18 08:28 - 2014-11-18 08:28 - 00007732 _____ () C:\Users\Administrator\AppData\Local\Temp\ASPNETSetup_00008.log
2014-11-18 08:28 - 2014-11-18 08:28 - 00006120 _____ () C:\Users\Administrator\AppData\Local\Temp\ASPNETSetup_00009.log
2014-11-18 08:25 - 2014-11-18 08:25 - 00018084 _____ () C:\Users\Administrator\AppData\Local\Temp\dd_wcf_CA_smci_20141118_072500_867.txt
2014-11-18 08:25 - 2014-11-18 08:25 - 00010408 _____ () C:\Users\Administrator\AppData\Local\Temp\RGIEDDB.tmp
2014-11-18 08:25 - 2014-11-18 08:25 - 00008938 _____ () C:\Users\Administrator\AppData\Local\Temp\RGIEDDB.tmp-tmp
2014-11-18 08:25 - 2014-11-18 08:25 - 00007732 _____ () C:\Users\Administrator\AppData\Local\Temp\ASPNETSetup_00006.log
2014-11-18 08:25 - 2014-11-18 08:25 - 00006120 _____ () C:\Users\Administrator\AppData\Local\Temp\ASPNETSetup_00007.log
2014-11-18 08:25 - 2014-11-18 08:25 - 00002734 _____ () C:\Users\Administrator\AppData\Local\Temp\dd_wcf_CA_smci_20141118_072503_113.txt
2014-11-18 08:21 - 2014-11-18 08:40 - 00000000 ____D () C:\Users\schwarzotta\AppData\Local\Temp\50
2014-11-18 08:14 - 2014-11-18 12:34 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\32
2014-11-18 08:10 - 2014-11-18 12:35 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\41
2014-11-18 08:02 - 2014-11-18 08:02 - 00000000 ____D () C:\Users\breitse\AppData\Roaming\VMware
2014-11-18 08:01 - 2014-11-18 12:35 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\49
2014-11-18 08:01 - 2014-11-18 08:01 - 00000000 ____D () C:\Users\breitse\AppData\Local\Temp\48
2014-11-18 07:59 - 2014-11-18 07:59 - 00000000 ____D () C:\Users\kandlerh\AppData\Local\Temp\47
2014-11-18 07:58 - 2014-11-18 07:58 - 00000000 ____D () C:\Users\osmanovica\AppData\Local\Temp\46
2014-11-18 07:54 - 2014-11-18 08:27 - 00000000 ____D () C:\Users\ullreiche\AppData\Local\Temp\45
2014-11-18 07:42 - 2014-11-18 11:00 - 00000000 ____D () C:\Users\lehnerh\AppData\Local\Temp\44
2014-11-18 07:29 - 2014-11-18 12:13 - 00000000 ____D () C:\Users\trebv\AppData\Local\Temp\39
2014-11-18 07:25 - 2014-11-18 07:26 - 00000000 ____D () C:\Users\trth2\AppData\Local\Temp\40
2014-11-18 07:06 - 2014-11-18 07:06 - 00000000 ____D () C:\Users\kloiberc\AppData\Local\Temp\LCFEM
2014-11-18 07:05 - 2014-11-18 07:05 - 00000000 ____D () C:\Users\kloiberc\AppData\Local\Temp\37
2014-11-18 07:03 - 2014-11-18 08:14 - 00000000 ____D () C:\Users\kraftj\AppData\Local\Temp\34
2014-11-18 07:03 - 2014-11-18 07:03 - 00000000 ____D () C:\Users\wkoze4\AppData\Local\Temp\36
2014-11-18 07:03 - 2014-11-18 07:03 - 00000000 ____D () C:\Users\wkoze3\AppData\Local\Temp\35
2014-11-18 07:02 - 2014-11-18 09:04 - 00000000 ____D () C:\Users\buchgraberp\AppData\Local\Temp\33
2014-11-18 07:01 - 2014-11-18 11:41 - 00000000 ____D () C:\Users\schmutzc\AppData\Local\Temp\31
2014-11-18 07:00 - 2014-11-18 12:36 - 00000000 ____D () C:\Users\pfuntnerv\AppData\Local\Temp\27
2014-11-18 07:00 - 2014-11-18 12:35 - 00000000 ____D () C:\Users\schoenweilerd\AppData\Local\Temp\28
2014-11-18 07:00 - 2014-11-18 10:53 - 00000000 ____D () C:\Users\idingera\AppData\Local\Temp\30
2014-11-18 07:00 - 2014-11-18 10:25 - 00000000 ____D () C:\Users\buscht\AppData\Local\Temp\29
2014-11-18 07:00 - 2014-11-18 07:00 - 00000000 ____D () C:\Users\laptopnx63251\AppData\Roaming\VMware
2014-11-18 06:59 - 2014-11-18 12:23 - 00000000 ____D () C:\Users\trzeit\AppData\Local\Temp\25
2014-11-18 06:59 - 2014-11-18 10:24 - 00000000 ____D () C:\Users\laptopnx63251\AppData\Local\Temp\26
2014-11-18 06:58 - 2014-11-18 11:49 - 00000000 ____D () C:\Users\waschulinf\AppData\Local\Temp\24
2014-11-18 06:58 - 2014-11-18 10:48 - 00000000 ____D () C:\Users\schmutzs\AppData\Local\Temp\23
2014-11-18 06:57 - 2014-11-18 06:57 - 00000000 ____D () C:\Users\kraftjo\AppData\Local\Temp\22
2014-11-18 06:56 - 2014-11-18 11:59 - 00000000 ____D () C:\Users\poikc\AppData\Local\Temp\21
2014-11-18 06:56 - 2014-11-18 11:08 - 00000000 ____D () C:\Users\wiedermannj\AppData\Local\Temp\20
2014-11-18 06:55 - 2014-11-18 11:49 - 00000000 ____D () C:\Users\derossie\AppData\Local\Temp\16
2014-11-18 06:55 - 2014-11-18 11:04 - 00000000 ____D () C:\Users\riedln\AppData\Local\Temp\19
2014-11-18 06:55 - 2014-11-18 10:36 - 00000000 ____D () C:\Users\fellnerr\AppData\Local\Temp\18
2014-11-18 06:55 - 2014-11-18 07:08 - 00000000 ____D () C:\Users\lutzj\AppData\Local\Temp\17
2014-11-18 06:54 - 2014-11-18 06:54 - 00000000 ____D () C:\Users\wwoze1\AppData\Local\Temp\15
2014-11-18 06:53 - 2014-11-18 12:04 - 00000000 ____D () C:\Users\Risdata\AppData\Local\Temp\13
2014-11-18 06:53 - 2014-11-18 11:11 - 00000000 ____D () C:\Users\ledererb\AppData\Local\Temp\14
2014-11-18 06:52 - 2014-11-18 12:35 - 00000000 ____D () C:\Users\blehap\AppData\Local\Temp\12
2014-11-18 06:51 - 2014-11-18 11:59 - 00000000 ____D () C:\Users\zwiebm\AppData\Local\Temp\11
2014-11-18 06:51 - 2014-11-18 06:51 - 00000000 ____D () C:\Users\wkoze2\AppData\Local\Temp\9
2014-11-18 06:51 - 2014-11-18 06:51 - 00000000 ____D () C:\Users\wkoze1\AppData\Local\Temp\10
2014-11-18 06:50 - 2014-11-18 11:03 - 00000000 ____D () C:\Users\radlf\AppData\Local\Temp\8
2014-11-18 06:48 - 2014-11-18 12:36 - 00000000 ____D () C:\Users\mantlerl\AppData\Local\Temp\6
2014-11-18 06:48 - 2014-11-18 11:44 - 00000000 ____D () C:\Users\brandstetterh.KORTS001LKO\AppData\Local\Temp\7
2014-11-18 06:48 - 2014-11-18 06:48 - 00000000 ____D () C:\Users\webze1\AppData\Local\Temp\4
2014-11-18 06:47 - 2014-11-18 12:34 - 00000000 ____D () C:\Users\frankd\AppData\Local\Temp\5
2014-11-18 06:46 - 2014-11-18 11:56 - 00000000 ____D () C:\Users\lahnerj\AppData\Local\Temp\2
2014-11-18 06:45 - 2014-11-18 11:29 - 00000000 ____D () C:\Users\holzmanne.KORTS001LKO\AppData\Local\Temp\3
2014-11-18 05:36 - 2014-11-18 12:36 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Temp\1
2014-11-17 19:52 - 2014-11-17 19:52 - 00020128 _____ () C:\Users\strell\AppData\Local\Temp\tmpB0FA.tmp
2014-11-17 19:52 - 2014-11-17 19:52 - 00000000 _____ () C:\Users\strell\AppData\Local\Temp\tmpB0F9.xml
2014-11-17 19:52 - 2014-11-17 19:52 - 00000000 _____ () C:\Users\strell\AppData\Local\Temp\tmpB0F9.tmp
2014-11-17 19:50 - 2014-11-17 19:50 - 00000000 _____ () C:\Users\strell\AppData\Local\Temp\tmp6F65.tmp
2014-11-17 19:33 - 2014-11-17 19:54 - 306091379 _____ () C:\Users\strell\Documents\Bootlog-2.pml
2014-11-17 19:33 - 2014-11-17 19:54 - 250265360 _____ () C:\Users\strell\Documents\Bootlog-3.pml
2014-11-17 19:33 - 2014-11-17 19:54 - 167050718 _____ () C:\Users\strell\Documents\Bootlog-4.pml
2014-11-17 19:32 - 2014-11-17 19:54 - 298103170 _____ () C:\Users\strell\Documents\Bootlog.pml
2014-11-17 19:32 - 2014-11-17 19:54 - 286812777 _____ () C:\Users\strell\Documents\Bootlog-1.pml
2014-11-17 18:12 - 2014-11-17 18:12 - 00000000 ____D () C:\Users\Administrator\Downloads\Autoruns
2014-11-17 18:11 - 2014-11-17 18:11 - 00511633 _____ () C:\Users\Administrator\Downloads\Autoruns.zip
2014-11-17 11:56 - 2014-11-18 07:26 - 00005154 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-kloiberc KORTS001LKO
2014-11-17 11:53 - 2014-11-17 11:53 - 00000000 ____D () C:\Users\kloiberc\Documents\Benutzerdefinierte Office-Vorlagen
2014-11-17 10:26 - 2014-11-17 10:26 - 00002400 _____ () C:\Users\motiondata\Desktop\MD_RLH_Rohgewinnjournal - Verknüpfung.lnk
2014-11-17 09:32 - 2014-11-17 09:33 - 00000000 ____D () C:\Users\motiondata\Documents\Visual Studio 2008
2014-11-17 09:27 - 2014-11-17 09:27 - 00001409 _____ () C:\Users\motiondata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-11-17 09:27 - 2014-11-17 09:27 - 00000502 __RSH () C:\Users\motiondata\ntuser.pol
2014-11-17 09:27 - 2014-11-17 09:27 - 00000000 ____D () C:\Users\motiondata\AppData\Roaming\ICAClient
2014-11-17 08:01 - 2014-11-17 13:01 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\53
2014-11-17 07:28 - 2014-11-18 12:36 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\42
2014-11-17 07:25 - 2014-11-17 17:22 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\40
2014-11-14 08:05 - 2014-11-14 13:00 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\45
2014-11-14 08:05 - 2014-11-14 08:06 - 00000000 ____D () C:\Users\motiondata3\Documents\Visual Studio 2008
2014-11-14 07:35 - 2014-11-17 17:20 - 00000000 ____D () C:\Users\trebv\AppData\Local\Temp\41
2014-11-14 07:32 - 2014-11-14 07:30 - 70087104 _____ (Microsoft Corporation) C:\NDP451-KB2858728-x86-x64-AllOS-ENU.exe
2014-11-14 07:30 - 2014-11-14 15:07 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\40
2014-11-14 07:26 - 2014-11-14 07:26 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\VMware
2014-11-14 06:53 - 2014-11-17 16:15 - 00000000 ____D () C:\Users\trzeit\AppData\Local\Temp\15
2014-11-13 17:00 - 2014-11-13 17:00 - 00000000 ____D () C:\Users\buchgraberp\AppData\Local\Temp\LCFEM
2014-11-13 16:58 - 2014-11-13 16:58 - 00000000 ____D () C:\Users\Risdata\AppData\Local\Temp\LCFEM
2014-11-13 16:13 - 2014-11-13 16:14 - 00006168 _____ () C:\Users\Administrator\Desktop\Neues Textdokument.txt
2014-11-13 16:12 - 2014-11-13 16:12 - 00000502 __RSH () C:\Users\motiondata3\ntuser.pol
2014-11-13 13:57 - 2014-11-13 13:57 - 00060300 _____ () C:\Users\labp\Desktop\Kopie von 1415800106179.xlsx
2014-11-13 12:01 - 2014-11-17 21:12 - 00000000 _____ () C:\Windows\SysWOW64\WscomMutex.Mutex
2014-11-13 12:00 - 2014-11-13 12:00 - 00000000 ____D () C:\Windows\SysWOW64\lsptem
2014-11-13 07:25 - 2014-11-13 14:04 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\144
2014-11-13 07:17 - 2014-11-13 16:14 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\139
2014-11-13 06:57 - 2014-11-13 16:04 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\90
2014-11-12 14:41 - 2014-11-12 14:41 - 00044319 _____ () C:\Users\schwarzotta\Documents\FAHRZEUG02.xlsx
2014-11-12 14:07 - 2014-11-12 16:07 - 00070096 _____ () C:\Users\schwarzotta\Documents\FAHRZEUG0 RICHTIGE LISTE.xlsx
2014-11-12 14:07 - 2014-11-12 14:07 - 00000000 ____D () C:\Users\schwarzotta\Documents\Benutzerdefinierte Office-Vorlagen
2014-11-12 13:07 - 2014-11-18 07:23 - 00005166 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-buchgraberp KORTS001LKO
2014-11-12 11:50 - 2014-11-12 16:18 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\131
2014-11-12 07:29 - 2014-11-12 13:56 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\136
2014-11-12 06:57 - 2014-11-12 16:01 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\67
2014-11-11 16:51 - 2014-11-18 07:14 - 00005150 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-Risdata KORTS001LKO
2014-11-11 08:53 - 2014-11-11 13:48 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\143
2014-11-11 07:47 - 2014-11-11 13:02 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\138
2014-11-11 07:11 - 2014-11-11 07:11 - 00000000 ____D () C:\Users\Test3\AppData\Local\Temp\LCFEM
2014-11-11 07:08 - 2014-11-11 18:11 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\129
2014-11-11 06:54 - 2014-11-11 16:12 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\29
2014-11-10 10:45 - 2014-11-10 10:45 - 00022528 _____ () C:\Users\bartalr\Documents\AW Vorgangs-Nr.23133516 Besichtigung.msg
2014-11-10 07:45 - 2014-11-10 13:55 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\134
2014-11-10 07:16 - 2014-11-10 16:11 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\128
2014-11-08 13:28 - 2014-11-08 13:28 - 00000000 ____D () C:\Users\Test3\AppData\Roaming\Adobe
2014-11-08 13:22 - 2014-11-12 10:43 - 00005144 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-Test3 KORTS001LKO
2014-11-08 10:43 - 2014-11-18 07:16 - 00005154 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-derossie KORTS001LKO
2014-11-08 10:40 - 2014-11-08 10:37 - 00001443 _____ () C:\Users\test4\Desktop\Internet Explorer.lnk
2014-11-08 10:40 - 2014-09-17 22:42 - 00003015 _____ () C:\Users\test4\Desktop\Word 2013.lnk
2014-11-08 10:40 - 2014-09-17 22:39 - 00003037 _____ () C:\Users\test4\Desktop\Excel 2013.lnk
2014-11-08 10:39 - 2014-11-08 10:39 - 00000576 _____ () C:\Users\test4\Desktop\koserver (kowaage) (I) - Verknüpfung.lnk
2014-11-08 10:39 - 2014-11-08 10:39 - 00000558 _____ () C:\Users\test4\Desktop\dtg (kornux) (G) - Verknüpfung.lnk
2014-11-08 10:37 - 2014-11-08 10:37 - 00001443 _____ () C:\Users\test4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-08 10:37 - 2014-11-08 10:37 - 00001409 _____ () C:\Users\test4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-11-08 10:37 - 2014-11-08 10:37 - 00000502 __RSH () C:\Users\test4\ntuser.pol
2014-11-08 10:37 - 2014-11-08 10:37 - 00000020 ___SH () C:\Users\test4\ntuser.ini
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Vorlagen
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Startmenü
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Netzwerkumgebung
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Lokale Einstellungen
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Eigene Dateien
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Druckumgebung
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Documents\Eigene Musik
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Documents\Eigene Bilder
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 _SHDL () C:\Users\test4\Anwendungsdaten
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 ____D () C:\Users\test4\WINDOWS
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 ____D () C:\Users\test4\AppData\Roaming\ICAClient
2014-11-08 10:37 - 2014-11-08 10:37 - 00000000 ____D () C:\Users\test4
2014-11-08 10:37 - 2009-07-14 05:58 - 00000000 ___RD () C:\Users\test4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-08 10:37 - 2009-07-14 05:53 - 00000000 ___RD () C:\Users\test4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-08 10:35 - 2014-11-08 10:32 - 00001443 _____ () C:\Users\Test3\Desktop\Internet Explorer.lnk
2014-11-08 10:33 - 2014-11-08 10:33 - 00000576 _____ () C:\Users\Test3\Desktop\koserver (kowaage) (I) - Verknüpfung.lnk
2014-11-08 10:33 - 2014-11-08 10:33 - 00000558 _____ () C:\Users\Test3\Desktop\dtg (kornux) (G) - Verknüpfung.lnk
2014-11-08 10:33 - 2014-09-17 22:42 - 00003015 _____ () C:\Users\Test3\Desktop\Word 2013.lnk
2014-11-08 10:33 - 2014-09-17 22:39 - 00003037 _____ () C:\Users\Test3\Desktop\Excel 2013.lnk
2014-11-08 10:32 - 2014-11-12 10:25 - 00000000 ____D () C:\Users\Test3\WINDOWS
2014-11-08 10:32 - 2014-11-12 10:22 - 00000000 ____D () C:\Users\Test3
2014-11-08 10:32 - 2014-11-08 10:32 - 00001443 _____ () C:\Users\Test3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-08 10:32 - 2014-11-08 10:32 - 00001409 _____ () C:\Users\Test3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-11-08 10:32 - 2014-11-08 10:32 - 00000502 __RSH () C:\Users\Test3\ntuser.pol
2014-11-08 10:32 - 2014-11-08 10:32 - 00000020 ___SH () C:\Users\Test3\ntuser.ini
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Vorlagen
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Startmenü
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Netzwerkumgebung
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Lokale Einstellungen
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Eigene Dateien
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Druckumgebung
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Documents\Eigene Musik
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Documents\Eigene Bilder
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 _SHDL () C:\Users\Test3\Anwendungsdaten
2014-11-08 10:32 - 2014-11-08 10:32 - 00000000 ____D () C:\Users\Test3\AppData\Roaming\ICAClient
2014-11-08 10:32 - 2009-07-14 05:58 - 00000000 ___RD () C:\Users\Test3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-08 10:32 - 2009-07-14 05:53 - 00000000 ___RD () C:\Users\Test3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-08 09:11 - 2014-11-08 09:11 - 00000502 __RSH () C:\Users\osmanovica\ntuser.pol
2014-11-08 09:11 - 2014-11-08 09:11 - 00000000 ____D () C:\Users\osmanovica\AppData\Roaming\ICAClient
2014-11-08 08:09 - 2014-11-08 14:20 - 00000000 ____D () C:\Users\frankd\AppData\Local\Temp\4
2014-11-07 07:53 - 2014-11-07 12:58 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\132
2014-11-07 07:07 - 2014-11-07 13:04 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\127
2014-11-06 14:36 - 2014-11-06 16:26 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\121
2014-11-06 14:12 - 2014-11-06 14:12 - 00000502 __RSH () C:\Users\laptopnx63251\ntuser.pol
2014-11-06 09:31 - 2014-11-06 09:31 - 00000000 ____D () C:\Users\buchgraberp\AppData\Local\Temp\Adobe
2014-11-06 07:25 - 2014-11-06 16:31 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\123
2014-11-05 10:54 - 2014-11-05 10:54 - 00000000 ____D () C:\Users\schmoellerla\AppData\Roaming\Macromedia
2014-11-05 08:03 - 2014-11-05 13:03 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\130
2014-11-05 07:28 - 2014-11-05 13:57 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\125
2014-11-05 07:12 - 2014-11-05 07:12 - 00000000 __HDC () C:\ProgramData\{E53F59DB-1816-4C22-A857-32973F50D2C4}
2014-11-04 10:49 - 2014-11-04 10:49 - 00000502 __RSH () C:\Users\motiondata4\ntuser.pol
2014-11-04 10:24 - 2014-11-18 09:40 - 00005150 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-meisslc KORTS001LKO
2014-11-04 07:47 - 2014-11-04 13:04 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\122
2014-11-04 07:28 - 2014-11-04 13:55 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\119
2014-11-04 07:24 - 2014-11-04 16:31 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\117
2014-11-04 07:15 - 2014-11-04 16:17 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\111
2014-11-04 06:41 - 2014-11-04 17:45 - 00000000 ____D () C:\Users\derossie\AppData\Local\Temp\5
2014-11-03 07:29 - 2014-11-03 13:47 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\116
2014-11-03 07:10 - 2014-11-03 16:20 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\101
2014-11-03 06:58 - 2014-11-03 06:58 - 00000502 __RSH () C:\Users\schoenweilerd\ntuser.pol
2014-10-31 06:55 - 2014-10-31 12:51 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\13
2014-10-31 06:42 - 2014-10-31 06:42 - 00000502 __RSH () C:\Users\ledererb\ntuser.pol
2014-10-30 14:58 - 2014-10-30 14:58 - 00000502 __RSH () C:\Users\kloiberc\ntuser.pol
2014-10-30 13:45 - 2014-10-30 13:45 - 00000000 ____D () C:\Users\strell\AppData\Roaming\ASE
2014-10-30 11:24 - 2014-10-30 11:24 - 00000000 ____D () C:\Users\pfuntnerv\AppData\Roaming\Macromedia
2014-10-30 08:39 - 2014-10-30 08:39 - 00000502 __RSH () C:\Users\schwarzotta\ntuser.pol
2014-10-30 07:58 - 2014-10-30 07:58 - 00000502 __RSH () C:\Users\freymuellerm\ntuser.pol
2014-10-30 07:56 - 2014-10-30 07:56 - 00000502 __RSH () C:\Users\ullreiche\ntuser.pol
2014-10-30 07:26 - 2014-10-30 14:59 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\113
2014-10-30 07:26 - 2014-10-30 07:26 - 00000502 __RSH () C:\Users\labp\ntuser.pol
2014-10-30 07:09 - 2014-10-30 17:14 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\102
2014-10-30 06:54 - 2014-10-30 06:54 - 00000502 __RSH () C:\Users\riedln\ntuser.pol
2014-10-29 09:51 - 2014-10-29 09:51 - 00000502 __RSH () C:\Users\breitse\ntuser.pol
2014-10-29 09:47 - 2014-10-29 09:47 - 00000502 __RSH () C:\Users\preinreicht\ntuser.pol
2014-10-29 09:47 - 2014-10-29 09:47 - 00000502 __RSH () C:\Users\idingera\ntuser.pol
2014-10-29 09:44 - 2014-10-29 09:44 - 00000502 __RSH () C:\Users\wkoze3\ntuser.pol
2014-10-29 09:36 - 2014-10-29 09:36 - 00000502 __RSH () C:\Users\binderm\ntuser.pol
2014-10-29 09:33 - 2014-10-29 09:33 - 00000502 __RSH () C:\Users\wwoze1\ntuser.pol
2014-10-29 09:32 - 2014-10-29 09:32 - 00000502 __RSH () C:\Users\buchgraberp\ntuser.pol
2014-10-29 09:31 - 2014-10-29 09:31 - 00000502 __RSH () C:\Users\kraftj\ntuser.pol
2014-10-29 09:28 - 2014-10-29 09:28 - 00000502 __RSH () C:\Users\ebwkjd\ntuser.pol
2014-10-29 09:27 - 2014-10-29 09:27 - 00000502 __RSH () C:\Users\lehnerh\ntuser.pol
2014-10-29 09:18 - 2014-10-29 09:18 - 00000502 __RSH () C:\Users\frankd\ntuser.pol
2014-10-29 09:16 - 2014-10-29 09:16 - 00000502 __RSH () C:\Users\strell\ntuser.pol
2014-10-29 09:15 - 2014-10-29 09:15 - 00000502 __RSH () C:\Users\meisslc\ntuser.pol
2014-10-29 09:11 - 2014-10-29 09:11 - 00000502 __RSH () C:\Users\wkoze1\ntuser.pol
2014-10-29 09:09 - 2014-10-29 09:09 - 00000502 __RSH () C:\Users\schmoellerla\ntuser.pol
2014-10-29 09:08 - 2014-10-29 09:08 - 00000502 __RSH () C:\Users\trth2\ntuser.pol
2014-10-29 09:03 - 2014-10-29 09:03 - 00000502 __RSH () C:\Users\webze1\ntuser.pol
2014-10-29 09:02 - 2014-10-29 09:02 - 00000502 __RSH () C:\Users\zwiebm\ntuser.pol
2014-10-29 09:02 - 2014-10-29 09:02 - 00000502 __RSH () C:\Users\sallmaiera\ntuser.pol
2014-10-29 09:01 - 2014-10-29 09:01 - 00000502 __RSH () C:\Users\wkoze4\ntuser.pol
2014-10-29 08:57 - 2014-10-29 08:57 - 00000502 __RSH () C:\Users\fahrbacha\ntuser.pol
2014-10-29 08:56 - 2014-10-29 08:56 - 00000502 __RSH () C:\Users\mantlerl\ntuser.pol
2014-10-29 08:55 - 2014-10-29 08:55 - 00000502 __RSH () C:\Users\schmutzc\ntuser.pol
2014-10-29 08:52 - 2014-10-29 08:52 - 00000502 __RSH () C:\Users\wittmannh\ntuser.pol
2014-10-29 08:52 - 2014-10-29 08:52 - 00000502 __RSH () C:\Users\fellnerr\ntuser.pol
2014-10-29 08:50 - 2014-10-29 08:50 - 00000502 __RSH () C:\Users\derossie\ntuser.pol
2014-10-29 08:48 - 2014-10-29 08:48 - 00000502 __RSH () C:\Users\pfuntnerv\ntuser.pol
2014-10-29 08:45 - 2014-10-29 08:45 - 00000502 __RSH () C:\Users\radlf\ntuser.pol
2014-10-29 08:44 - 2014-10-29 08:44 - 00000502 __RSH () C:\Users\schmutzs\ntuser.pol
2014-10-29 08:43 - 2014-10-29 08:43 - 00000502 __RSH () C:\Users\wiedermannj\ntuser.pol
2014-10-29 08:43 - 2014-10-29 08:43 - 00000502 __RSH () C:\Users\mayerm\ntuser.pol
2014-10-29 08:42 - 2014-10-29 08:42 - 00000502 __RSH () C:\Users\kraftjo\ntuser.pol
2014-10-29 08:37 - 2014-10-29 08:37 - 00000502 __RSH () C:\Users\holzmanne.KORTS001LKO\ntuser.pol
2014-10-29 08:36 - 2014-10-29 08:36 - 00000502 __RSH () C:\Users\bartalr\ntuser.pol
2014-10-29 08:35 - 2014-10-29 08:35 - 00000502 __RSH () C:\Users\blehap\ntuser.pol
2014-10-29 08:34 - 2014-10-29 08:34 - 00000502 __RSH () C:\Users\poikc\ntuser.pol
2014-10-29 08:33 - 2014-10-29 08:33 - 00000502 __RSH () C:\Users\Risdata\ntuser.pol
2014-10-29 08:33 - 2014-10-29 08:33 - 00000502 __RSH () C:\Users\lutzj\ntuser.pol
2014-10-29 08:30 - 2014-10-29 08:30 - 00000502 __RSH () C:\Users\stinglt\ntuser.pol
2014-10-29 08:29 - 2014-10-29 08:29 - 00000502 __RSH () C:\Users\buscht\ntuser.pol
2014-10-29 08:26 - 2014-10-29 08:26 - 00000502 __RSH () C:\Users\klausl\ntuser.pol
2014-10-29 08:21 - 2014-10-29 08:21 - 00000502 __RSH () C:\Users\wwoetl1\ntuser.pol
2014-10-29 08:20 - 2014-10-29 08:20 - 00000502 __RSH () C:\Users\penischa\ntuser.pol
2014-10-29 08:19 - 2014-10-29 08:19 - 00000502 __RSH () C:\Users\wkoze2\ntuser.pol
2014-10-29 08:18 - 2014-10-29 08:18 - 00000502 __RSH () C:\Users\trebv\ntuser.pol
2014-10-29 08:16 - 2014-10-29 08:16 - 00000502 __RSH () C:\Users\lahnerj\ntuser.pol
2014-10-29 08:15 - 2014-10-29 08:15 - 00000502 __RSH () C:\Users\kandlerh\ntuser.pol
2014-10-29 08:12 - 2014-10-29 08:12 - 00000502 __RSH () C:\Users\waschulinf\ntuser.pol
2014-10-29 08:08 - 2014-10-29 08:08 - 00000502 __RSH () C:\Users\trzeit\ntuser.pol
2014-10-29 08:03 - 2014-11-18 05:36 - 00000502 __RSH () C:\Users\Administrator\ntuser.pol
2014-10-29 08:03 - 2014-10-29 08:03 - 00000502 __RSH () C:\Users\brandstetterh.KORTS001LKO\ntuser.pol
2014-10-29 07:12 - 2014-10-29 16:33 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\87
2014-10-29 06:58 - 2014-10-29 16:01 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\35
2014-10-29 06:53 - 2014-10-29 18:14 - 00000000 ____D () C:\Users\derossie\AppData\Local\Temp\17
2014-10-28 17:26 - 2014-10-28 17:26 - 00057114 _____ () C:\Users\frankd\Desktop\Depot_20141028_171005.xlsx
2014-10-28 13:56 - 2014-10-28 13:56 - 00000000 ____D () C:\Users\ebwkjd\AppData\Roaming\ICAClient
2014-10-28 11:30 - 2014-11-06 15:31 - 00000000 ____D () C:\Users\fahrbacha\AppData\Local\Temp\120
2014-10-28 11:30 - 2014-10-28 11:30 - 00000000 ____D () C:\Users\fahrbacha\AppData\Roaming\ICAClient
2014-10-28 07:56 - 2014-10-29 13:40 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\109
2014-10-28 07:29 - 2014-10-28 13:54 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\104
2014-10-27 11:02 - 2014-10-27 11:02 - 00000000 ____D () C:\Users\wwoetl2\AppData\Roaming\ICAClient
2014-10-27 10:10 - 2014-11-13 16:42 - 00000000 ____D () C:\Users\trebv\AppData\Local\Temp\115
2014-10-27 08:03 - 2014-10-27 13:05 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\110
2014-10-27 07:30 - 2014-10-27 13:55 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\105
2014-10-27 06:56 - 2014-10-27 16:00 - 00000000 ____D () C:\Users\blehap\AppData\Local\Temp\33
2014-10-24 12:15 - 2014-10-24 12:15 - 00084886 _____ () C:\Users\labp\Desktop\Reifendepotliste per 24.10.14.xlsx
2014-10-24 10:19 - 2014-10-24 10:19 - 00001409 _____ () C:\Users\laptopnx63251\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-10-24 10:19 - 2014-10-24 10:19 - 00000000 ____D () C:\Users\laptopnx63251\AppData\Roaming\ICAClient
2014-10-24 08:51 - 2014-10-24 08:51 - 00008550 _____ () C:\Users\labp\Documents\Provisionen.xlsx
2014-10-24 06:07 - 2014-10-24 12:04 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\93
2014-10-24 05:50 - 2014-10-24 12:16 - 00000000 ____D () C:\Users\frankd\AppData\Local\Temp\6
2014-10-23 12:30 - 2014-10-23 12:59 - 00013943 _____ () C:\Users\labp\Desktop\Kopie von Urlaubsliste Tresdorf.xlsx
2014-10-23 11:27 - 2014-10-23 11:27 - 00004421 _____ () C:\Users\Risdata\Documents\1 MdAxp + AxpMd_KO.stmt
2014-10-23 06:29 - 2014-10-23 13:26 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\91
2014-10-23 05:56 - 2014-10-23 15:15 - 00000000 ____D () C:\Users\ellinger\AppData\Local\Temp\16
2014-10-22 09:37 - 2014-10-22 11:15 - 00015219 _____ () C:\Users\labp\Desktop\Kopie von RG_PFUNTNER_43 21 10 Verlust.xlsx
2014-10-22 06:28 - 2014-10-22 12:16 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\82
2014-10-22 06:24 - 2014-10-22 15:33 - 00000000 ____D () C:\Users\bartalr\AppData\Local\Temp\76
2014-10-22 06:08 - 2014-10-23 16:04 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\39
2014-10-21 13:34 - 2014-11-13 16:41 - 00000000 ____D () C:\Users\binderm\AppData\Local\Temp\86
2014-10-21 12:03 - 2014-11-13 16:43 - 00000000 ____D () C:\Users\idingera\AppData\Local\Temp\34
2014-10-21 06:57 - 2014-10-21 11:11 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\97
2014-10-21 06:32 - 2014-10-21 12:51 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\96
2014-10-21 06:13 - 2014-10-21 06:13 - 00000000 ____D () C:\Users\wernardp\AppData\Roaming\ICAClient
2014-10-20 11:42 - 2014-10-23 11:33 - 00013539 _____ () C:\Users\labp\Desktop\Reifen Fragen Andreas.xlsx
2014-10-20 11:07 - 2014-10-21 11:32 - 00013021 _____ () C:\Users\frankd\Desktop\Kundendaten ergänzen.xlsx
2014-10-20 07:16 - 2014-10-24 12:02 - 00000000 ____D () C:\Users\trebv\AppData\Local\Temp\95
2014-10-20 06:58 - 2014-10-20 12:00 - 00000000 ____D () C:\Users\meisslc\AppData\Local\Temp\92
2014-10-20 06:33 - 2014-10-20 12:51 - 00000000 ____D () C:\Users\labp\AppData\Local\Temp\85
2014-10-20 06:18 - 2014-10-20 16:02 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\81
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-18 12:35 - 2014-05-22 06:47 - 00000000 ____D () C:\Users\labp\Documents\Outlook-Dateien
2014-11-18 12:26 - 2014-08-20 15:26 - 00005138 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-labp KORTS001LKO
2014-11-18 11:12 - 2012-01-17 14:05 - 01059460 _____ () C:\Windows\WindowsUpdate.log
2014-11-18 09:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-18 08:43 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\inetsrv
2014-11-18 08:41 - 2012-02-10 08:14 - 01727682 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-11-18 08:41 - 2010-11-21 06:48 - 00755466 _____ () C:\Windows\system32\perfh007.dat
2014-11-18 08:41 - 2010-11-21 06:48 - 00167168 _____ () C:\Windows\system32\perfc007.dat
2014-11-18 08:41 - 2009-07-14 06:10 - 01727682 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-18 08:35 - 2014-07-25 06:51 - 00005162 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-sallmaiera KORTS001LKO
2014-11-18 08:31 - 2014-10-14 14:32 - 00005150 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-bartalr KORTS001LKO
2014-11-18 08:18 - 2014-09-01 08:57 - 00000000 ____D () C:\Users\meisslc\Desktop\Diverses, Passwörter
2014-11-18 08:01 - 2013-03-12 11:01 - 00000000 ____D () C:\Users\breitse
2014-11-18 07:59 - 2012-01-27 10:01 - 00000000 ____D () C:\Users\kandlerh
2014-11-18 07:58 - 2014-09-30 07:04 - 00000000 ____D () C:\Users\binderm\AppData\Local\Temp\43
2014-11-18 07:39 - 2014-07-07 13:56 - 00000000 ____D () C:\Users\binderm
2014-11-18 07:33 - 2009-07-14 05:49 - 00023168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-18 07:33 - 2009-07-14 05:49 - 00023168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-18 07:25 - 2014-05-09 10:04 - 00000000 ____D () C:\Users\trth2
2014-11-18 07:09 - 2014-09-01 06:52 - 00005164 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-waschulinf KORTS001LKO
2014-11-18 07:08 - 2014-09-01 14:12 - 00005146 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-frankd KORTS001LKO
2014-11-18 07:05 - 2012-01-26 16:00 - 00000000 ____D () C:\Users\kloiberc
2014-11-18 07:04 - 2012-01-26 15:42 - 00000000 ____D () C:\Users\pfuntnerv
2014-11-18 07:03 - 2012-03-06 14:00 - 00000000 ____D () C:\Users\wkoze4
2014-11-18 07:01 - 2013-02-11 06:58 - 00000000 ____D () C:\Users\schoenweilerd\AppData\Roaming\VMware
2014-11-18 07:01 - 2012-03-14 07:00 - 00000000 ____D () C:\Users\idingera\AppData\Roaming\VMware
2014-11-18 06:59 - 2014-05-16 10:34 - 00000000 ____D () C:\Users\trzeit
2014-11-18 06:59 - 2012-11-06 07:21 - 00000000 ____D () C:\Users\laptopnx63251
2014-11-18 06:57 - 2012-01-27 13:52 - 00000000 ____D () C:\Users\kraftjo
2014-11-18 06:52 - 2012-06-05 08:41 - 00000000 ____D () C:\Users\blehap
2014-11-18 06:51 - 2013-09-05 05:54 - 00000000 ____D () C:\Users\wkoze1\AppData\Roaming\VMware
2014-11-18 06:49 - 2012-05-29 06:21 - 00000000 ____D () C:\Users\brandstetterh.KORTS001LKO\AppData\Roaming\VMware
2014-11-18 06:48 - 2014-08-01 08:40 - 00000000 ____D () C:\Users\frankd
2014-11-18 06:48 - 2012-04-04 06:54 - 00000000 ____D () C:\Users\brandstetterh.KORTS001LKO
2014-11-18 06:48 - 2012-01-27 13:25 - 00000000 ____D () C:\Users\webze1
2014-11-18 05:36 - 2012-01-17 14:04 - 00000000 ____D () C:\Users\Administrator
2014-11-18 05:34 - 2012-01-17 17:28 - 00000000 ____D () C:\Windows\system32\lserver
2014-11-18 05:34 - 2009-07-14 06:06 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-18 05:34 - 2009-07-14 05:56 - 00021036 _____ () C:\Windows\setupact.log
2014-11-17 20:00 - 2012-02-15 16:07 - 00000542 _____ () C:\Windows\Tasks\Neue zeitgesteuerte Überprüfung.job
2014-11-17 18:48 - 2014-03-06 23:53 - 02510528 _____ (Sysinternals - www.sysinternals.com) C:\Users\Administrator\Desktop\Procmon.exe
2014-11-17 18:12 - 2014-09-11 08:57 - 00593080 _____ (Sysinternals - www.sysinternals.com) C:\Users\Administrator\Desktop\autoruns.exe
2014-11-17 11:40 - 2014-10-08 09:03 - 00000000 ____D () C:\Users\bartalr\Desktop\Versicherung-Rechnungen
2014-11-17 09:27 - 2012-01-30 10:48 - 00001443 _____ () C:\Users\motiondata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-17 09:27 - 2012-01-30 10:48 - 00000000 ____D () C:\Users\motiondata
2014-11-17 07:09 - 2014-06-27 06:09 - 00000000 ____D () C:\Users\trth2\AppData\Roaming\VMware
2014-11-17 06:57 - 2012-03-14 06:59 - 00000000 ____D () C:\Users\mantlerl\AppData\Roaming\VMware
2014-11-17 06:55 - 2012-08-17 05:59 - 00000000 ____D () C:\Users\riedln\AppData\Roaming\VMware
2014-11-15 00:08 - 2013-04-25 18:52 - 00000000 ___HD () C:\Backup Exec AOFO Store
2014-11-14 13:01 - 2014-09-18 06:05 - 00000000 ____D () C:\Users\sallmaiera\AppData\Local\Temp\33
2014-11-14 09:19 - 2014-05-27 06:58 - 00000000 ____D () C:\Users\bartalr\Desktop\Schadenmeldungen
2014-11-14 07:40 - 2012-03-14 14:41 - 00000000 ____D () C:\ERE
2014-11-14 06:57 - 2014-06-05 05:55 - 00000000 ____D () C:\Users\bartalr\AppData\Roaming\VMware
2014-11-14 06:55 - 2012-03-22 13:05 - 00000000 ____D () C:\Users\lutzj\AppData\Roaming\VMware
2014-11-13 17:43 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-11-13 16:57 - 2012-01-27 11:18 - 00000000 ____D () C:\Users\Risdata
2014-11-13 16:48 - 2014-10-13 11:52 - 00001483 _____ () C:\Users\Public\Desktop\MOTIONDATA Online Update Manager.lnk
2014-11-13 16:48 - 2014-07-04 08:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MOTIONDATA
2014-11-13 16:45 - 2010-11-21 04:47 - 00052688 _____ () C:\Windows\PFRO.log
2014-11-13 16:12 - 2012-11-13 15:04 - 00000000 ____D () C:\Users\motiondata3
2014-11-13 10:11 - 2014-06-12 13:58 - 00000000 ____D () C:\Users\bartalr\Desktop\REHA-PRUCKNER-UMBAUTEN
2014-11-13 08:30 - 2014-09-01 11:27 - 00000000 ____D () C:\Users\frankd\Desktop\Eigener Ordner
2014-11-13 07:17 - 2014-05-13 12:07 - 00000000 ____D () C:\Users\sallmaiera
2014-11-13 06:57 - 2014-05-13 12:02 - 00000000 ____D () C:\Users\bartalr
2014-11-12 16:59 - 2014-05-13 10:58 - 00000000 ____D () C:\Users\derossie
2014-11-12 11:44 - 2014-05-21 13:10 - 00000000 _____ () C:\Windows\system32\vireng.log
2014-11-12 10:06 - 2012-01-27 13:42 - 00000000 ____D () C:\Users\buscht\WINDOWS
2014-11-12 08:03 - 2014-08-27 12:20 - 00000000 ____D () C:\Users\meisslc
2014-11-12 07:29 - 2014-05-13 12:11 - 00000000 ____D () C:\Users\labp
2014-11-12 07:01 - 2013-01-29 07:04 - 00000000 ____D () C:\Users\pfuntnerv\AppData\Roaming\VMware
2014-11-12 06:59 - 2012-06-14 05:57 - 00000000 ____D () C:\Users\holzmanne.KORTS001LKO\AppData\Roaming\VMware
2014-11-12 06:58 - 2012-07-02 05:58 - 00000000 ____D () C:\Users\wiedermannj\AppData\Roaming\VMware
2014-11-12 06:58 - 2012-03-30 05:58 - 00000000 ____D () C:\Users\schmutzs\AppData\Roaming\VMware
2014-11-11 08:14 - 2012-01-25 11:09 - 00000000 ____D () C:\ProgramData\MOTIONDATA Software GmbH
2014-11-11 06:58 - 2013-02-12 06:59 - 00000000 ____D () C:\Users\ledererb\AppData\Roaming\VMware
2014-11-11 06:57 - 2012-09-28 05:57 - 00000000 ____D () C:\Users\kraftjo\AppData\Roaming\VMware
2014-11-11 06:56 - 2013-03-05 07:01 - 00000000 ____D () C:\Users\radlf\AppData\Roaming\VMware
2014-11-08 09:11 - 2012-01-27 13:58 - 00000000 ____D () C:\Users\osmanovica
2014-11-07 10:25 - 2014-10-14 10:50 - 00000000 ____D () C:\Users\mayerm\Desktop\Fotos Gebrauchtwagen
2014-11-07 08:42 - 2014-08-01 06:16 - 00005144 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-trth2 KORTS001LKO
2014-11-05 07:42 - 2014-09-18 10:26 - 00000950 _____ () C:\Users\Public\Desktop\Ere-Manager.lnk
2014-11-05 07:42 - 2014-08-12 12:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EurotaxGlass
2014-11-04 18:29 - 2014-10-06 06:23 - 00005144 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for KORTS001LKO-trebv KORTS001LKO
2014-11-04 10:49 - 2013-02-05 15:55 - 00000000 ____D () C:\Users\motiondata4
2014-11-03 06:58 - 2012-01-27 12:03 - 00000000 ____D () C:\Users\schoenweilerd
2014-10-31 06:42 - 2012-01-27 10:33 - 00000000 ____D () C:\Users\ledererb
2014-10-30 08:39 - 2012-01-27 09:55 - 00000000 ____D () C:\Users\schwarzotta
2014-10-30 07:58 - 2012-11-14 13:49 - 00000000 ____D () C:\Users\freymuellerm
2014-10-30 07:56 - 2012-01-27 12:22 - 00000000 ____D () C:\Users\ullreiche
2014-10-30 06:54 - 2012-06-29 14:33 - 00000000 ____D () C:\Users\riedln
2014-10-29 09:47 - 2012-01-27 13:41 - 00000000 ____D () C:\Users\preinreicht
2014-10-29 09:47 - 2012-01-27 13:10 - 00000000 ____D () C:\Users\idingera
2014-10-29 09:44 - 2012-02-13 07:04 - 00000000 ____D () C:\Users\wkoze3
2014-10-29 09:33 - 2012-01-27 12:13 - 00000000 ____D () C:\Users\wwoze1
2014-10-29 09:32 - 2012-03-13 14:46 - 00000000 ____D () C:\Users\buchgraberp
2014-10-29 09:31 - 2012-01-27 13:38 - 00000000 ____D () C:\Users\kraftj
2014-10-29 09:28 - 2012-12-06 13:02 - 00000000 ____D () C:\Users\ebwkjd
2014-10-29 09:27 - 2012-01-27 07:52 - 00000000 ____D () C:\Users\lehnerh
2014-10-29 09:16 - 2013-11-04 08:42 - 00000000 ____D () C:\Users\strell
2014-10-29 09:11 - 2012-02-08 13:07 - 00000000 ____D () C:\Users\wkoze1
2014-10-29 09:09 - 2012-03-01 08:04 - 00000000 ____D () C:\Users\schmoellerla
2014-10-29 09:02 - 2012-01-27 10:12 - 00000000 ____D () C:\Users\zwiebm
2014-10-29 08:57 - 2012-01-27 10:07 - 00000000 ____D () C:\Users\fahrbacha
2014-10-29 08:56 - 2012-01-27 10:10 - 00000000 ____D () C:\Users\mantlerl
2014-10-29 08:55 - 2012-01-27 13:30 - 00000000 ____D () C:\Users\schmutzc
2014-10-29 08:52 - 2012-03-23 07:33 - 00000000 ____D () C:\Users\wittmannh
2014-10-29 08:52 - 2012-01-27 12:17 - 00000000 ____D () C:\Users\fellnerr
2014-10-29 08:45 - 2013-02-11 13:35 - 00000000 ____D () C:\Users\radlf
2014-10-29 08:44 - 2012-01-27 10:05 - 00000000 ____D () C:\Users\schmutzs
2014-10-29 08:43 - 2014-06-18 06:14 - 00000000 ____D () C:\Users\mayerm
2014-10-29 08:43 - 2012-01-27 10:29 - 00000000 ____D () C:\Users\wiedermannj
2014-10-29 08:37 - 2012-04-11 07:38 - 00000000 ____D () C:\Users\holzmanne.KORTS001LKO
2014-10-29 08:34 - 2012-01-27 10:03 - 00000000 ____D () C:\Users\poikc
2014-10-29 08:33 - 2012-01-27 12:16 - 00000000 ____D () C:\Users\lutzj
2014-10-29 08:30 - 2012-05-09 13:27 - 00000000 ____D () C:\Users\stinglt
2014-10-29 08:29 - 2012-01-27 10:28 - 00000000 ____D () C:\Users\buscht
2014-10-29 08:26 - 2012-01-27 10:30 - 00000000 ____D () C:\Users\klausl
2014-10-29 08:21 - 2012-03-29 11:26 - 00000000 ____D () C:\Users\wwoetl1
2014-10-29 08:20 - 2012-01-27 14:03 - 00000000 ____D () C:\Users\penischa
2014-10-29 08:19 - 2012-02-08 13:17 - 00000000 ____D () C:\Users\wkoze2
2014-10-29 08:18 - 2014-05-27 20:19 - 00000000 ____D () C:\Users\trebv
2014-10-29 08:16 - 2012-01-27 12:11 - 00000000 ____D () C:\Users\lahnerj
2014-10-29 07:52 - 2014-07-03 06:48 - 00001912 __RSH () C:\ProgramData\ntuser.pol
2014-10-29 06:55 - 2012-11-09 06:58 - 00000000 ____D () C:\Users\poikc\AppData\Roaming\VMware
2014-10-28 16:07 - 2014-06-30 13:21 - 00000000 ____D () C:\Temp
2014-10-27 11:02 - 2012-05-08 11:01 - 00000000 ____D () C:\Users\wwoetl2
2014-10-27 06:53 - 2012-11-02 07:01 - 00000000 ____D () C:\Users\zwiebm\AppData\Roaming\VMware
2014-10-24 10:19 - 2012-11-06 07:21 - 00001443 _____ () C:\Users\laptopnx63251\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-10-24 09:21 - 2014-08-20 13:10 - 00097674 _____ () C:\Users\Risdata\Desktop\RG_RISDATA_43.csv
2014-10-24 09:19 - 2013-10-17 13:38 - 00313092 _____ () C:\Users\Risdata\Desktop\RG_RISDATA_18.csv
2014-10-24 05:55 - 2012-04-30 06:03 - 00000000 ____D () C:\Users\fellnerr\AppData\Roaming\VMware
2014-10-23 10:21 - 2013-10-17 13:17 - 00450906 _____ () C:\Users\Risdata\Desktop\RG_RISDATA_8.csv
2014-10-23 05:57 - 2014-10-16 05:59 - 00000000 ____D () C:\Users\ellinger\AppData\Roaming\VMware
2014-10-22 12:40 - 2014-06-18 13:54 - 00000000 ____D () C:\Program Files\Canon
2014-10-22 09:51 - 2013-10-17 14:04 - 00176616 _____ () C:\Users\Risdata\Desktop\RG_RISDATA_34.csv
2014-10-22 06:03 - 2014-09-12 07:17 - 00020070 _____ () C:\Users\Risdata\Desktop\RG_RISDATA_42.csv
2014-10-22 05:53 - 2012-10-08 05:54 - 00000000 ____D () C:\Users\lahnerj\AppData\Roaming\VMware
2014-10-21 11:34 - 2012-10-22 05:57 - 00000000 ____D () C:\Users\wkoze3\AppData\Roaming\VMware
Files to move or delete:
====================
C:\Users\mayerm\TsAllUsr.Dat
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-15 05:46
==================== End Of Log ============================ --- --- --- |