Hi Schrauber,
vielen Dank für deine Unterstützung!
Die Fehlermeldung wurde mir trotz deaktiviertem AV (Im Programm war alles auf Deaktiviert allerdings zeigt mir die Addition.txt dennoch enabled an) trotzdem angezeigt.
Genaue Fehlermeldung:
"Diese App kann auf dem PC nicht ausgeführt werden
Wenden Sie sich an den Softwareherausgeber, um eine geeignete Version für Ihren PC zu finden."
Habe die aktuellste Version und auch die Richtige. ( 32 / 64 Bit )
Ich habe allerdings diesmal dennoch Untersuchen gedrückt und es hat dann auch die Untersuchung wie gewünscht ausgeführt.
Logs:
Erstmal Addition da das FRST riesig ist. Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:19-11-2015
durchgeführt von Robert (2015-11-20 12:07:57)
Gestartet von C:\Users\rober\Desktop
Windows 10 Home (X64) (2015-11-13 19:39:50)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-3938361683-1663457597-2333501448-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3938361683-1663457597-2333501448-503 - Limited - Disabled)
Gast (S-1-5-21-3938361683-1663457597-2333501448-501 - Limited - Disabled)
Robert (S-1-5-21-3938361683-1663457597-2333501448-1005 - Administrator - Enabled) => C:\Users\rober
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.009.20077 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
CyberLink Home Cinema 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.)
CyberLink PhotoDirector 5 (Version: 5.0.5.6602 - CyberLink Corp.) Hidden
CyberLink PowerDirector 12 (Version: 12.0.4118.0 - CyberLink Corp.) Hidden
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.7.0.4308 - CyberLink Corp.)
CyberLink PowerRecover (Version: 5.7.0.4308 - CyberLink Corp.) Hidden
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.6.3.1 - Dolby Laboratories Inc)
ELAN Touchpad 15.19.7.1_X64_WHQL (HKLM\...\Elantech) (Version: 15.19.7.1 - ELAN Microelectronic Corp.)
Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4240 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 1.1.253.0 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{DC5673D2-228D-45BC-B9BB-9610CE67DFC0}) (Version: 17.1.1524.1353 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{c92e37dd-de51-4a9e-abfc-54c4b71d1b72}) (Version: 18.11.0 - Intel Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
Malwarebytes Anti-Exploit version 1.07.1.1015 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.07.1.1015 - Malwarebytes)
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
McAfee LiveSafe (HKLM-x32\...\MSC) (Version: 14.0.5120 - McAfee, Inc.)
Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 15.0.4763.1003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4763.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4763.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4763.1003 - Microsoft Corporation) Hidden
PHotkey (HKLM-x32\...\{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}) (Version: 1.00.0116 - Pegatron Corporation)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.31213 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7503 - Realtek Semiconductor Corp.)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-3938361683-1663457597-2333501448-1005_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\rober\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\FileCoAuth.exe (Microsoft Corporation)
==================== Wiederherstellungspunkte =========================
ACHTUNG: Systemwiederherstellung ist deaktiviert
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2015-07-10 12:04 - 2015-07-10 12:02 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0B74010B-8940-410C-A9A2-1E14DCA76260} - System32\Tasks\PDVDServ12 Task => C:\Program Files (x86)\CyberLink\PowerDVD12\PDVD12Serv.exe [2015-06-03] (CyberLink Corp.)
Task: {16E362E0-9EB6-4294-A91F-C94BB719C71A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-30] (Microsoft Corporation)
Task: {181EF958-CF2C-45C1-BFE2-0048458E3EFC} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterUserDevice
Task: {2300B6D1-D409-499E-92DF-030662B73A6B} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic6
Task: {317107BF-13F6-48B4-AA5A-BA0B03A02F4B} - System32\Tasks\Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate
Task: {33046BDC-2974-457F-A198-055760713D46} - System32\Tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Management Initialization
Task: {3627755F-6629-4D94-850A-FBE43D28BEB8} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\CryptoPolicyTask
Task: {4208A7BF-D622-476E-A1A3-F9EB2719ECD4} - System32\Tasks\Microsoft\Windows\Management\Provisioning\Logon => C:\Windows\system32\ProvTool.exe [2015-11-13] (Microsoft Corporation)
Task: {45A1E736-EAAA-4735-ABBA-A9C5CF2BDAEF} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic1
Task: {469DDCA1-BAE7-4087-9067-C9EADC5F5240} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-11-13] (Microsoft Corporation)
Task: {4A944005-EAD7-4E3D-A0CB-E36A03948234} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck
Task: {4E3CB8C2-8A0C-4570-A32E-7319C6E8E432} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic24
Task: {511B8427-C77B-4A61-9235-7310F33ECF9D} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe [2015-06-03] (CyberLink Corp.)
Task: {51A83D7F-98D3-4715-94FA-A3A5CCBE89FC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-30] (Microsoft Corporation)
Task: {697E18DD-943C-470A-B9E3-6E5DDCB42D05} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange
Task: {6B696BCF-C866-41CA-B4E4-3D19FB1E9250} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceManagerTask => C:\Windows\system32\SpaceMan.exe [2015-10-30] (Microsoft Corporation)
Task: {71B964CD-263C-4B0A-B748-4F57566B088B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-07] (Microsoft Corporation)
Task: {71E53243-3A2D-47EE-9DAB-6D71B2366657} - System32\Tasks\Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate
Task: {76F4F6AB-4F5E-486E-8230-D5790FAFFE10} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {860F596C-A1D8-4651-B747-D134041D80AD} - System32\Tasks\Microsoft\Windows\DiskFootprint\StorageSense => Rundll32.exe %windir%\system32\StorageUsage.dll,GetStorageUsageInfo
Task: {90D79106-3D12-40AF-A9BA-231F2327770C} - System32\Tasks\Microsoft\Windows\DUSM\dusmtask => C:\Windows\System32\dusmtask.exe [2015-10-30] (Microsoft Corporation)
Task: {98B5B019-7E1F-4B09-B341-C5BC423BE2C8} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-19] (Adobe Systems Incorporated)
Task: {98C5435C-0149-4493-88CB-63E0C9FFD220} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
Task: {A483A62A-BEE2-43EF-B43D-C4B6555D6F1E} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceAccountChange
Task: {ADDADEB8-5A06-413F-9665-31F98F6878F1} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe [2014-04-08] (Dolby Laboratories Inc.)
Task: {BFA02A09-10D0-449D-9450-63B653E67F3A} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-10-30] (Microsoft Corporation)
Task: {C881A742-1A15-4EAC-96B9-9C6EA38AC7FA} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceConnectedToNetwork
Task: {D6DD3EA3-D1F8-4D28-9DD0-5FC63928C68D} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-07] (Microsoft Corporation)
Task: {E03596C8-B2A4-4553-B379-B678F0EBCA95} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff
Task: {F120A436-C215-4927-87AA-934387AF5782} - System32\Tasks\Microsoft\Windows\License Manager\TempSignedLicenseExchange
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2015-10-30 08:17 - 2015-10-30 08:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2015-07-16 22:01 - 2014-08-07 18:45 - 00135680 _____ () C:\Program Files (x86)\PHotkey\PGFNEXSrv.exe
2015-10-29 23:27 - 2015-10-07 19:28 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-07-16 21:34 - 2014-04-15 02:59 - 00389896 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-07-16 22:01 - 2015-03-11 18:24 - 02406912 _____ () C:\Program Files (x86)\PHotkey\PHotkey.exe
2015-07-16 22:01 - 2010-01-13 01:36 - 00117256 _____ () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2015-07-16 22:01 - 2010-01-13 01:36 - 00121864 _____ () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2015-10-30 08:17 - 2015-10-30 08:17 - 02652784 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-30 08:17 - 2015-10-30 08:17 - 02652784 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00396688 _____ () C:\WINDOWS\system32\igfxTray.exe
2015-07-16 22:01 - 2010-12-17 22:04 - 00449032 _____ () C:\Program Files (x86)\PHotkey\ATouch64.exe
2015-10-30 08:17 - 2015-10-30 08:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2015-10-30 08:17 - 2015-10-30 08:17 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-10-30 08:18 - 2015-10-30 19:44 - 08005632 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-10-30 08:18 - 2015-10-30 19:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-10-30 08:18 - 2015-10-30 19:44 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-30 08:18 - 2015-10-30 19:44 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-16 22:01 - 2014-04-04 02:41 - 03471872 _____ () C:\Program Files (x86)\PHotkey\POSD.exe
2015-07-16 22:01 - 2014-02-22 01:19 - 08857088 _____ () C:\Program Files (x86)\PHotkey\GPMTray.exe
2015-07-16 22:01 - 2015-03-20 17:44 - 00331776 _____ () C:\Program Files (x86)\PHotkey\Keyboardmonitortool.exe
2015-11-19 16:38 - 2015-11-19 16:39 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.13005.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-07-16 22:01 - 2009-12-18 23:36 - 00973432 _____ () C:\Program Files (x86)\PHotkey\acAuth.dll
2015-07-16 22:01 - 2013-09-18 07:23 - 00108032 _____ () C:\Program Files (x86)\PHotkey\PGFNEX.dll
2015-10-29 23:27 - 2015-10-29 23:27 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
2015-11-19 16:38 - 2015-11-19 16:38 - 00152064 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.13005.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2015-11-19 16:38 - 2015-11-19 16:39 - 18906624 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.13005.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-10-29 23:27 - 2015-10-29 23:27 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
AlternateDataStreams: C:\49f582e8f77954ca29a2:Win32App
AlternateDataStreams: C:\95ddbafa5c2cc0cdd6f383caa7de:Win32App
AlternateDataStreams: C:\96f6b3985cf12df0ce5edcde0b26a6:Win32App
AlternateDataStreams: C:\b0406cbce1c2c6749e:Win32App
AlternateDataStreams: C:\e8a23ac715320c67cc:Win32App
AlternateDataStreams: C:\Program Files\Dolby Digital Plus:Win32App_1
AlternateDataStreams: C:\Program Files\mcafee:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Office 15:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Cisco:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\CyberLink:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Intel:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Exploit:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Mozilla Firefox:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\PHotkey:Win32App_1
AlternateDataStreams: C:\ProgramData\regid.1991-06.com.microsoft:Win32App_1
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52} => ""="Firmware"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\uefi.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52} => ""="Firmware"
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
IE trusted site: HKU\S-1-5-21-3938361683-1663457597-2333501448-1005\...\sharepoint.com -> hxxps://bwedu.sharepoint.com
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-3938361683-1663457597-2333501448-1005\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-3938361683-1663457597-2333501448-1005\...\StartupApproved\StartupFolder: => "OneDrive for Business.lnk"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{9BFAE211-BE4A-43EB-8508-E6924EBC8A0B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{AAFD122C-3B98-47B1-B842-23FFA5AE64E3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C464E992-557F-4F51-83B9-BCA1C187ACB4}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{1F32F8BA-269F-4147-A49F-D2CF7FBF94AF}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{D4E23C57-6ADD-4231-A426-296E9C340FF1}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{CE7C5EC4-9875-47B3-8DB2-627B05244B27}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{26819A87-634D-4E56-9C02-552A0F86337F}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{19CF8B1D-1477-43B9-88EC-28E03FA7F603}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{222799A9-E4DF-44E6-8CFF-E28192F545C0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{98FDD75D-A7D4-46E8-9503-AD6DDB75167A}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{CEAF7138-5535-4371-99EF-8D495F3BB775}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{092E1525-C03F-447B-8160-4E339DCD1B50}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe
FirewallRules: [{33477B02-2369-4037-9E02-98E550403495}] => (Allow) C:\Program Files\CyberLink\PowerDirector12\PDR10.EXE
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (11/19/2015 10:09:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: 9vb5fvhg.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: 9vb5fvhg.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x1b48
Startzeit der fehlerhaften Anwendung: 0x9vb5fvhg.exe0
Pfad der fehlerhaften Anwendung: 9vb5fvhg.exe1
Pfad des fehlerhaften Moduls: 9vb5fvhg.exe2
Berichtskennung: 9vb5fvhg.exe3
Vollständiger Name des fehlerhaften Pakets: 9vb5fvhg.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: 9vb5fvhg.exe5
Error: (11/18/2015 00:38:54 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (11/15/2015 03:38:51 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8
Error: (11/13/2015 09:51:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ROBERT-LAPTOP)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/13/2015 09:51:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ROBERT-LAPTOP)
Description: Bei der Aktivierung der App „Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App“ ist folgender Fehler aufgetreten: -2147023564. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/13/2015 09:51:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SystemSettings.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d822
Name des fehlerhaften Moduls: twinapi.appcore.dll, Version: 10.0.10586.0, Zeitstempel: 0x5632d2f5
Ausnahmecode: 0xc000027b
Fehleroffset: 0x000000000004b199
ID des fehlerhaften Prozesses: 0x618
Startzeit der fehlerhaften Anwendung: 0xSystemSettings.exe0
Pfad der fehlerhaften Anwendung: SystemSettings.exe1
Pfad des fehlerhaften Moduls: SystemSettings.exe2
Berichtskennung: SystemSettings.exe3
Vollständiger Name des fehlerhaften Pakets: SystemSettings.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: SystemSettings.exe5
Error: (11/13/2015 09:26:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ROBERT-LAPTOP)
Description: Bei der Aktivierung der App „Microsoft.WindowsPhone_8wekyb3d8bbwe!CompanionApp.App“ ist folgender Fehler aufgetreten: -2147024770. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/13/2015 09:20:59 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ROBERT-LAPTOP)
Description: Bei der Aktivierung der App „Microsoft.WindowsPhone_8wekyb3d8bbwe!CompanionApp.App“ ist folgender Fehler aufgetreten: -2147024770. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/13/2015 09:20:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ROBERT-LAPTOP)
Description: Bei der Aktivierung der App „Microsoft.WindowsPhone_8wekyb3d8bbwe!CompanionApp.App“ ist folgender Fehler aufgetreten: -2147024770. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/13/2015 09:14:55 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ROBERT-LAPTOP)
Description: Bei der Aktivierung der App „Microsoft.WindowsPhone_8wekyb3d8bbwe!CompanionApp.App“ ist folgender Fehler aufgetreten: -2147024770. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Systemfehler:
=============
Error: (11/19/2015 10:48:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenzugriff_76bb1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/19/2015 10:48:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenspeicher _76bb1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/19/2015 10:48:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Kontaktdaten_76bb1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/19/2015 10:48:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_76bb1" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/19/2015 10:48:31 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (11/19/2015 10:10:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenzugriff_6ce8373" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/19/2015 10:10:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Benutzerdatenspeicher _6ce8373" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/19/2015 10:10:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Kontaktdaten_6ce8373" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/19/2015 10:10:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Synchronisierungshost_6ce8373" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/19/2015 10:10:17 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
CodeIntegrity:
===================================
Date: 2015-11-19 22:11:13.286
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2015-11-15 15:32:49.796
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2015-11-13 20:47:26.394
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2015-11-13 20:38:12.584
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2015-11-13 20:37:40.024
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2015-11-13 20:32:18.479
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i5-5257U CPU @ 2.70GHz
Prozentuale Nutzung des RAM: 36%
Installierter physikalischer RAM: 6062.84 MB
Verfügbarer physikalischer RAM: 3862.59 MB
Summe virtueller Speicher: 7726.84 MB
Verfügbarer virtueller Speicher: 5526.07 MB
==================== Laufwerke ================================
Drive c: (Boot) (Fixed) (Total:117.53 GB) (Free:72.55 GB) NTFS
Drive d: (Data) (Fixed) (Total:871.51 GB) (Free:867 GB) NTFS
Drive e: (Recover) (Fixed) (Total:60 GB) (Free:40.36 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 9CD1CACC)
Partition 1: (Not Active) - (Size=871.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=60 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 119.2 GB) (Disk ID: 9CD1CAD6)
Partition: GPT.
==================== Ende von Addition.txt ============================ MfG
Rob Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:19-11-2015
durchgeführt von Robert (Administrator) auf ROBERT-LAPTOP (20-11-2015 12:06:41)
Gestartet von C:\Users\rober\Desktop
Geladene Profile: Robert (Verfügbare Profile: Robert)
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
() C:\Program Files (x86)\PHotkey\PGFNEXSrv.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes) D:\Programme\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) D:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.6.1180.0\McCSPServiceHost.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(Malwarebytes) D:\Programme\Malwarebytes Anti-Malware\mbam.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Program Files (x86)\PHotkey\Atouch64.exe
() C:\Program Files (x86)\PHotkey\POsd.exe
() C:\Program Files (x86)\PHotkey\GPMTray.exe
() C:\Program Files (x86)\PHotkey\KeyboardMonitorTool.exe
(Dolby Laboratories Inc.) C:\Program Files\Dolby Digital Plus\ddp.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\Core\mchost.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.13005.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13876952 2015-04-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3352808 2015-11-13] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [110008 2015-05-26] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [499128 2015-05-26] (CyberLink Corp.)
HKLM-x32\...\Run: [PowerDVD12Agent] => "C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe"
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2620728 2015-07-22] (Malwarebytes Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-10-30] (Microsoft Corporation)
Startup: C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneDrive for Business.lnk [2015-10-30]
ShortcutTarget: OneDrive for Business.lnk -> C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE (Microsoft Corporation)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{356e4e92-d547-4176-bafd-e42f46454a14}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3938361683-1663457597-2333501448-1005\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3938361683-1663457597-2333501448-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCTE
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-10-30] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-30] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-10-30] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-19] (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-10-30] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-19] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-10-30] (Microsoft Corporation)
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll [2015-10-30] (Microsoft Corporation)
Handler-x32: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll [2015-10-30] (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2015-09-28] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2015-09-28] (McAfee, Inc.)
FireFox:
========
FF ProfilePath: C:\Users\rober\AppData\Roaming\Mozilla\Firefox\Profiles\hej9hy6t.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-19] ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-09-28] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-19] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-19] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-09-28] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-10-30] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-10-29] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Extension: NoScript - C:\Users\rober\AppData\Roaming\Mozilla\Firefox\Profiles\hej9hy6t.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-10-29]
FF Extension: Adblock Plus - C:\Users\rober\AppData\Roaming\Mozilla\Firefox\Profiles\hej9hy6t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-10-29]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2015-11-02] [ist nicht signiert]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2780856 2015-10-07] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144104 2015-11-13] (ELAN Microelectronics Corp.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-24] (Intel Corporation)
R2 ibtsiva; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [150256 2015-06-09] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-11-13] (Intel Corporation)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [713016 2015-07-22] (Malwarebytes Corporation)
R2 MBAMScheduler; D:\Programme\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; D:\Programme\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [783120 2015-09-28] (McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [338208 2015-03-20] (McAfee, Inc.)
R2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.6.1180.0\McCSPServiceHost.exe [1694152 2015-09-01] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [639456 2015-08-11] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
S3 MessagingService; C:\Windows\System32\MessagingService.dll [52736 2015-10-30] (Microsoft Corporation)
S3 MessagingService_2f57ec; C:\WINDOWS\system32\svchost.exe [43944 2015-10-30] (Microsoft Corporation)
S3 MessagingService_2f57ec; C:\WINDOWS\SysWOW64\svchost.exe [37256 2015-10-30] (Microsoft Corporation)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-07-31] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [376264 2015-08-10] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [254792 2015-07-31] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-06-12] ()
R2 OneSyncSvc_2f57ec; C:\WINDOWS\system32\svchost.exe [43944 2015-10-30] (Microsoft Corporation)
R2 OneSyncSvc_2f57ec; C:\WINDOWS\SysWOW64\svchost.exe [37256 2015-10-30] (Microsoft Corporation)
R2 PGFNEXSrv; C:\Program Files (x86)\PHotkey\PGFNEXSrv.exe [135680 2014-08-07] () [Datei ist nicht signiert]
R3 PimIndexMaintenanceSvc_2f57ec; C:\WINDOWS\system32\svchost.exe [43944 2015-10-30] (Microsoft Corporation)
R3 PimIndexMaintenanceSvc_2f57ec; C:\WINDOWS\SysWOW64\svchost.exe [37256 2015-10-30] (Microsoft Corporation)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-15] ()
S3 TieringEngineService; C:\Windows\system32\TieringEngineService.exe [290304 2015-10-30] (Microsoft Corporation)
S4 tzautoupdate; C:\Windows\system32\tzautoupdate.dll [87040 2015-11-13] (Microsoft Corporation)
R3 UnistoreSvc_2f57ec; C:\WINDOWS\System32\svchost.exe [43944 2015-10-30] (Microsoft Corporation)
R3 UnistoreSvc_2f57ec; C:\WINDOWS\SysWOW64\svchost.exe [37256 2015-10-30] (Microsoft Corporation)
R3 UserDataSvc_2f57ec; C:\WINDOWS\system32\svchost.exe [43944 2015-10-30] (Microsoft Corporation)
R3 UserDataSvc_2f57ec; C:\WINDOWS\SysWOW64\svchost.exe [37256 2015-10-30] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831200 2015-06-12] (Intel® Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 bcmfn; C:\Windows\System32\drivers\bcmfn.sys [9728 2015-10-30] (Windows (R) Win 7 DDK provider)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [80768 2015-08-10] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R3 clwvd6; C:\Windows\system32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2015-07-22] ()
R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [30808 2015-11-13] (ELAN Microelectronic Corp.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc.)
S3 iai2c; C:\Windows\System32\drivers\iai2c.sys [81408 2015-10-30] (Intel(R) Corporation)
S3 iaLPSS2i_I2C; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [165888 2015-10-30] (Intel Corporation)
R3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [46856 2015-06-15] (Intel Corporation)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [263952 2015-11-13] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-20] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [183584 2015-06-12] (Intel Corporation)
R2 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [413432 2015-08-10] (McAfee, Inc.)
R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [349096 2015-08-10] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [82072 2015-08-10] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [495856 2015-08-10] (McAfee, Inc.)
R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [839376 2015-08-10] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [537408 2015-08-12] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [111256 2015-08-12] (McAfee, Inc.)
R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [244024 2015-08-10] (McAfee, Inc.)
R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3776792 2015-06-22] (Intel Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
R3 PegaRadioSwitch; C:\Windows\System32\drivers\PegaRadioSwitch.sys [33560 2015-06-05] (Windows (R) Win 7 DDK provider)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [411712 2015-05-19] (Realsil Semiconductor Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [45056 2015-10-30] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-11-20 12:06 - 2015-11-20 12:06 - 00019853 _____ C:\Users\rober\Desktop\FRST.txt
2015-11-19 22:48 - 2015-11-20 12:05 - 00000000 ____D C:\Users\rober\Desktop\Scans
2015-11-19 22:10 - 2015-11-19 22:10 - 00003398 _____ C:\WINDOWS\PFRO.log
2015-11-19 22:00 - 2015-11-20 12:06 - 00000000 ____D C:\FRST
2015-11-19 21:58 - 2015-11-19 21:58 - 00000000 _____ C:\Users\rober\defogger_reenable
2015-11-19 21:41 - 2015-11-19 22:01 - 02020352 _____ (Farbar) C:\Users\rober\Desktop\FRST64.exe
2015-11-19 20:46 - 2015-11-19 20:59 - 00000000 ____D C:\ProgramData\Oracle
2015-11-19 20:46 - 2015-11-19 20:59 - 00000000 ____D C:\Program Files (x86)\Java
2015-11-19 20:46 - 2015-11-19 20:58 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-11-19 20:46 - 2015-11-19 20:58 - 00000000 ____D C:\Users\rober\.oracle_jre_usage
2015-11-19 20:46 - 2015-11-19 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-19 20:46 - 2015-11-19 20:46 - 00000000 ____D C:\Users\rober\AppData\Roaming\Sun
2015-11-19 20:46 - 2015-11-19 20:46 - 00000000 ____D C:\Users\rober\AppData\LocalLow\Sun
2015-11-19 20:46 - 2015-11-19 20:46 - 00000000 ____D C:\Users\rober\AppData\LocalLow\Oracle
2015-11-19 19:59 - 2015-11-20 12:00 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-19 19:59 - 2015-11-19 19:59 - 00000792 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-19 19:59 - 2015-11-19 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-19 19:59 - 2015-11-19 19:59 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-11-19 19:59 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-11-19 19:59 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-11-19 19:59 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-11-19 19:50 - 2015-11-20 12:01 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-19 19:50 - 2015-11-19 19:50 - 00003860 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-11-19 18:28 - 2015-11-19 18:28 - 00000000 ____D C:\ProgramData\VsTelemetry
2015-11-19 16:38 - 2015-11-13 07:55 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2015-11-19 16:38 - 2015-11-13 07:54 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-19 16:38 - 2015-11-13 07:51 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-11-19 16:38 - 2015-11-13 07:51 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-11-19 16:38 - 2015-11-13 07:51 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2015-11-19 16:38 - 2015-11-13 07:43 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-11-19 16:38 - 2015-11-13 07:43 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-11-19 16:38 - 2015-11-13 07:43 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-11-19 16:38 - 2015-11-13 07:43 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-11-19 16:38 - 2015-11-13 07:43 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-11-19 16:38 - 2015-11-13 07:43 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-11-19 16:38 - 2015-11-13 07:43 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2015-11-19 16:38 - 2015-11-13 07:42 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-11-19 16:38 - 2015-11-13 07:42 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-11-19 16:38 - 2015-11-13 07:42 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-11-19 16:38 - 2015-11-13 07:41 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-11-19 16:38 - 2015-11-13 07:41 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-19 16:38 - 2015-11-13 07:33 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2015-11-19 16:38 - 2015-11-13 07:33 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-11-19 16:38 - 2015-11-13 07:33 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-11-19 16:38 - 2015-11-13 07:32 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2015-11-19 16:38 - 2015-11-13 07:21 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-11-19 16:38 - 2015-11-13 07:21 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-11-19 16:38 - 2015-11-13 07:21 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-11-19 16:38 - 2015-11-13 07:21 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-11-19 16:38 - 2015-11-13 07:21 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-11-19 16:38 - 2015-11-13 07:21 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2015-11-19 16:38 - 2015-11-13 07:21 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-11-19 16:38 - 2015-11-13 07:21 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2015-11-19 16:38 - 2015-11-13 07:19 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-19 16:38 - 2015-11-13 07:18 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-11-19 16:38 - 2015-11-13 07:09 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2015-11-19 16:38 - 2015-11-13 07:07 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-11-19 16:38 - 2015-11-13 07:06 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-11-19 16:38 - 2015-11-13 07:06 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-11-19 16:38 - 2015-11-13 07:05 - 16984064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-11-19 16:38 - 2015-11-13 07:05 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-11-19 16:38 - 2015-11-13 07:05 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-11-19 16:38 - 2015-11-13 07:05 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-11-19 16:38 - 2015-11-13 07:05 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2015-11-19 16:38 - 2015-11-13 07:04 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-11-19 16:38 - 2015-11-13 07:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2015-11-19 16:38 - 2015-11-13 07:04 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2015-11-19 16:38 - 2015-11-13 07:04 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-11-19 16:38 - 2015-11-13 07:03 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2015-11-19 16:38 - 2015-11-13 07:03 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-11-19 16:38 - 2015-11-13 07:02 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-11-19 16:38 - 2015-11-13 07:02 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-11-19 16:38 - 2015-11-13 07:01 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-11-19 16:38 - 2015-11-13 07:00 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2015-11-19 16:38 - 2015-11-13 07:00 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2015-11-19 16:38 - 2015-11-13 07:00 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2015-11-19 16:38 - 2015-11-13 06:59 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2015-11-19 16:38 - 2015-11-13 06:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-11-19 16:38 - 2015-11-13 06:58 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-11-19 16:38 - 2015-11-13 06:57 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2015-11-19 16:38 - 2015-11-13 06:57 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-11-19 16:38 - 2015-11-13 06:56 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-11-19 16:38 - 2015-11-13 06:56 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-11-19 16:38 - 2015-11-13 06:56 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-11-19 16:38 - 2015-11-13 06:55 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-11-19 16:38 - 2015-11-13 06:55 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2015-11-19 16:38 - 2015-11-13 06:54 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-11-19 16:38 - 2015-11-13 06:53 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2015-11-19 16:38 - 2015-11-13 06:53 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-11-19 16:38 - 2015-11-13 06:50 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-19 16:38 - 2015-11-13 06:50 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-19 16:38 - 2015-11-13 06:49 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-11-19 16:38 - 2015-11-13 06:49 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-19 16:38 - 2015-11-13 06:45 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-19 16:38 - 2015-11-13 06:41 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2015-11-19 16:38 - 2015-11-13 06:40 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2015-11-19 16:38 - 2015-11-13 06:40 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2015-11-19 16:38 - 2015-11-13 06:39 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-11-19 16:38 - 2015-11-13 06:39 - 01998848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-11-19 16:38 - 2015-11-13 06:38 - 13017088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-11-19 16:38 - 2015-11-13 06:37 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2015-11-19 16:38 - 2015-11-13 06:34 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2015-11-19 16:38 - 2015-11-13 06:33 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-11-19 16:38 - 2015-11-13 06:32 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2015-11-19 16:38 - 2015-11-13 06:30 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-11-19 16:38 - 2015-11-13 06:30 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-11-19 16:38 - 2015-11-13 06:29 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-11-19 16:38 - 2015-11-13 06:28 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-11-19 16:38 - 2015-11-13 06:27 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2015-11-19 16:38 - 2015-11-13 06:23 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-19 16:38 - 2015-11-13 06:19 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-11-19 16:38 - 2015-11-13 06:17 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-19 16:38 - 2015-11-13 06:15 - 01707008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2015-11-15 15:39 - 2015-11-15 15:39 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-11-13 20:52 - 2015-11-13 20:52 - 00000424 _____ C:\Users\rober\Desktop\Dieser PC.lnk
2015-11-13 20:44 - 2015-11-13 20:44 - 00000000 ____D C:\Users\rober\AppData\Local\ActiveSync
2015-11-13 20:42 - 2015-11-13 20:42 - 00000020 ___SH C:\Users\rober\ntuser.ini
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Vorlagen
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Startmenü
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Programme
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\ProgramData\Vorlagen
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\ProgramData\Startmenü
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\ProgramData\Dokumente
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2015-11-13 20:39 - 2015-11-13 20:39 - 00000000 _SHDL C:\Dokumente und Einstellungen
2015-11-13 20:38 - 2015-11-19 22:11 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-13 20:38 - 2015-11-13 20:38 - 00022960 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-11-13 20:36 - 2015-11-13 20:36 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-11-13 20:34 - 2015-11-19 21:58 - 00000000 ____D C:\Users\rober
2015-11-13 20:34 - 2015-11-13 20:42 - 00000000 ___RD C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-11-13 20:34 - 2015-11-13 20:36 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Vorlagen
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Startmenü
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Netzwerkumgebung
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Lokale Einstellungen
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Eigene Dateien
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Druckumgebung
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Documents\Eigene Musik
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Documents\Eigene Bilder
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\AppData\Local\Verlauf
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\AppData\Local\Anwendungsdaten
2015-11-13 20:34 - 2015-11-13 20:34 - 00000000 _SHDL C:\Users\rober\Anwendungsdaten
2015-11-13 20:34 - 2015-10-30 08:24 - 00000000 __RSD C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-11-13 20:34 - 2015-10-30 08:24 - 00000000 ___RD C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-11-13 20:34 - 2015-10-30 08:24 - 00000000 ___RD C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-11-13 20:34 - 2015-10-30 08:24 - 00000000 ____D C:\Users\rober\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-11-13 20:34 - 2015-10-30 08:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-11-13 20:33 - 2015-11-20 12:00 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-13 20:33 - 2015-11-13 20:36 - 00000000 ____D C:\Program Files\Elantech
2015-11-13 20:33 - 2015-11-13 20:33 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2015-11-13 20:33 - 2015-11-13 20:33 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_ETD_01011.Wdf
2015-11-13 20:33 - 2015-11-13 20:33 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-11-13 20:33 - 2015-11-13 20:33 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2015-11-13 20:33 - 2015-11-13 20:33 - 00000000 ____D C:\Program Files\Realtek
2015-11-13 20:33 - 2015-11-13 20:12 - 00086528 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2015-11-13 20:33 - 2015-11-13 20:12 - 00082432 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2015-11-13 20:32 - 2015-11-15 17:01 - 00012848 _____ C:\WINDOWS\setupact.log
2015-11-13 20:32 - 2015-11-13 20:35 - 00000000 ____D C:\Program Files\Intel
2015-11-13 20:32 - 2015-11-13 20:32 - 00027705 _____ C:\WINDOWS\system32\NetSetupMig.log
2015-11-13 20:32 - 2015-11-13 20:32 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-11-13 20:31 - 2015-11-19 22:11 - 00349296 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-13 20:31 - 2015-11-13 20:39 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-13 20:29 - 2015-11-13 20:29 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 13376512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 12120064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-13 20:29 - 2015-11-13 20:29 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2015-11-13 20:29 - 2015-11-13 20:29 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2015-11-13 20:29 - 2015-11-13 20:29 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-13 20:29 - 2015-11-13 20:29 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-13 20:29 - 2015-11-13 20:29 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-13 20:29 - 2015-11-13 20:29 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-13 20:29 - 2015-11-13 20:29 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-13 20:29 - 2015-11-13 20:29 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-11-13 20:29 - 2015-11-13 20:29 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2015-11-13 20:29 - 2015-11-13 20:29 - 00000000 ____D C:\Windows.old
2015-11-13 20:28 - 2015-10-29 19:43 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2015-11-13 20:28 - 2015-10-29 19:43 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-11-13 20:28 - 2015-10-29 19:41 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-11-13 20:28 - 2015-10-29 19:25 - 06359040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2015-11-13 20:28 - 2015-10-29 19:24 - 04847616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2015-11-13 20:25 - 2015-11-13 20:25 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-11-13 20:24 - 2015-11-13 20:24 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2015-11-13 20:24 - 2015-11-13 20:24 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-11-13 20:24 - 2015-11-13 20:24 - 00000000 ____D C:\Program Files\MSBuild
2015-11-13 20:24 - 2015-11-13 20:24 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-11-13 20:24 - 2015-11-13 20:24 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-11-13 20:23 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-11-13 20:23 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-13 20:23 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-11-13 20:23 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-11-13 20:23 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-11-13 20:23 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 36681912 _____ (Intel Corporation) C:\WINDOWS\system32\igdumdim64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 35768808 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumdim32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 30404056 _____ (Intel Corporation) C:\WINDOWS\system32\igd11dxva64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 29613040 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd11dxva32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 29084160 _____ (Intel Corporation) C:\WINDOWS\system32\common_clang64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 19844096 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\common_clang32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 13727296 _____ (Intel Corporation) C:\WINDOWS\system32\igd10iumd64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 13211648 _____ (Intel Corporation) C:\WINDOWS\system32\ig8icd64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 12880160 _____ (Intel Corporation) C:\WINDOWS\system32\igc64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 11276968 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10iumd32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 10528136 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igc32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 10032128 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig8icd32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 06741482 _____ C:\WINDOWS\system32\igdclbif.bin
2015-11-13 20:12 - 2015-11-13 20:12 - 06389688 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2015-11-13 20:12 - 2015-11-13 20:12 - 06305696 _____ (Intel Corporation) C:\WINDOWS\system32\igdusc64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 05467648 _____ (Intel Corporation) C:\WINDOWS\system32\igdmcl64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 05245440 _____ (Intel Corporation) C:\WINDOWS\system32\GfxResources.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 05121136 _____ (Intel Corporation) C:\WINDOWS\system32\igd12umd64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 05092320 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd12umd32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 04841488 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdusc32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 04443136 _____ (Intel Corporation) C:\WINDOWS\system32\igdrcl64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 03873280 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdrcl32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 03801600 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmcl32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 02813952 _____ C:\WINDOWS\system32\iglhxa64.cpa
2015-11-13 20:12 - 2015-11-13 20:12 - 02028032 _____ (Intel Corporation) C:\WINDOWS\system32\igfxLHM.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 01858632 _____ (Intel Corporation) C:\WINDOWS\system32\igdmd64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 01767992 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 01765408 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 01565696 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 01456408 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmd32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 01216000 _____ (Intel Corporation) C:\WINDOWS\system32\igdfcl64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 01156608 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 01008016 _____ C:\WINDOWS\system32\igfxSDK.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00970752 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdfcl32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00927120 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv4_0.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00923536 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv2_0.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00803113 _____ C:\WINDOWS\system32\DisplayAudiox64.cab
2015-11-13 20:12 - 2015-11-13 20:12 - 00723456 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDH.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00641530 _____ C:\WINDOWS\system32\FilmModeDetection.wmv
2015-11-13 20:12 - 2015-11-13 20:12 - 00624128 _____ (Intel Corporation) C:\WINDOWS\system32\MetroIntelGenericUIFramework.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00589712 _____ C:\WINDOWS\system32\IntelCpHDCPSvc.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00519056 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUMS64.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00511260 _____ C:\WINDOWS\system32\cp_resources.bin
2015-11-13 20:12 - 2015-11-13 20:12 - 00448912 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUIEx.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00425472 _____ (Intel Corporation) C:\WINDOWS\system32\igdbcl64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00403671 _____ C:\WINDOWS\system32\ImageStabilization.wmv
2015-11-13 20:12 - 2015-11-13 20:12 - 00397824 _____ (Intel Corporation) C:\WINDOWS\system32\IntelOpenCL64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00396688 _____ C:\WINDOWS\system32\igfxTray.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00386048 _____ (Intel Corporation) C:\WINDOWS\system32\igfxOSP.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00375173 _____ C:\WINDOWS\system32\ColorImageEnhancement.wmv
2015-11-13 20:12 - 2015-11-13 20:12 - 00373248 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdbcl32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00353280 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDI.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00351120 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCUIService.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00331808 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiMCComp64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00328080 _____ (Intel Corporation) C:\WINDOWS\system32\igfxEM.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00313888 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUtils64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00300032 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelOpenCL32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00284280 _____ (Intel Corporation) C:\WINDOWS\system32\igd10idpp64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00283024 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00269360 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10idpp32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00263952 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\ibtusb.sys
2015-11-13 20:12 - 2015-11-13 20:12 - 00256000 _____ C:\WINDOWS\system32\igfxCPL.cpl
2015-11-13 20:12 - 2015-11-13 20:12 - 00249232 _____ (Intel Corporation) C:\WINDOWS\system32\igfxHK.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00243200 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDTCM.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00242448 _____ (Intel Corporation) C:\WINDOWS\system32\ibtproppage.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00220432 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00219024 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00214416 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyApp.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00213904 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyAppv2_0.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00206848 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4256.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00200856 _____ (Intel Corporation) C:\WINDOWS\system32\igdde64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00184352 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00172032 _____ (Intel Corporation) C:\WINDOWS\system32\igdail64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00163776 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00162752 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00160680 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdde32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00157072 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2015-11-13 20:12 - 2015-11-13 20:12 - 00153600 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdail32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00143904 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiLogServer64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00141080 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00140056 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00090112 _____ ( ) C:\WINDOWS\system32\igfxSDKLibv2_0.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00086528 _____ (Khronos Group) C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00086016 _____ C:\WINDOWS\system32\igfxCUIServicePS.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00082944 _____ ( ) C:\WINDOWS\system32\igfxSDKLib.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00082432 _____ (Khronos Group) C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00073728 _____ ( ) C:\WINDOWS\system32\igfxDHLibv2_0.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00064512 _____ ( ) C:\WINDOWS\system32\igfxDHLib.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00044025 _____ C:\WINDOWS\system32\iglhxo64.vp
2015-11-13 20:12 - 2015-11-13 20:12 - 00043816 _____ C:\WINDOWS\system32\iglhxc64_dev.vp
2015-11-13 20:12 - 2015-11-13 20:12 - 00043494 _____ C:\WINDOWS\system32\iglhxc64.vp
2015-11-13 20:12 - 2015-11-13 20:12 - 00043298 _____ C:\WINDOWS\system32\iglhxg64_dev.vp
2015-11-13 20:12 - 2015-11-13 20:12 - 00043256 _____ C:\WINDOWS\system32\iglhxg64.vp
2015-11-13 20:12 - 2015-11-13 20:12 - 00042079 _____ C:\WINDOWS\system32\iglhxo64_dev.vp
2015-11-13 20:12 - 2015-11-13 20:12 - 00036616 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00035328 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00011776 _____ ( ) C:\WINDOWS\system32\igfxDILib.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00011264 _____ ( ) C:\WINDOWS\system32\igfxDILibv2_0.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00010240 _____ ( ) C:\WINDOWS\system32\igfxEMLibv2_0.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00010240 _____ ( ) C:\WINDOWS\system32\igfxEMLib.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00005120 _____ ( ) C:\WINDOWS\system32\igfxLHMLibv2_0.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00005120 _____ ( ) C:\WINDOWS\system32\igfxLHMLib.dll
2015-11-13 20:12 - 2015-11-13 20:12 - 00004682 _____ C:\WINDOWS\system32\iglhxs64.vp
2015-11-13 20:12 - 2015-11-13 20:12 - 00001125 _____ C:\WINDOWS\system32\iglhxa64.vp
2015-11-13 19:30 - 2015-11-13 19:30 - 00589912 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\Drivers\ETD.sys
2015-11-13 19:30 - 2015-11-13 19:30 - 00168168 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\ETDCoInstaller15006.dll
2015-11-07 17:43 - 2015-11-07 17:43 - 00000000 ____D C:\Users\rober\AppData\Local\Macromedia
2015-11-02 23:32 - 2015-11-04 14:28 - 00000000 ____D C:\Users\rober\AppData\Roaming\Processing
2015-11-02 18:50 - 2015-11-02 18:50 - 00000000 ____D C:\Users\rober\AppData\LocalLow\Adobe
2015-11-02 18:50 - 2015-11-02 18:50 - 00000000 ____D C:\Users\rober\AppData\Local\CEF
2015-11-02 18:48 - 2015-11-13 20:38 - 00002954 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-02 18:47 - 2015-11-02 23:57 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-02 18:47 - 2015-11-02 18:50 - 00000000 ____D C:\ProgramData\Adobe
2015-11-02 18:47 - 2015-11-02 18:47 - 00002128 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-11-02 18:47 - 2015-11-02 18:47 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-10-31 19:08 - 2015-10-31 19:08 - 00000000 ____D C:\Users\rober\Documents\Avatar
2015-10-31 19:07 - 2015-10-31 19:07 - 00000000 ____D C:\Users\rober\AppData\Roaming\CyberLink
2015-10-31 13:26 - 2015-10-31 13:26 - 00000000 ___HD C:\OneDriveTemp
2015-10-30 20:27 - 2015-11-13 20:17 - 00000000 ___HD C:\$WINDOWS.~BT
2015-10-30 19:45 - 2015-10-30 08:19 - 00031816 _____ C:\WINDOWS\Core.xml
2015-10-30 19:44 - 2015-11-13 20:27 - 00000000 ____D C:\Program Files\Windows Journal
2015-10-30 19:44 - 2015-10-30 19:44 - 00000000 __RHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
2015-10-30 19:44 - 2015-10-30 19:44 - 00000000 ____D C:\WINDOWS\ShellNew
2015-10-30 19:36 - 2015-11-13 20:28 - 00000000 ____D C:\WINDOWS\OCR
2015-10-30 19:36 - 2015-10-30 19:36 - 00000000 ____D C:\WINDOWS\SKB
2015-10-30 19:35 - 2015-11-19 22:18 - 00777804 _____ C:\WINDOWS\system32\perfh007.dat
2015-10-30 19:35 - 2015-11-19 22:18 - 00156080 _____ C:\WINDOWS\system32\perfc007.dat
2015-10-30 19:35 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2015-10-30 19:35 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2015-10-30 19:35 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2015-10-30 19:35 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2015-10-30 19:35 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\system32\winrm
2015-10-30 19:35 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\system32\WCN
2015-10-30 19:35 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\system32\slmgr
2015-10-30 19:35 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2015-10-30 19:35 - 2015-10-30 19:35 - 00305634 _____ C:\WINDOWS\system32\perfi007.dat
2015-10-30 19:35 - 2015-10-30 19:35 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat
2015-10-30 19:35 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2015-10-30 19:35 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\SysWOW64\de
2015-10-30 19:35 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2015-10-30 19:35 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\system32\de
2015-10-30 19:35 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\system32\0409
2015-10-30 19:35 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\DigitalLocker
2015-10-30 13:07 - 2015-10-30 13:07 - 00000000 __RHD C:\MSOCache
2015-10-30 09:13 - 2015-10-30 09:13 - 00028672 ___SH C:\WINDOWS\system32\config\BCD-Template.LOG
2015-10-30 08:26 - 2015-11-03 01:12 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-30 08:26 - 2015-11-03 01:12 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-30 08:26 - 2015-10-30 08:26 - 00000000 ____D C:\WINDOWS\Setup
2015-10-30 08:25 - 2015-11-13 20:36 - 00003949 _____ C:\WINDOWS\DtcInstall.log
2015-10-30 08:24 - 2015-11-20 12:00 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-30 08:24 - 2015-11-19 22:10 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-30 08:24 - 2015-11-19 22:10 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-10-30 08:24 - 2015-11-19 22:10 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-30 08:24 - 2015-11-19 22:10 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-30 08:24 - 2015-11-19 22:10 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-30 08:24 - 2015-11-19 22:10 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-30 08:24 - 2015-11-19 16:41 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-30 08:24 - 2015-11-16 22:16 - 00000000 ____D C:\WINDOWS\rescache
2015-10-30 08:24 - 2015-11-15 15:25 - 00000000 ____D C:\WINDOWS\appcompat
2015-10-30 08:24 - 2015-11-13 20:42 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-10-30 08:24 - 2015-11-13 20:42 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-10-30 08:24 - 2015-11-13 20:39 - 00000000 ____D C:\Program Files\Windows NT
2015-10-30 08:24 - 2015-11-13 20:38 - 00000000 __RHD C:\Users\Public\Libraries
2015-10-30 08:24 - 2015-11-13 20:38 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-10-30 08:24 - 2015-11-13 20:38 - 00000000 ____D C:\WINDOWS\Registration
2015-10-30 08:24 - 2015-11-13 20:36 - 00000000 __RSD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-30 08:24 - 2015-11-13 20:36 - 00000000 __RSD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-30 08:24 - 2015-11-13 20:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-30 08:24 - 2015-11-13 20:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-30 08:24 - 2015-11-13 20:35 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-10-30 08:24 - 2015-11-13 20:35 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2015-10-30 08:24 - 2015-11-13 20:35 - 00000000 ____D C:\WINDOWS\system32\spool
2015-10-30 08:24 - 2015-11-13 20:35 - 00000000 ____D C:\ProgramData\USOPrivate
2015-10-30 08:24 - 2015-11-13 20:35 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-30 08:24 - 2015-11-13 20:34 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-10-30 08:24 - 2015-11-13 20:31 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ___SD C:\WINDOWS\system32\dsc
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ____D C:\WINDOWS\system32\migwiz
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ____D C:\Program Files\Windows Defender
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2015-10-30 08:24 - 2015-11-13 20:27 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-10-30 08:24 - 2015-11-13 20:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2015-10-30 08:24 - 2015-11-13 20:24 - 00000000 ____D C:\WINDOWS\system32\MUI
2015-10-30 08:24 - 2015-10-30 19:44 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-30 08:24 - 2015-10-30 19:44 - 00000000 ____D C:\WINDOWS\Web
2015-10-30 08:24 - 2015-10-30 19:44 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-10-30 08:24 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2015-10-30 08:24 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2015-10-30 08:24 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-30 08:24 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\system32\setup
2015-10-30 08:24 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\system32\Com
2015-10-30 08:24 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\IME
2015-10-30 08:24 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\Help
2015-10-30 08:24 - 2015-10-30 19:35 - 00000000 ____D C:\Program Files\Common Files\System
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 __RSD C:\WINDOWS\Media
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___SD C:\Program Files\WindowsPowerShell
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___SD C:\Program Files (x86)\WindowsPowerShell
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DesktopTileResources
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Vss
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\tracing
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\TAPI
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\WindowsPowerShell
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\uk-UA
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\th-TH
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\sru
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\sr-Latn-RS
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\sr-Latn-CS
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\sppui
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\spp
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Speech_OneCore
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Speech
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\sl-SI
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\sk-SK
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\ro-RO
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\restore
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Recovery
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\RasToast
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\networklist
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MSDRM
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Licenses
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\hr-HR
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\he-IL
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\fr-CA
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\es-MX
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\bg-BG
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\ar-SA
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SystemResources
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\winevt
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WindowsPowerShell
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\uk-UA
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\th-TH
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-RS
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-CS
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\sppui
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\spp
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Speech_OneCore
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Speech
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\sl-SI
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\sk-SK
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\ro-RO
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\restore
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\RasToast
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\ras
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\networklist
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MSDRM
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Licenses
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\IME
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\icsxml
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\ias
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\hr-HR
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\he-IL
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\fr-CA
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\et-EE
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\es-MX
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\en-GB
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\bg-BG
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\ar-SA
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\System
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Speech_OneCore
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Speech
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\security
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\schemas
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SchCache
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Resources
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\PLA
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Performance
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\InputMethod
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Globalization
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Cursors
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Branding
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\addins
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\Comms
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\Services
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows NT
2015-10-30 08:24 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2015-10-30 08:24 - 2015-10-30 08:21 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2015-10-30 08:24 - 2015-10-30 08:21 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2015-10-30 08:24 - 2015-10-30 08:21 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2015-10-30 08:24 - 2015-10-30 08:21 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2015-10-30 08:24 - 2015-10-30 08:21 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2015-10-30 08:24 - 2015-10-30 08:21 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat
2015-10-30 08:24 - 2015-10-30 08:21 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat
2015-10-30 08:24 - 2015-10-30 08:21 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2015-10-30 08:24 - 2015-10-30 08:21 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat
2015-10-30 08:24 - 2015-10-30 08:21 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat
2015-10-30 08:24 - 2015-10-30 08:21 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2015-10-30 08:24 - 2015-10-30 08:21 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2015-10-30 08:24 - 2015-10-30 08:21 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2015-10-30 08:20 - 2015-10-30 08:20 - 00926208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSRESM.dll
2015-10-30 08:20 - 2015-10-30 08:20 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOMEX.dll
2015-10-30 08:20 - 2015-10-30 08:20 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
2015-10-30 08:20 - 2015-10-30 08:20 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spp.dll
2015-10-30 08:20 - 2015-10-30 08:20 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOM.dll
2015-10-30 08:20 - 2015-10-30 08:20 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxproxy.dll
2015-10-30 08:20 - 2015-10-30 08:20 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinFax.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 02535424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkAnalysis.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsCpl.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsCpl.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00669696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00501760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00274224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpendp.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2015-10-30 08:19 - 2015-10-30 19:44 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsClassExtension.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfdts.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rfxvmt.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorPerformanceEvents.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\jnwmon.dll
2015-10-30 08:19 - 2015-10-30 19:44 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorCustomAdbAlgorithm.dll
2015-10-30 08:19 - 2015-10-30 19:36 - 12039680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0007.dll
2015-10-30 08:19 - 2015-10-30 19:36 - 12039680 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0007.dll
2015-10-30 08:19 - 2015-10-30 19:36 - 11602944 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0007.dll
2015-10-30 08:19 - 2015-10-30 19:36 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0007.dll
2015-10-30 08:19 - 2015-10-30 19:36 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0007.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 28851224 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 28083144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 12585984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 09375232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2015-10-30 08:19 - 2015-10-30 08:19 - 09375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2015-10-30 08:19 - 2015-10-30 08:19 - 06971392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 04830896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 04646400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2015-10-30 08:19 - 2015-10-30 08:19 - 04238848 _____ (Microsoft) C:\WINDOWS\SysWOW64\GameUXLegacyGDFs.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 04238848 _____ (Microsoft) C:\WINDOWS\system32\GameUXLegacyGDFs.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 04170240 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 03750912 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-30 08:19 - 2015-10-30 08:19 - 03573248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll |