der zweite Teil Code:
2017-07-18 22:09 - 2017-07-18 22:09 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll
2017-07-18 22:09 - 2017-07-18 22:09 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2017-07-18 22:09 - 2017-07-18 22:09 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-07-18 22:09 - 2017-07-18 22:09 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2017-07-18 22:08 - 2017-07-18 22:08 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-07-18 22:08 - 2017-07-18 22:08 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe
2017-07-18 22:08 - 2017-07-18 22:08 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys
2017-07-18 22:08 - 2017-07-18 22:08 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-07-18 22:08 - 2017-07-18 22:08 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-07-18 22:07 - 2017-07-18 22:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-07-18 22:03 - 2017-03-17 23:00 - 05739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2017-07-18 22:03 - 2017-03-17 22:59 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2017-07-18 22:03 - 2017-03-17 22:48 - 06348288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2017-07-18 22:03 - 2017-03-17 22:43 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2017-07-18 22:03 - 2017-03-17 22:35 - 05484544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2017-07-18 22:01 - 2017-07-18 22:01 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-07-18 22:01 - 2017-07-18 21:28 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\WINDOWS\system32\msmq
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\Program Files\MSBuild
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-07-18 21:57 - 2017-07-18 21:57 - 00000000 ____D C:\inetpub
2017-07-18 21:56 - 2017-07-18 21:56 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-07-18 21:56 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-07-18 21:56 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-07-18 21:56 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-07-18 21:55 - 2017-07-18 21:55 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-07-18 21:55 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-07-18 21:55 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-07-18 21:55 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-07-18 21:47 - 2017-07-18 21:47 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2017-07-18 21:46 - 2017-07-18 21:58 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-07-18 21:40 - 2017-07-18 21:40 - 00000000 ____D C:\ProgramData\USOShared
2017-07-18 21:35 - 2017-07-19 09:16 - 00000000 ____D C:\Users\Andrea und Hans-Jörg
2017-07-18 21:35 - 2017-07-18 22:22 - 00000000 ____D C:\Users\simon
2017-07-18 21:35 - 2017-07-18 22:14 - 00000000 ____D C:\Users\DefaultAppPool
2017-07-18 21:35 - 2017-07-18 22:09 - 00000000 ____D C:\Users\otto
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Vorlagen
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Startmenü
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Netzwerkumgebung
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Lokale Einstellungen
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Eigene Dateien
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Druckumgebung
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Documents\Eigene Videos
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Documents\Eigene Musik
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Documents\Eigene Bilder
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\AppData\Local\Verlauf
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\AppData\Local\Anwendungsdaten
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\simon\Anwendungsdaten
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Vorlagen
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Startmenü
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Netzwerkumgebung
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Lokale Einstellungen
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Eigene Dateien
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Druckumgebung
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Documents\Eigene Videos
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Documents\Eigene Musik
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Documents\Eigene Bilder
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\AppData\Local\Verlauf
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\AppData\Local\Anwendungsdaten
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\otto\Anwendungsdaten
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Vorlagen
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Startmenü
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Netzwerkumgebung
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Lokale Einstellungen
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Eigene Dateien
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Druckumgebung
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Documents\Eigene Videos
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Documents\Eigene Musik
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Documents\Eigene Bilder
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\AppData\Local\Verlauf
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\AppData\Local\Anwendungsdaten
2017-07-18 21:35 - 2017-07-18 21:35 - 00000000 _SHDL C:\Users\Andrea und Hans-Jörg\Anwendungsdaten
2017-07-18 21:34 - 2017-07-18 22:06 - 02106252 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-18 21:34 - 2017-07-18 21:34 - 02011386 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-07-18 21:33 - 2017-07-18 21:33 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-07-18 21:33 - 2017-07-18 21:33 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2017-07-18 21:33 - 2017-07-18 21:33 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-07-18 21:33 - 2017-07-18 21:33 - 00000000 ____D C:\WINDOWS\system32\DAX2
2017-07-18 21:33 - 2017-07-18 21:33 - 00000000 ____D C:\Program Files\Realtek
2017-07-18 21:33 - 2017-07-18 21:33 - 00000000 ____D C:\Program Files\Common Files\logishrd
2017-07-18 21:33 - 2017-05-01 22:51 - 06437312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-07-18 21:33 - 2017-05-01 22:51 - 02479552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-07-18 21:33 - 2017-05-01 22:51 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-07-18 21:33 - 2017-05-01 22:51 - 00548800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-07-18 21:33 - 2017-05-01 22:51 - 00392312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-07-18 21:33 - 2017-05-01 22:51 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-07-18 21:33 - 2017-05-01 22:51 - 00069752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-07-18 21:33 - 2017-04-25 23:11 - 07944687 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-07-18 21:32 - 2017-07-18 23:01 - 00000000 ____D C:\ProgramData\NVIDIA
2017-07-18 21:32 - 2017-07-18 21:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-07-18 21:32 - 2017-07-18 21:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-07-18 21:32 - 2017-07-18 21:33 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-07-18 21:32 - 2017-05-01 22:52 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-07-18 21:32 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-07-18 21:28 - 2017-07-18 22:42 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-18 21:28 - 2017-07-18 22:00 - 00217120 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-07-18 19:13 - 2017-07-18 19:14 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{131C1342-3D38-4AB6-9C13-996FA996FC48}
2017-07-17 22:54 - 2017-07-17 22:54 - 02899954 _____ C:\Users\Andrea und Hans-Jörg\Downloads\globalfoodgardenbrochure.pdf
2017-07-17 21:06 - 2017-07-17 21:06 - 01072975 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Broschuere_Ausbildung___Karriere_00704620_DE_de.pdf
2017-07-17 21:05 - 2017-07-17 21:05 - 04955313 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Broschuere_Hochschule___Karriere_00704616_DE_de_SCREEN.pdf
2017-07-17 20:13 - 2017-07-17 20:13 - 00173100 _____ C:\Users\Andrea und Hans-Jörg\Downloads\egov-content496239.pdf
2017-07-17 19:41 - 2017-07-17 19:41 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{3B2B1EED-A855-47E2-8B12-9007C1D0257F}
2017-07-15 08:26 - 2017-07-15 08:26 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{BBAA7CE3-206B-473B-B863-86BBFB8BE5E6}
2017-07-14 22:20 - 2017-07-18 22:28 - 00000000 ___DC C:\WINDOWS\Panther
2017-07-14 12:49 - 2017-07-14 12:49 - 00559047 _____ C:\Users\Andrea und Hans-Jörg\Downloads\01_haushaltsscheck_19904_version_07(1).pdf
2017-07-14 12:10 - 2017-07-14 12:10 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{B1F7D874-AE32-48A8-8547-0EAB6462E1C1}
2017-07-14 11:57 - 2017-07-14 11:57 - 00598863 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Tabellenkalulation.pdf
2017-07-14 11:09 - 2017-07-14 11:09 - 00940525 _____ C:\Users\Andrea und Hans-Jörg\Downloads\06791DA4_Musterseite.pdf
2017-07-12 21:58 - 2017-07-12 21:58 - 00049992 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-07-12 21:58 - 2017-07-12 21:58 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-07-12 21:58 - 2017-07-12 21:58 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-07-12 21:58 - 2017-07-12 21:58 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-07-12 21:28 - 2017-07-18 21:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2017-07-12 21:26 - 2017-07-12 21:27 - 07178424 _____ (VS Revo Group ) C:\Users\Andrea und Hans-Jörg\Downloads\revosetup_v2.0.3.exe
2017-07-12 18:12 - 2017-07-12 18:12 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{5E97DCCD-2F69-41DC-BD0C-AC23F07AF558}
2017-07-12 17:13 - 2017-07-12 17:14 - 00330358 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Infoblatt_fuer_Bewerberinnen_und_Bewerber_Stand__16_03_2017.pdf
2017-07-12 17:13 - 2017-07-12 17:14 - 00109079 _____ C:\Users\Andrea und Hans-Jörg\Downloads\antrag-chipkarte-kl-ps-zw.pdf
2017-07-12 17:12 - 2017-07-12 17:12 - 00020162 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Reportd22bcce2-c370-44bc-8856-989d1fcb596e.pdf
2017-07-12 16:56 - 2017-07-12 16:56 - 03369812 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Seite.pdf
2017-07-12 16:41 - 2017-07-12 16:41 - 00067814 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Antragsformular_20170712-164138_.pdf
2017-07-11 21:42 - 2017-07-11 21:42 - 00028411 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Satzung_ergaenzendes_Hochschulauswahlverfahren_ueberarbeitet_02022016.pdf
2017-07-11 09:58 - 2017-07-11 09:58 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{7B1D620E-7D53-4E28-B5EB-674C9C486252}
2017-07-10 22:14 - 2017-07-10 22:14 - 00853941 _____ C:\Users\Andrea und Hans-Jörg\Downloads\studentische_aushilfe_tz_2016.pdf
2017-07-10 21:40 - 2017-07-10 21:40 - 00021143 _____ C:\Users\Andrea und Hans-Jörg\Downloads\2133_206_1499710833_898.pdf
2017-07-10 14:35 - 2017-07-10 14:35 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{E1B29CCE-DEE3-49DC-9696-4634742296E0}
2017-07-09 19:24 - 2017-07-09 19:24 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{76BB552F-69D4-4AAE-ACE8-81C243BCE2E7}
2017-07-09 00:20 - 2017-07-09 00:20 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{C0C58CDF-E46C-49A9-BC32-EA563E385E21}
2017-07-08 12:50 - 2017-07-08 12:50 - 00067813 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Antragsformular_20170708-124934_.pdf
2017-07-08 12:37 - 2017-07-08 12:37 - 00279334 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Report4e994e1d-ef23-49cc-84ac-47bf4b930580.pdf
2017-07-08 00:36 - 2017-07-08 00:36 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{206A89F9-D419-431D-857B-314687583D9A}
2017-07-07 22:05 - 2017-07-07 22:05 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\UNP
2017-07-07 17:48 - 2017-07-07 17:48 - 00085004 _____ C:\Users\Andrea und Hans-Jörg\Downloads\PrintChordSheet(3)
2017-07-07 17:45 - 2017-07-07 17:45 - 00082815 _____ C:\Users\Andrea und Hans-Jörg\Downloads\PrintChordSheet(2)
2017-07-07 17:45 - 2017-07-07 17:45 - 00082814 _____ C:\Users\Andrea und Hans-Jörg\Downloads\das-ist-mein-konig-E.pdf
2017-07-07 17:44 - 2017-07-07 17:44 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\LocalLow\F-Secure
2017-07-07 17:43 - 2017-07-07 17:43 - 00087659 _____ C:\Users\Andrea und Hans-Jörg\Downloads\PrintChordSheet(1)
2017-07-07 17:43 - 2017-07-07 17:43 - 00087656 _____ C:\Users\Andrea und Hans-Jörg\Downloads\PrintChordSheet
2017-07-07 16:27 - 2017-07-18 21:59 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-07-07 16:27 - 2017-07-07 16:28 - 00000000 ____D C:\Program Files\UNP
2017-07-07 12:36 - 2017-07-07 12:36 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{535B325F-7556-4CE4-821D-91E9DFB77E2B}
2017-07-05 22:53 - 2017-07-05 22:53 - 01686834 _____ C:\Users\Andrea und Hans-Jörg\Downloads\170419_ZuslassungsSatzung_IBO-B_pdf.pdf
2017-07-05 22:49 - 2017-07-05 22:49 - 01680256 _____ C:\Users\Andrea und Hans-Jörg\Downloads\170419_ZuslassungsSatzung_IBIS-B_pdf.pdf
2017-07-05 22:48 - 2017-07-05 22:48 - 00043981 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Bachelor_NC_Liste_WiSe201617(1).pdf
2017-07-05 22:44 - 2017-07-05 22:44 - 00043981 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Bachelor_NC_Liste_WiSe201617.pdf
2017-07-05 22:25 - 2017-07-05 22:25 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{2481844C-6921-45B1-943D-CF4BBB208A77}
2017-07-05 22:07 - 2017-07-05 22:07 - 00790815 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Reportc78b3879-ac7e-4f34-b799-a0319780ce3d.pdf
2017-07-05 22:05 - 2017-07-05 22:05 - 00097209 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Report147ffb2a-f4df-4b43-b061-b7eb3c1cb40b.pdf
2017-07-04 09:38 - 2017-07-04 09:38 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{1B6B6BD1-5410-4901-B735-0AC1E1BF4D24}
2017-07-03 21:37 - 2017-07-03 21:37 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{219E0236-60D3-447B-A477-A62EE3C6793A}
2017-07-03 09:37 - 2017-07-03 09:37 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{E01A6E94-24C3-4FC8-8239-02F10E5BE53F}
2017-07-01 15:51 - 2017-07-01 15:51 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{69A59D33-B66B-4245-B942-B60603AF64BA}
2017-06-30 23:47 - 2017-06-30 23:47 - 00057663 _____ C:\Users\Andrea und Hans-Jörg\Downloads\enveloppe gabarit 01.pdf
2017-06-30 23:45 - 2017-06-30 23:45 - 00239408 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Umschlag-DIN-C6.pdf
2017-06-30 22:47 - 2017-06-30 22:47 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{D8341D40-85E1-4F22-9688-AC0D8DAF3155}
2017-06-30 10:47 - 2017-06-30 10:47 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{66A81CBB-AF9D-4EF8-9FDA-AA1DBA10A95B}
2017-06-30 10:23 - 2017-07-12 16:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-29 15:22 - 2017-06-29 15:22 - 00060505 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Ticket_S10105-13096.pdf
2017-06-29 14:07 - 2017-06-29 14:07 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{CF53E68F-5225-48B8-9696-9A6DA26E808D}
2017-06-28 20:52 - 2017-06-28 20:52 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Roaming\GeoGebra 5.0
2017-06-28 20:47 - 2017-06-28 20:47 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{C8A16279-ECF1-463D-BCB1-42716D3F2C15}
2017-06-28 18:36 - 2017-06-28 18:36 - 05500785 _____ C:\Users\Andrea und Hans-Jörg\Downloads\verlegehinweise_trapez_und_wellprofile_von201504.pdf
2017-06-28 18:28 - 2017-06-28 18:28 - 00082147 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Montagehinweise.pdf
2017-06-28 18:27 - 2017-06-28 18:27 - 13514143 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Trapezblech Gesamt_Katalog_2013_1.pdf
2017-06-28 17:58 - 2017-06-28 17:58 - 00267895 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Garagenschwingtor_DL.pdf
2017-06-28 17:38 - 2017-06-28 17:39 - 07801423 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Einbaudaten_Rolltore_Rollgitter_SB_TGT_DD.pdf
2017-06-27 20:59 - 2017-06-27 20:59 - 00248403 _____ C:\Users\Andrea und Hans-Jörg\Downloads\stegplatten_verlegeanleitung.pdf
2017-06-27 15:04 - 2017-06-27 15:04 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{A6A3690A-C653-41CB-8214-2C4D8194BBB1}
2017-06-26 23:03 - 2017-06-26 23:03 - 02075462 _____ C:\Users\Andrea und Hans-Jörg\Downloads\brustor_brochure_outdoor_living_def2017_deu_lr.pdf
2017-06-26 22:51 - 2017-06-26 22:51 - 01372940 _____ C:\Users\Andrea und Hans-Jörg\Downloads\prospekt-rollfenster-mit-logo-2014.pdf
2017-06-26 14:47 - 2017-06-26 14:47 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{49AC19D1-03ED-4DDF-ABEB-B3CA5326FAD8}
2017-06-24 22:23 - 2017-06-24 22:23 - 04256939 _____ C:\Users\Andrea und Hans-Jörg\Downloads\ZS2017-Flyer.pdf
2017-06-24 19:51 - 2017-06-24 19:51 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{A78576A1-F584-46E2-8A9C-67B846A82DE9}
2017-06-24 07:26 - 2017-06-24 07:26 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{E9BFEC98-4528-45AA-9980-511C13FCD5D7}
2017-06-23 11:17 - 2017-06-23 11:17 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{B60E96A2-FC60-4020-AC07-5B253BC8686A}
2017-06-23 09:43 - 2017-06-23 09:43 - 00177036 _____ C:\Users\Andrea und Hans-Jörg\Downloads\0304 Klassenarbeit 1 Klasse 8l - Loesung.pdf
2017-06-23 09:43 - 2017-06-23 09:43 - 00014381 _____ C:\Users\Andrea und Hans-Jörg\Downloads\5 Klassenarbeit 7b_2006_07_Burgau(3).pdf
2017-06-23 09:42 - 2017-06-23 09:42 - 00101091 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Geometrie_01_Klasse07.pdf
2017-06-23 09:42 - 2017-06-23 09:42 - 00014381 _____ C:\Users\Andrea und Hans-Jörg\Downloads\5 Klassenarbeit 7b_2006_07_Burgau(2).pdf
2017-06-23 09:41 - 2017-06-23 09:41 - 00014381 _____ C:\Users\Andrea und Hans-Jörg\Downloads\5 Klassenarbeit 7b_2006_07_Burgau(1).pdf
2017-06-23 09:39 - 2017-06-23 09:39 - 00014381 _____ C:\Users\Andrea und Hans-Jörg\Downloads\5 Klassenarbeit 7b_2006_07_Burgau.pdf
2017-06-23 09:36 - 2017-06-23 09:36 - 00044562 _____ C:\Users\Andrea und Hans-Jörg\Downloads\dw-bsp-4598-3-ablatt-OXTV.pdf
2017-06-23 09:36 - 2017-06-23 09:36 - 00044326 _____ C:\Users\Andrea und Hans-Jörg\Downloads\dw-bsp-4598-2-ablatt-PPLY.pdf
2017-06-23 09:35 - 2017-06-23 09:35 - 00279922 _____ C:\Users\Andrea und Hans-Jörg\Downloads\KL_Ma7_4_130208.pdf
2017-06-23 09:35 - 2017-06-23 09:35 - 00044148 _____ C:\Users\Andrea und Hans-Jörg\Downloads\dw-bsp-4598-1-ablatt-IEGG.pdf
2017-06-22 16:59 - 2017-06-22 16:59 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{1A2B7290-D3DA-4569-A0FB-E73C1A6572F3}
2017-06-22 16:36 - 2017-06-22 16:36 - 00093999 _____ C:\Users\Andrea und Hans-Jörg\Downloads\aad5c94e-5766-41b9-82ea-9d48ac8ae480.pdf
2017-06-21 23:58 - 2017-06-21 23:58 - 03957379 _____ C:\Users\Andrea und Hans-Jörg\Downloads\MEA TechnDaten.pdf
2017-06-21 23:58 - 2017-06-21 23:58 - 01269580 _____ C:\Users\Andrea und Hans-Jörg\Downloads\techn_daten_mea_laufrollen_freitragend.pdf
2017-06-21 23:29 - 2017-06-21 23:29 - 00686884 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Trapezblech_aus_Aluminium_80_277_Negativlage.pdf
2017-06-21 23:29 - 2017-06-21 23:29 - 00684797 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Trapezblech_aus_Aluminium_80_277_Positivlage.pdf
2017-06-21 23:28 - 2017-06-21 23:28 - 00910406 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Trapezblech_aus_Stahl_70_200_Positivlage.pdf
2017-06-21 23:27 - 2017-06-21 23:27 - 00274473 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Trapezblech_aus_Stahl_45_333.pdf
2017-06-21 23:26 - 2017-06-21 23:26 - 00396408 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Trapezblech_aus_Stahl_Akustik_45_150.pdf
2017-06-21 20:45 - 2017-06-21 20:45 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{58D63453-421E-4192-A686-A3BD137D025E}
2017-06-21 14:42 - 2017-07-18 21:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GeoGebra 5
2017-06-21 14:42 - 2017-06-21 14:42 - 00001924 _____ C:\Users\Public\Desktop\GeoGebra.lnk
2017-06-21 14:41 - 2017-06-21 14:42 - 00000000 ____D C:\Program Files (x86)\GeoGebra 5.0
2017-06-21 14:41 - 2017-06-21 14:41 - 00000000 ____D C:\Program Files (x86)\Chip Digital GmbH
2017-06-21 12:21 - 2017-06-21 12:22 - 01496584 _____ C:\Users\Andrea und Hans-Jörg\Downloads\GeoGebra - CHIP-Installer.exe
2017-06-21 08:45 - 2017-06-21 08:45 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{8F4ACECB-FFE4-4F7F-8CF4-9944B49330A5}
2017-06-20 14:39 - 2017-06-20 14:39 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{C7B2C814-D6EB-49F4-A160-E48E08976D57}
2017-06-19 23:53 - 2017-06-19 23:54 - 00000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-06-19 23:43 - 2017-06-19 23:43 - 00102668 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Lifepoint_Fragebogen_10.06.2017.pdf
2017-06-19 23:40 - 2017-06-19 23:40 - 00204334 _____ C:\Users\Andrea und Hans-Jörg\Downloads\Lifepoint_Planun_9.06.2017.pdf
2017-06-19 15:27 - 2017-06-19 15:27 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\{BE902481-3E65-4BBE-AC6A-6D3B3874A496}
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-07-19 11:23 - 2015-04-29 11:03 - 00020793 _____ C:\Users\Andrea und Hans-Jörg\Downloads\FRST.txt
2017-07-19 11:16 - 2015-04-29 11:03 - 00000000 ____D C:\FRST
2017-07-19 09:38 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-19 09:38 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-19 09:20 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF
2017-07-19 09:20 - 2016-11-18 11:54 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\LocalLow\Mozilla
2017-07-19 09:19 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat
2017-07-18 22:47 - 2015-08-18 19:55 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\Packages
2017-07-18 22:36 - 2016-09-28 20:53 - 00002469 _____ C:\Users\Andrea und Hans-Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-07-18 22:36 - 2014-01-22 12:11 - 00000000 ___RD C:\Users\Andrea und Hans-Jörg\SkyDrive
2017-07-18 22:29 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-07-18 22:29 - 2015-08-18 19:55 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-07-18 22:28 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows NT
2017-07-18 22:27 - 2017-03-18 23:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-07-18 22:27 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-07-18 22:27 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Registration
2017-07-18 22:25 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache
2017-07-18 22:22 - 2017-03-18 23:06 - 00000000 ____D C:\WINDOWS\Setup
2017-07-18 22:22 - 2017-03-18 23:03 - 00000000 __RSD C:\WINDOWS\Media
2017-07-18 22:22 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ___RD C:\Program Files\Windows Defender
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\migwiz
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-07-18 22:21 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-07-18 22:21 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-07-18 22:17 - 2017-03-20 06:37 - 00000000 ____D C:\WINDOWS\HoloShell
2017-07-18 22:16 - 2017-03-20 06:35 - 00896874 _____ C:\WINDOWS\system32\perfh007.dat
2017-07-18 22:16 - 2017-03-20 06:35 - 00199986 _____ C:\WINDOWS\system32\perfc007.dat
2017-07-18 22:16 - 2015-08-18 19:07 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-07-18 22:15 - 2017-03-18 23:03 - 00000000 __RHD C:\Users\Public\Libraries
2017-07-18 22:11 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-07-18 22:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-07-18 22:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Provisioning
2017-07-18 22:10 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-07-18 22:08 - 2015-08-19 21:45 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-07-18 22:03 - 2017-03-20 06:36 - 00000000 ____D C:\WINDOWS\OCR
2017-07-18 21:59 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-07-18 21:59 - 2017-03-18 13:40 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-07-18 21:59 - 2015-10-30 20:44 - 00000000 ____D C:\WINDOWS\ShellNew
2017-07-18 21:59 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\tr
2017-07-18 21:59 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\sl
2017-07-18 21:59 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\pl
2017-07-18 21:59 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\nl
2017-07-18 21:59 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\it
2017-07-18 21:58 - 2017-05-30 14:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2017-07-18 21:58 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-07-18 21:58 - 2017-03-02 18:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO steuer Sparbuch 2017
2017-07-18 21:58 - 2016-12-30 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-07-18 21:58 - 2016-12-09 22:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dm-Fotowelt
2017-07-18 21:58 - 2016-08-23 08:27 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRITZ!Box
2017-07-18 21:58 - 2016-05-03 17:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnityMedia
2017-07-18 21:58 - 2016-04-04 20:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FRITZ!Fernzugang
2017-07-18 21:58 - 2016-02-10 10:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO steuer Sparbuch 2016
2017-07-18 21:58 - 2015-12-14 10:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\fotokasten comfort
2017-07-18 21:58 - 2015-11-19 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanWizard 5 für Windows
2017-07-18 21:58 - 2015-10-31 19:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Connectify 2015
2017-07-18 21:58 - 2015-09-23 11:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO Mein Geld 365
2017-07-18 21:58 - 2015-09-03 22:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minimal ADB and Fastboot
2017-07-18 21:58 - 2015-07-07 17:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2017-07-18 21:58 - 2015-03-02 12:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\svnet
2017-07-18 21:58 - 2015-02-03 11:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO Steuer-Sparbuch 2015
2017-07-18 21:58 - 2015-02-02 15:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\phase-6
2017-07-18 21:58 - 2015-01-19 11:57 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.3
2017-07-18 21:58 - 2014-11-24 22:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\online-foto Bestellsoftware
2017-07-18 21:58 - 2014-11-18 23:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FotoUp3
2017-07-18 21:58 - 2014-05-26 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-07-18 21:58 - 2014-03-28 09:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftMaker FreeOffice
2017-07-18 21:58 - 2014-01-22 12:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-07-18 21:58 - 2014-01-18 18:57 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2017-07-18 21:58 - 2014-01-16 19:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-07-18 21:58 - 2013-12-17 22:19 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover
2017-07-18 21:58 - 2013-12-16 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Schulware
2017-07-18 21:58 - 2013-12-02 18:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-07-18 21:58 - 2013-10-29 18:08 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\tiptoi® Manager
2017-07-18 21:58 - 2013-10-28 21:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-07-18 21:58 - 2013-10-15 19:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2017-07-18 21:58 - 2013-10-07 16:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO Steuer-Sparbuch 2013 20104
2017-07-18 21:58 - 2013-09-19 10:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
2017-07-18 21:58 - 2013-09-17 16:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2017-07-18 21:58 - 2013-08-14 22:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FRITZ!Box
2017-07-18 21:58 - 2013-07-01 16:55 - 00000000 ____D C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoftMaker FreeOffice
2017-07-18 21:58 - 2013-02-07 12:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF to Word Doc Converter
2017-07-18 21:58 - 2013-01-31 16:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FamilySearch
2017-07-18 21:58 - 2012-10-09 09:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WordToPDF
2017-07-18 21:58 - 2012-08-30 10:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2017-07-18 21:58 - 2012-05-15 10:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-07-18 21:58 - 2012-05-10 09:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Documents To Go Desktop for Android
2017-07-18 21:58 - 2012-04-24 09:50 - 00000000 ____D C:\WINDOWS\de
2017-07-18 21:58 - 2012-04-24 09:50 - 00000000 ____D C:\WINDOWS\da
2017-07-18 21:58 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\hu
2017-07-18 21:58 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\fr
2017-07-18 21:58 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\es
2017-07-18 21:58 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\en
2017-07-18 21:58 - 2012-04-24 09:49 - 00000000 ____D C:\WINDOWS\el
2017-07-18 21:58 - 2012-04-11 09:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PixelNet Software
2017-07-18 21:58 - 2012-03-09 18:17 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WISO Steuer-Sparbuch 2012
2017-07-18 21:58 - 2012-03-06 23:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GeoGebra
2017-07-18 21:58 - 2012-02-29 22:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\maxdome
2017-07-18 21:58 - 2012-02-29 21:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2017-07-18 21:58 - 2011-12-25 21:37 - 00000000 ____D C:\Users\simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover
2017-07-18 21:58 - 2011-12-08 22:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ALDI Bestellsoftware
2017-07-18 21:58 - 2011-10-19 21:07 - 00000000 ____D C:\Users\otto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover
2017-07-18 21:58 - 2011-10-19 20:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Deutsch)
2017-07-18 21:58 - 2011-10-06 10:48 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover
2017-07-18 21:58 - 2011-10-06 10:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Versandhelfer
2017-07-18 21:58 - 2011-04-11 22:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2017-07-18 21:58 - 2011-04-11 22:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerDVD Copy
2017-07-18 21:58 - 2011-04-11 22:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LabelPrint
2017-07-18 21:57 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-07-18 21:57 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-07-18 21:57 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-07-18 21:57 - 2017-03-18 22:59 - 00611840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2017-07-18 21:57 - 2017-03-18 22:59 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2017-07-18 21:57 - 2017-03-18 22:59 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2017-07-18 21:57 - 2017-03-18 22:59 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2017-07-18 21:57 - 2017-03-18 22:59 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2017-07-18 21:57 - 2017-03-18 22:59 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2017-07-18 21:57 - 2017-03-18 22:59 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2017-07-18 21:57 - 2017-03-18 22:59 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2017-07-18 21:57 - 2017-03-18 22:56 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2017-07-18 21:57 - 2017-03-18 22:56 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2017-07-18 21:57 - 2017-03-18 22:56 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2017-07-18 21:57 - 2017-03-18 22:56 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2017-07-18 21:57 - 2017-03-18 22:56 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2017-07-18 21:57 - 2017-03-18 22:56 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2017-07-18 21:57 - 2017-03-18 22:56 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2017-07-18 21:57 - 2017-03-18 22:56 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2017-07-18 21:57 - 2017-03-18 22:56 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\simptcp.dll
2017-07-18 21:56 - 2017-03-18 22:59 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2017-07-18 21:56 - 2017-03-18 22:59 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2017-07-18 21:56 - 2017-03-18 22:56 - 01380352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2017-07-18 21:56 - 2017-03-18 22:56 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2017-07-18 21:56 - 2017-03-18 22:56 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2017-07-18 21:56 - 2017-03-18 22:56 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2017-07-18 21:56 - 2017-03-18 22:56 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2017-07-18 21:56 - 2017-03-18 22:56 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2017-07-18 21:56 - 2017-03-18 22:56 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2017-07-18 21:49 - 2017-03-20 06:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\spool
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-07-18 21:49 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\IME
2017-07-18 21:49 - 2013-10-15 19:00 - 00000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2017-07-18 21:48 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\schemas
2017-07-18 21:48 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-07-18 21:47 - 2017-03-18 23:03 - 00000000 __SHD C:\Program Files\Windows Sidebar
2017-07-18 21:47 - 2017-03-18 23:03 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-07-18 21:47 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\IME
2017-07-18 21:47 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-07-18 21:47 - 2017-02-10 10:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-07-18 21:47 - 2016-12-01 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xiaomi
2017-07-18 21:47 - 2016-08-31 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-07-18 21:47 - 2016-03-08 12:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2017-07-18 21:47 - 2015-12-14 22:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XiaoYi
2017-07-18 21:47 - 2015-07-06 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2017-07-18 21:47 - 2014-06-07 14:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Krita (x85)
2017-07-18 21:47 - 2014-01-03 15:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec
2017-07-18 21:47 - 2013-09-18 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2017-07-18 21:47 - 2012-09-06 20:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2017-07-18 21:47 - 2011-11-07 22:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WEB.DE
2017-07-18 21:47 - 2011-04-11 22:33 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Power2Go
2017-07-18 21:47 - 2011-04-11 22:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
2017-07-18 21:47 - 2011-04-11 22:26 - 00000000 ____D C:\Program Files\Intel
2017-07-18 21:47 - 2011-04-11 22:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2017-07-18 21:47 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games
2017-07-18 21:46 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-07-18 21:45 - 2016-09-28 20:24 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover
2017-07-18 21:45 - 2016-09-28 20:24 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerRecover
2017-07-18 21:44 - 2016-11-21 13:35 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xiaomi
2017-07-18 21:44 - 2013-07-02 11:29 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2017-07-18 21:40 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\USOPrivate
2017-07-18 21:37 - 2016-02-29 16:13 - 00000000 ____D C:\Users\otto\AppData\Local\Packages
2017-07-18 21:36 - 2015-12-13 04:39 - 00000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER
2017-07-18 21:33 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Help
2017-07-18 21:33 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-07-18 21:33 - 2012-08-31 23:08 - 00000000 ____D C:\temp
2017-07-18 20:23 - 2017-03-20 07:06 - 00000000 ___HD C:\$WINDOWS.~BT
2017-07-15 12:42 - 2016-10-07 17:18 - 00006144 _____ C:\Users\Andrea und Hans-Jörg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-07-14 17:09 - 2017-01-10 21:06 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\CrashDumps
2017-07-12 21:32 - 2016-11-03 19:15 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-07-12 21:28 - 2011-10-06 11:40 - 00000000 ____D C:\Program Files (x86)\virenschutz
2017-07-12 17:05 - 2013-08-14 23:28 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-07-12 17:01 - 2011-03-14 16:08 - 135225752 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-07-12 16:15 - 2013-01-09 09:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-07-11 16:58 - 2015-03-30 23:44 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\Documents\Simon
2017-07-10 22:12 - 2015-02-26 11:04 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\Documents\WISO Mein Geld
2017-07-05 22:36 - 2016-08-23 14:05 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\Documents\Otto
2017-07-05 22:36 - 2015-07-07 14:19 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\Documents\David
2017-06-28 21:46 - 2012-06-22 20:00 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\ElevatedDiagnostics
2017-06-21 21:32 - 2011-11-19 17:24 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\Documents\Andrea
2017-06-21 14:41 - 2012-09-06 20:22 - 00000000 ____D C:\Users\Andrea und Hans-Jörg\AppData\Local\Downloaded Installations
2017-06-20 14:26 - 2011-10-06 19:38 - 354593356 _____ C:\WINDOWS\MEMORY.DMP
2017-06-19 16:51 - 2012-05-15 10:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-06-19 16:51 - 2012-05-15 10:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-06-19 15:05 - 2013-12-17 12:48 - 00000000 ____D C:\ProgramData\F-Secure
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2010-04-05 00:08 - 2010-04-05 00:08 - 1253376 _____ (Florian Gilles) C:\Program Files\nsm.dll
2010-04-05 00:07 - 2010-04-05 00:07 - 0071680 _____ (Florian Gilles) C:\Program Files\nsmc.exe
2016-10-07 17:18 - 2017-07-15 12:42 - 0006144 _____ () C:\Users\Andrea und Hans-Jörg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-21 14:42 - 2012-04-21 14:42 - 0000084 _____ () C:\Users\Andrea und Hans-Jörg\AppData\Local\DVDPATH.TXT
2012-01-12 10:05 - 2012-01-12 10:05 - 0000000 _____ () C:\Users\Andrea und Hans-Jörg\AppData\Local\{670BECA3-CBE3-4478-B5A7-E2541980EFEE}
2017-07-18 21:33 - 2017-07-18 21:33 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-02-26 09:24 - 2015-10-23 11:25 - 0000325 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\simon\Kies_2.1.1.11124_17_6 (1).exe
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert oh ein paar Zeilen am Schluss habe ich vergessen: Code:
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-07-18 21:28 der report von TDSS Killer Code:
19:44:11.0814 0x30dc TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02
19:44:20.0315 0x30dc ============================================================
19:44:20.0315 0x30dc Current date / time: 2017/07/19 19:44:20.0315
19:44:20.0315 0x30dc SystemInfo:
19:44:20.0315 0x30dc
19:44:20.0315 0x30dc OS Version: 10.0.15063 ServicePack: 0.0
19:44:20.0315 0x30dc Product type: Workstation
19:44:20.0315 0x30dc ComputerName: PALAVAS
19:44:20.0315 0x30dc UserName: Andrea und Hans-Jörg
19:44:20.0315 0x30dc Windows directory: C:\WINDOWS
19:44:20.0315 0x30dc System windows directory: C:\WINDOWS
19:44:20.0315 0x30dc Running under WOW64
19:44:20.0315 0x30dc Processor architecture: Intel x64
19:44:20.0315 0x30dc Number of processors: 4
19:44:20.0315 0x30dc Page size: 0x1000
19:44:20.0315 0x30dc Boot type: Normal boot
19:44:20.0315 0x30dc CodeIntegrityOptions = 0x00000001
19:44:20.0315 0x30dc ============================================================
19:44:20.0831 0x30dc KLMD registered as C:\WINDOWS\system32\drivers\57639367.sys
19:44:20.0831 0x30dc KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 15063.0, osProperties = 0x19
19:44:21.0315 0x30dc System UUID: {2E3553E2-4595-6F8C-6FF7-BB17B06F8717}
19:44:21.0878 0x30dc Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:44:21.0893 0x30dc ============================================================
19:44:21.0893 0x30dc \Device\Harddisk0\DR0:
19:44:21.0893 0x30dc MBR partitions:
19:44:21.0893 0x30dc \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
19:44:21.0893 0x30dc \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xE4FD5800
19:44:21.0893 0x30dc \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xE5008000, BlocksNum 0x3C00000
19:44:21.0893 0x30dc ============================================================
19:44:21.0909 0x30dc C: <-> \Device\Harddisk0\DR0\Partition2
19:44:21.0940 0x30dc D: <-> \Device\Harddisk0\DR0\Partition3
19:44:21.0940 0x30dc ============================================================
19:44:21.0940 0x30dc Initialize success
19:44:21.0940 0x30dc ============================================================
19:44:25.0269 0x30ec ============================================================
19:44:25.0269 0x30ec Scan started
19:44:25.0269 0x30ec Mode: Manual;
19:44:25.0269 0x30ec ============================================================
19:44:25.0269 0x30ec KSN ping started
19:44:25.0409 0x30ec KSN ping finished: true
19:44:36.0723 0x30ec ================ Scan system memory ========================
19:44:36.0723 0x30ec System memory - ok
19:44:36.0723 0x30ec ================ Scan services =============================
19:44:37.0458 0x30ec 1394ohci - ok
19:44:37.0458 0x30ec 3ware - ok
19:44:37.0489 0x30ec ACPI - ok
19:44:37.0489 0x30ec AcpiDev - ok
19:44:37.0504 0x30ec acpiex - ok
19:44:37.0504 0x30ec acpipagr - ok
19:44:37.0520 0x30ec AcpiPmi - ok
19:44:37.0536 0x30ec acpitime - ok
19:44:37.0723 0x30ec [ 8D6BA8E7676038A27FD4ECF12CC744B0, F5D59B764DCB4A06A51939533DC7B2391FD68E3979C48939C023A60DCE0D2101 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:44:37.0723 0x30ec AdobeARMservice - ok
19:44:38.0083 0x30ec [ 0DC99843E91A0313F0C6591656D650A5, 583DCD5D3BA3F470FF9F39221358EF2DF01FE62B98562FCFD1AD99FA1C01892E ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:44:38.0083 0x30ec AdobeFlashPlayerUpdateSvc - ok
19:44:38.0098 0x30ec ADP80XX - ok
19:44:38.0114 0x30ec AFD - ok
19:44:38.0129 0x30ec ahcache - ok
19:44:38.0145 0x30ec AJRouter - ok
19:44:38.0145 0x30ec ALG - ok
19:44:38.0161 0x30ec AmdK8 - ok
19:44:38.0161 0x30ec AmdPPM - ok
19:44:38.0176 0x30ec amdsata - ok
19:44:38.0192 0x30ec amdsbs - ok
19:44:38.0192 0x30ec amdxata - ok
19:44:38.0254 0x30ec AppHostSvc - ok
19:44:38.0270 0x30ec AppID - ok
19:44:38.0270 0x30ec AppIDSvc - ok
19:44:38.0270 0x30ec Appinfo - ok
19:44:38.0426 0x30ec [ 7D811EA7A2AAA49B0446D42CBC1CD338, AFECE5E44E48F756C7EB81D95C9237552AF8A9C02CBE756E0F3D3C6524DE49AD ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
19:44:38.0442 0x30ec Apple Mobile Device Service - ok
19:44:38.0458 0x30ec applockerfltr - ok
19:44:38.0489 0x30ec AppReadiness - ok
19:44:38.0504 0x30ec AppXSvc - ok
19:44:38.0520 0x30ec arcsas - ok
19:44:38.0723 0x30ec aspnet_state - ok
19:44:38.0739 0x30ec AsyncMac - ok
19:44:38.0755 0x30ec atapi - ok
19:44:38.0786 0x30ec AudioEndpointBuilder - ok
19:44:38.0786 0x30ec Audiosrv - ok
19:44:38.0848 0x30ec [ 6A300AD0E23A155B2C3A7FAB0D4AABD1, AD283CC530482C0C155727C3234BFA4773C8C80B4C9912448196F83407C3CFD4 ] avmaura C:\WINDOWS\System32\drivers\avmaura.sys
19:44:38.0880 0x30ec avmaura - ok
19:44:38.0895 0x30ec AxInstSV - ok
19:44:38.0895 0x30ec b06bdrv - ok
19:44:38.0911 0x30ec BasicDisplay - ok
19:44:38.0927 0x30ec BasicRender - ok
19:44:38.0942 0x30ec bcmfn2 - ok
19:44:38.0973 0x30ec BDESVC - ok
19:44:38.0973 0x30ec Beep - ok
19:44:38.0989 0x30ec BFE - ok
19:44:39.0020 0x30ec BITS - ok
19:44:39.0098 0x30ec [ B5C2F92EE1106DFE7BB1CCE4D35B6037, E399C390687589194D8AAD385055F0CFA7D52AD9E837D8FF95008B8EB2B34E50 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
19:44:39.0114 0x30ec Bonjour Service - ok
19:44:39.0114 0x30ec bowser - ok
19:44:39.0114 0x30ec BrokerInfrastructure - ok
19:44:39.0130 0x30ec Browser - ok
19:44:39.0145 0x30ec BthAvrcpTg - ok
19:44:39.0161 0x30ec BthHFEnum - ok
19:44:39.0161 0x30ec bthhfhid - ok
19:44:39.0177 0x30ec BthHFSrv - ok
19:44:39.0177 0x30ec BTHMODEM - ok
19:44:39.0192 0x30ec bthserv - ok
19:44:39.0239 0x30ec buttonconverter - ok
19:44:39.0255 0x30ec CAD - ok
19:44:39.0255 0x30ec CapImg - ok
19:44:39.0255 0x30ec cdfs - ok
19:44:39.0286 0x30ec CDPSvc - ok
19:44:39.0302 0x30ec CDPUserSvc - ok
19:44:39.0348 0x30ec cdrom - ok
19:44:39.0364 0x30ec CertPropSvc - ok
19:44:39.0552 0x30ec [ 59B4AB79011957DD3B83F0C2E63741BD, 5DE68785D701DBA0F98452B7D5CC407BEECD51685F39516157733CED2EF2FA19 ] chip1click C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe
19:44:39.0552 0x30ec chip1click - ok
19:44:39.0552 0x30ec cht4iscsi - ok
19:44:39.0567 0x30ec cht4vbd - ok
19:44:39.0567 0x30ec circlass - ok
19:44:39.0567 0x30ec CldFlt - ok
19:44:39.0598 0x30ec CLFS - ok
19:44:39.0723 0x30ec [ 99C73D65BF6E6AE66D1B4337D8260C97, D13E9861125ABFA892F7FCED1E007FD5FBEE27954C9084286FFD186193157D3A ] ClickToRunSvc C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
19:44:39.0817 0x30ec ClickToRunSvc - ok
19:44:39.0864 0x30ec ClipSVC - ok
19:44:39.0864 0x30ec clreg - ok
19:44:39.0880 0x30ec CmBatt - ok
19:44:39.0880 0x30ec CNG - ok
19:44:39.0880 0x30ec cnghwassist - ok
19:44:39.0895 0x30ec [ E78714B423B73BF2A380EC7E7A3EEA02, 12FCFF7CD17450A51F18E7A7D3DF7CA2A8DF58A612E1379BCABF3D6D6D2B1D64 ] cnnctfy3 C:\WINDOWS\system32\DRIVERS\cnnctfy3.sys
19:44:40.0020 0x30ec cnnctfy3 - ok
19:44:40.0208 0x30ec CompositeBus - ok
19:44:40.0223 0x30ec COMSysApp - ok
19:44:40.0223 0x30ec condrv - ok
19:44:40.0286 0x30ec [ 1F579D39EA90F02391818EACE88695FA, 8C2214CDF4DE5ADDCC4B464C3EFF07BD31C16A918E1E9E2067B652CC1847909C ] Connectify C:\Program Files (x86)\Connectify\ConnectifyService.exe
19:44:40.0286 0x30ec Connectify - ok
19:44:40.0317 0x30ec CoreMessagingRegistrar - ok
19:44:40.0348 0x30ec CryptSvc - ok
19:44:40.0473 0x30ec [ B4D1D62A09F09CB2DFD55628350CDAFB, 7DD3CE77D88B5AFAC4B6187F4CA6D50B7BD3398207163B2A1E4C76467801FF28 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
19:44:40.0489 0x30ec cvhsvc - ok
19:44:40.0505 0x30ec dam - ok
19:44:40.0583 0x30ec [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdate C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
19:44:40.0583 0x30ec dbupdate - ok
19:44:40.0598 0x30ec [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdatem C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
19:44:40.0598 0x30ec dbupdatem - ok
19:44:40.0708 0x30ec [ F0A3CA65871C39CB5BE6475A139536DD, 4715426A4F5AAA27BBC359D8F810005613A26A31439CC4C59C98E7220308238D ] DbxSvc C:\WINDOWS\system32\DbxSvc.exe
19:44:41.0255 0x30ec DbxSvc - ok
19:44:41.0271 0x30ec DcomLaunch - ok
19:44:41.0271 0x30ec defragsvc - ok
19:44:41.0286 0x30ec DeviceAssociationService - ok
19:44:41.0286 0x30ec DeviceInstall - ok
19:44:41.0317 0x30ec DevicesFlowUserSvc - ok
19:44:41.0349 0x30ec DevQueryBroker - ok
19:44:41.0349 0x30ec Dfsc - ok
19:44:41.0411 0x30ec [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
19:44:41.0677 0x30ec dg_ssudbus - ok
19:44:41.0708 0x30ec Dhcp - ok
19:44:41.0755 0x30ec diagnosticshub.standardcollector.service - ok
19:44:41.0755 0x30ec DiagTrack - ok
19:44:41.0755 0x30ec Disk - ok
19:44:41.0771 0x30ec DmEnrollmentSvc - ok
19:44:41.0771 0x30ec dmvsc - ok
19:44:41.0786 0x30ec dmwappushservice - ok
19:44:41.0802 0x30ec Dnscache - ok
19:44:41.0817 0x30ec dot3svc - ok
19:44:41.0849 0x30ec DPS - ok
19:44:41.0896 0x30ec drmkaud - ok
19:44:41.0911 0x30ec DsmSvc - ok
19:44:41.0911 0x30ec DsSvc - ok
19:44:41.0927 0x30ec DusmSvc - ok
19:44:41.0958 0x30ec DXGKrnl - ok
19:44:42.0021 0x30ec e1iexpress - ok
19:44:42.0036 0x30ec EapHost - ok
19:44:42.0036 0x30ec ebdrv - ok
19:44:42.0052 0x30ec EFS - ok
19:44:42.0052 0x30ec EhStorClass - ok
19:44:42.0052 0x30ec EhStorTcgDrv - ok
19:44:42.0067 0x30ec embeddedmode - ok
19:44:42.0067 0x30ec EntAppSvc - ok
19:44:42.0067 0x30ec ErrDev - ok
19:44:42.0099 0x30ec EventSystem - ok
19:44:42.0099 0x30ec exfat - ok
19:44:42.0177 0x30ec [ 05B9A810AACFAD4AEABBED95CA627097, 211D37859C229F10F099A7C304BCC4871EC4488FD227CCAD27317132F3FFF034 ] F-Secure Gatekeeper C:\Program Files (x86)\Kabel BW\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys
19:44:42.0177 0x30ec F-Secure Gatekeeper - ok
19:44:42.0224 0x30ec [ 4C87B3BF15F4334E339169E37F637F97, 53B1AB75936D6257F91837DACF27E658045CC3D41FACBF15B218F7A08D3482CD ] F-Secure HIPS C:\Program Files (x86)\Kabel BW\apps\ComputerSecurity\HIPS\drivers\fshs.sys
19:44:42.0224 0x30ec F-Secure HIPS - ok
19:44:42.0239 0x30ec fastfat - ok
19:44:42.0286 0x30ec Fax - ok
19:44:42.0411 0x30ec fdc - ok
19:44:42.0443 0x30ec fdPHost - ok
19:44:42.0474 0x30ec FDResPub - ok
19:44:42.0505 0x30ec fhsvc - ok
19:44:42.0536 0x30ec FileCrypt - ok
19:44:42.0536 0x30ec FileInfo - ok
19:44:42.0536 0x30ec Filetrace - ok
19:44:42.0552 0x30ec flpydisk - ok
19:44:42.0552 0x30ec FltMgr - ok
19:44:42.0567 0x30ec FontCache - ok
19:44:42.0677 0x30ec FontCache3.0.0.0 - ok
19:44:42.0677 0x30ec FrameServer - ok
19:44:42.0708 0x30ec [ AA0F9F7EC70D19EA1E6390FD0D93E4AB, 0DA5A3020F0D57C38AF9D1F51A4AA6A1C24CBCB065F960E683DF00127891DB18 ] fsbts C:\WINDOWS\system32\Drivers\fsbts.sys
19:44:42.0708 0x30ec fsbts - ok
19:44:42.0708 0x30ec FsDepends - ok
19:44:42.0724 0x30ec [ 7CF18849F5250961137D6318C906141D, 20CC67B5DE041C8D7376D94D6645E0EC4A864270C1994B43E4C3D9A633FA09C8 ] fshoster C:\Program Files (x86)\Kabel BW\fshoster32.exe
19:44:42.0740 0x30ec fshoster - ok
19:44:42.0755 0x30ec [ 2B50E6EEA5470950AA0741FB259CC301, 3A67C4EF53308CC6D63D20EA2D7B510712BD8D1BFCBC6B053A4F196664D85204 ] FSMA C:\Program Files (x86)\Kabel BW\apps\ComputerSecurity\Common\FSMA32.EXE
19:44:42.0771 0x30ec FSMA - ok
19:44:42.0771 0x30ec [ 7CF18849F5250961137D6318C906141D, 20CC67B5DE041C8D7376D94D6645E0EC4A864270C1994B43E4C3D9A633FA09C8 ] fsnethoster C:\Program Files (x86)\Kabel BW\fshoster32.exe
19:44:42.0771 0x30ec fsnethoster - ok
19:44:42.0880 0x30ec [ 3E256298A209F8704CCC90B55B28C69E, 94A7984B115D190D5DFFBABC8A64F1161B66CF61637DECFBC030FC634693799C ] fsni C:\Program Files (x86)\Kabel BW\apps\CCF_Scanning\bin\fsni64.sys
19:44:42.0896 0x30ec fsni - ok
19:44:42.0943 0x30ec [ 11F829E0748FFBFD0290FFE2F58DE963, DD7534183FCA3375E7767E4AE772C3C1A8FC69723DE992A3929A80E3922E91E7 ] FSORSPClient C:\Program Files (x86)\Kabel BW\apps\CCF_Reputation\fsorsp.exe
19:44:42.0943 0x30ec FSORSPClient - ok
19:44:43.0224 0x30ec [ DDEE99DC54EFA20BD5A442CD733C4462, 941D6C5D91F6419198F1A53BF7D33AA2D9118CEAC028B6ED8E5308751810B9B5 ] FsUsbExDisk C:\Windows\SysWOW64\FsUsbExDisk.SYS
19:44:43.0724 0x30ec FsUsbExDisk - ok
19:44:43.0802 0x30ec [ 6BF89A2514C10C19E72CF973FEC1948B, 3D61280F176C50E69A2443316989984063F3BBDD4626BBC08A1F583DBAFE8C54 ] fsvista C:\Program Files (x86)\Kabel BW\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys
19:44:43.0802 0x30ec fsvista - ok
19:44:44.0302 0x30ec Fs_Rec - ok
19:44:44.0302 0x30ec fvevol - ok
19:44:44.0333 0x30ec [ E403AACF8C7BB11375122D2464560311, 0427B8FFD999D256EA1A5135F218692959A7577CB32354D3087CF0FB4F0577DF ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
19:44:44.0333 0x30ec GEARAspiWDM - ok
19:44:44.0349 0x30ec gencounter - ok
19:44:44.0365 0x30ec genericusbfn - ok
19:44:44.0380 0x30ec GPIOClx0101 - ok
19:44:44.0396 0x30ec gpsvc - ok
19:44:44.0396 0x30ec GpuEnergyDrv - ok
19:44:44.0411 0x30ec HDAudBus - ok
19:44:44.0411 0x30ec HidBatt - ok
19:44:44.0427 0x30ec HidBth - ok
19:44:44.0443 0x30ec hidi2c - ok
19:44:44.0443 0x30ec hidinterrupt - ok
19:44:44.0443 0x30ec HidIr - ok
19:44:44.0443 0x30ec hidserv - ok
19:44:44.0458 0x30ec HidUsb - ok
19:44:44.0505 0x30ec [ 258DE302160DEEAFAB4453BB292CCF8F, A4333211D7B7FF8FAA630F5BA409564DC5C94E700E2AF59401D7E5BDE6B839EC ] hitmanpro37 C:\Windows\system32\drivers\hitmanpro37.sys
19:44:44.0505 0x30ec hitmanpro37 - ok
19:44:44.0521 0x30ec HomeGroupListener - ok
19:44:44.0521 0x30ec HomeGroupProvider - ok
19:44:44.0536 0x30ec HpSAMD - ok
19:44:44.0536 0x30ec HTTP - ok
19:44:44.0552 0x30ec HvHost - ok
19:44:44.0552 0x30ec hvservice - ok
19:44:44.0552 0x30ec hwpolicy - ok
19:44:44.0568 0x30ec hyperkbd - ok
19:44:44.0568 0x30ec i8042prt - ok
19:44:44.0568 0x30ec iagpio - ok
19:44:44.0568 0x30ec iai2c - ok
19:44:44.0568 0x30ec iaLPSS2i_GPIO2 - ok
19:44:44.0583 0x30ec iaLPSS2i_GPIO2_BXT_P - ok
19:44:44.0583 0x30ec iaLPSS2i_I2C - ok
19:44:44.0599 0x30ec iaLPSS2i_I2C_BXT_P - ok
19:44:44.0599 0x30ec iaLPSSi_GPIO - ok
19:44:44.0615 0x30ec iaLPSSi_I2C - ok
19:44:44.0708 0x30ec [ 87A72502C8AC5E89B5A46FF6E874F5C5, A72C8C96BA29B5894A3085CA2ADB6343FEFA79534B334416F8D4751CF8A30008 ] IAMTVE C:\WINDOWS\system32\drivers\IAMTVE.sys
19:44:44.0724 0x30ec IAMTVE - ok
19:44:44.0724 0x30ec iaStorAV - ok
19:44:44.0724 0x30ec iaStorV - ok
19:44:44.0740 0x30ec ibbus - ok
19:44:44.0755 0x30ec icssvc - ok
19:44:44.0771 0x30ec IKEEXT - ok
19:44:44.0787 0x30ec IndirectKmd - ok
19:44:44.0958 0x30ec [ 622868E4BAE8FBCD22CB1A5901A2C824, C1A2264C0984DD16C83B663C9CE43E049E1356E32C5771C3ACE225F285699138 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
19:44:45.0099 0x30ec IntcAzAudAddService - ok
19:44:45.0130 0x30ec [ A1E1304444BC82C827A09AEB393C0450, 920958A93361CCFA4E6697ECCD5C942E509A2B20316204DAF6D1006F97A9B1CF ] Intel(R) PROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
19:44:45.0599 0x30ec Intel(R) PROSet Monitoring Service - ok
19:44:45.0599 0x30ec intelide - ok
19:44:45.0615 0x30ec intelpep - ok
19:44:45.0646 0x30ec intelppm - ok
19:44:45.0677 0x30ec [ E45575812630B049CE0F679D87561A4D, 2645B87960DAA51295530ECF5518E5872B17520293068E7DEA064FEAE3884E87 ] ioatdma1 C:\WINDOWS\System32\Drivers\qd162x64.sys
19:44:45.0677 0x30ec ioatdma1 - ok
19:44:45.0693 0x30ec [ 2C23820DD9E81199E60F553EB50BC449, AF3847AD90A79E9D22DC67F4ED52B1D3FAF7C6420D60F2044C1FB49FD338BB70 ] ioatdma2 C:\WINDOWS\System32\Drivers\qd262x64.sys
19:44:45.0693 0x30ec ioatdma2 - ok
19:44:45.0693 0x30ec iorate - ok
19:44:45.0709 0x30ec IpFilterDriver - ok
19:44:45.0724 0x30ec iphlpsvc - ok
19:44:45.0740 0x30ec IPMIDRV - ok
19:44:45.0740 0x30ec IPNAT - ok
19:44:45.0834 0x30ec [ A9E19D4C0E9487544B0A87D511514DA9, 83767BA2A7EE1DE39DBF824B57D898355F8C5E3CE146CA280B0E336428837E70 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
19:44:45.0849 0x30ec iPod Service - ok
19:44:45.0865 0x30ec IpxlatCfgSvc - ok
19:44:45.0865 0x30ec irda - ok
19:44:45.0865 0x30ec IRENUM - ok
19:44:45.0865 0x30ec irmon - ok
19:44:45.0880 0x30ec isapnp - ok
19:44:45.0896 0x30ec iScsiPrt - ok
19:44:45.0896 0x30ec kbdclass - ok
19:44:45.0896 0x30ec kbdhid - ok
19:44:45.0912 0x30ec kdnic - ok
19:44:45.0927 0x30ec KeyIso - ok
19:44:45.0943 0x30ec KSecDD - ok
19:44:45.0943 0x30ec KSecPkg - ok
19:44:45.0959 0x30ec ksthunk - ok
19:44:45.0959 0x30ec KtmRm - ok
19:44:45.0974 0x30ec LanmanServer - ok
19:44:45.0974 0x30ec LanmanWorkstation - ok
19:44:45.0990 0x30ec lfsvc - ok
19:44:45.0990 0x30ec LicenseManager - ok
19:44:45.0990 0x30ec lltdio - ok
19:44:45.0990 0x30ec lltdsvc - ok
19:44:46.0005 0x30ec lmhosts - ok
19:44:46.0005 0x30ec LSI_SAS - ok
19:44:46.0005 0x30ec LSI_SAS2i - ok
19:44:46.0005 0x30ec LSI_SAS3i - ok
19:44:46.0037 0x30ec LSI_SSS - ok
19:44:46.0052 0x30ec LSM - ok
19:44:46.0052 0x30ec luafv - ok
19:44:46.0130 0x30ec [ A0A527569856B9814E8920F52EBB67F5, 4347277C84B47E4CC048850BDEFB258CFB3B476AA99FD503FD71FBB70FFF5ACF ] lvrs64 C:\WINDOWS\system32\DRIVERS\lvrs64.sys
19:44:46.0146 0x30ec lvrs64 - ok
19:44:46.0193 0x30ec MapsBroker - ok
19:44:46.0193 0x30ec mausbhost - ok
19:44:46.0193 0x30ec mausbip - ok
19:44:46.0224 0x30ec megasas - ok
19:44:46.0224 0x30ec megasas2i - ok
19:44:46.0240 0x30ec megasr - ok
19:44:46.0287 0x30ec [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
19:44:46.0287 0x30ec MEIx64 - ok
19:44:46.0302 0x30ec MessagingService - ok
19:44:46.0302 0x30ec mlx4_bus - ok
19:44:46.0318 0x30ec MMCSS - ok
19:44:46.0318 0x30ec Modem - ok
19:44:46.0349 0x30ec monitor - ok
19:44:46.0349 0x30ec mouclass - ok
19:44:46.0365 0x30ec mouhid - ok
19:44:46.0365 0x30ec mountmgr - ok
19:44:46.0412 0x30ec [ 86C9215967686BB8A6AEE8008D914BF8, 907A156AADC880F06EB7BBBC0C57EC14A205CEE43A2AD509F6BD4040CA4F327D ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
19:44:46.0412 0x30ec MozillaMaintenance - ok
19:44:46.0427 0x30ec mpsdrv - ok
19:44:46.0427 0x30ec MpsSvc - ok
19:44:46.0443 0x30ec MQAC - ok
19:44:46.0459 0x30ec MRxDAV - ok
19:44:46.0459 0x30ec mrxsmb - ok
19:44:46.0459 0x30ec mrxsmb10 - ok
19:44:46.0474 0x30ec mrxsmb20 - ok
19:44:46.0474 0x30ec MsBridge - ok
19:44:46.0490 0x30ec MSDTC - ok
19:44:46.0490 0x30ec Msfs - ok
19:44:46.0490 0x30ec msgpiowin32 - ok
19:44:46.0490 0x30ec mshidkmdf - ok
19:44:46.0505 0x30ec mshidumdf - ok
19:44:46.0505 0x30ec msisadrv - ok
19:44:46.0505 0x30ec MSiSCSI - ok
19:44:46.0505 0x30ec msiserver - ok
19:44:46.0537 0x30ec MSKSSRV - ok
19:44:46.0537 0x30ec MsLldp - ok
19:44:46.0568 0x30ec MSMQ - ok
19:44:46.0568 0x30ec MSPCLOCK - ok
19:44:46.0584 0x30ec MSPQM - ok
19:44:46.0584 0x30ec MsRPC - ok
19:44:46.0599 0x30ec mssmbios - ok
19:44:46.0599 0x30ec MSTEE - ok
19:44:46.0599 0x30ec MTConfig - ok
19:44:46.0599 0x30ec Mup - ok
19:44:46.0615 0x30ec mvumis - ok
19:44:46.0630 0x30ec NativeWifiP - ok
19:44:46.0630 0x30ec NaturalAuthentication - ok
19:44:46.0630 0x30ec NcaSvc - ok
19:44:46.0646 0x30ec NcbService - ok
19:44:46.0646 0x30ec NcdAutoSetup - ok
19:44:46.0646 0x30ec ndfltr - ok
19:44:46.0646 0x30ec NDIS - ok
19:44:46.0646 0x30ec NdisCap - ok
19:44:46.0662 0x30ec NdisImPlatform - ok
19:44:46.0662 0x30ec NdisTapi - ok
19:44:46.0662 0x30ec Ndisuio - ok
19:44:46.0662 0x30ec NdisVirtualBus - ok
19:44:46.0662 0x30ec NdisWan - ok
19:44:46.0677 0x30ec ndiswanlegacy - ok
19:44:46.0677 0x30ec ndproxy - ok
19:44:46.0677 0x30ec Ndu - ok
19:44:46.0677 0x30ec NetAdapterCx - ok
19:44:46.0677 0x30ec NetBIOS - ok
19:44:46.0693 0x30ec NetBT - ok
19:44:46.0709 0x30ec Netlogon - ok
19:44:46.0709 0x30ec Netman - ok
19:44:46.0912 0x30ec NetMsmqActivator - ok
19:44:46.0912 0x30ec NetPipeActivator - ok
19:44:46.0927 0x30ec netprofm - ok
19:44:46.0943 0x30ec NetSetupSvc - ok
19:44:46.0943 0x30ec NetTcpActivator - ok
19:44:46.0959 0x30ec NetTcpPortSharing - ok
19:44:46.0974 0x30ec netvsc - ok
19:44:46.0990 0x30ec NgcCtnrSvc - ok
19:44:46.0990 0x30ec NgcSvc - ok
19:44:46.0990 0x30ec NlaSvc - ok
19:44:47.0005 0x30ec Npfs - ok
19:44:47.0005 0x30ec npsvctrig - ok
19:44:47.0005 0x30ec nsi - ok
19:44:47.0021 0x30ec nsiproxy - ok
19:44:47.0037 0x30ec NTFS - ok
19:44:47.0037 0x30ec Null - ok
19:44:47.0052 0x30ec nvdimmn - ok
19:44:47.0084 0x30ec [ 56C8DEBA76DAA3E9D0D3CF861E2E2362, 7232A89D0A5BF7E86729F53EC85ACEA08B3AC6AE547873405B72751923CE1B0C ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
19:44:47.0084 0x30ec NVHDA - ok
19:44:48.0037 0x30ec [ F99ED2DDEED17D6FC478D1E7D85D5BE5, A462892646846747FFEDAA841F90693D0D83939B5D9D476E416572B817F93D7F ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nvmowu.inf_amd64_bf9b13c3decf0aa6\nvlddmkm.sys
19:44:48.0709 0x30ec nvlddmkm - ok
19:44:48.0771 0x30ec nvraid - ok
19:44:48.0771 0x30ec nvstor - ok
19:44:48.0787 0x30ec OneSyncSvc - ok
19:44:48.0974 0x30ec [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:44:48.0974 0x30ec ose - ok
19:44:49.0334 0x30ec [ FE9C0029E1AF26350D9985D00520E5C8, 967079CCF7B2CBD4B48C9F076675C26AF93A1CEC26C96811F279414E34004EE6 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
19:44:49.0490 0x30ec osppsvc - ok
19:44:49.0506 0x30ec p2pimsvc - ok
19:44:49.0521 0x30ec p2psvc - ok
19:44:49.0521 0x30ec Parport - ok
19:44:49.0521 0x30ec partmgr - ok
19:44:49.0537 0x30ec PcaSvc - ok
19:44:49.0553 0x30ec pci - ok
19:44:49.0553 0x30ec pciide - ok
19:44:49.0553 0x30ec pcmcia - ok
19:44:49.0553 0x30ec pcw - ok
19:44:49.0568 0x30ec pdc - ok
19:44:49.0584 0x30ec PEAUTH - ok
19:44:49.0584 0x30ec percsas2i - ok
19:44:49.0584 0x30ec percsas3i - ok
19:44:49.0834 0x30ec PerfHost - ok
19:44:49.0850 0x30ec PhoneSvc - ok
19:44:49.0865 0x30ec PimIndexMaintenanceSvc - ok
19:44:49.0865 0x30ec pla - ok
19:44:49.0881 0x30ec PlugPlay - ok
19:44:49.0881 0x30ec pmem - ok
19:44:49.0881 0x30ec PNRPAutoReg - ok
19:44:49.0881 0x30ec PNRPsvc - ok
19:44:49.0896 0x30ec PolicyAgent - ok
19:44:49.0928 0x30ec Power - ok
19:44:49.0928 0x30ec PptpMiniport - ok
19:44:50.0506 0x30ec [ 5404E7A968A26DF03793B6F68536594D, BE5A85581E87EFE4DB43AD17B8D42D3F7F32364AEEC1416DBB94279C4A203FF2 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
19:44:50.0553 0x30ec PrintNotify - ok
19:44:50.0584 0x30ec Processor - ok
19:44:50.0584 0x30ec ProfSvc - ok
19:44:50.0740 0x30ec [ 9CC2C93394241E602DA63826413055FF, 844FA885A2FF59758D5E97084AD81C48DFA2BBC39E4CDE7B04D200820426D7EA ] Prosieben C:\Program Files (x86)\maxdome\DCBin\DCService.exe
19:44:50.0740 0x30ec Prosieben - ok
19:44:50.0772 0x30ec Psched - ok
19:44:50.0818 0x30ec [ 65D32E9BBCC9FFD36F2BF38C595D283F, 185ADC9094D302B42C1B3080CCEDE16606027FDBE24FE9C70291291F2E38E3B1 ] qcusbser C:\WINDOWS\system32\DRIVERS\qcusbser.sys
19:44:50.0834 0x30ec qcusbser - ok
19:44:50.0850 0x30ec QWAVE - ok
19:44:50.0850 0x30ec QWAVEdrv - ok
19:44:50.0850 0x30ec RasAcd - ok
19:44:50.0865 0x30ec RasAgileVpn - ok
19:44:50.0865 0x30ec RasAuto - ok
19:44:50.0865 0x30ec Rasl2tp - ok
19:44:50.0881 0x30ec RasMan - ok
19:44:50.0881 0x30ec RasPppoe - ok
19:44:50.0881 0x30ec RasSstp - ok
19:44:50.0881 0x30ec rdbss - ok
19:44:50.0912 0x30ec rdpbus - ok
19:44:50.0912 0x30ec RDPDR - ok
19:44:50.0928 0x30ec RdpVideoMiniport - ok
19:44:50.0928 0x30ec rdyboost - ok
19:44:50.0943 0x30ec ReFS - ok
19:44:50.0943 0x30ec ReFSv1 - ok
19:44:50.0943 0x30ec RemoteAccess - ok
19:44:50.0959 0x30ec RemoteRegistry - ok
19:44:50.0959 0x30ec RetailDemo - ok
19:44:50.0959 0x30ec RmSvc - ok
19:44:50.0975 0x30ec RpcEptMapper - ok
19:44:50.0990 0x30ec RpcLocator - ok
19:44:50.0990 0x30ec RpcSs - ok
19:44:50.0990 0x30ec rspndr - ok
19:44:50.0990 0x30ec RTL8192su - ok
19:44:51.0006 0x30ec s3cap - ok
19:44:51.0006 0x30ec SamSs - ok
19:44:51.0006 0x30ec sbp2port - ok
19:44:51.0022 0x30ec SCardSvr - ok
19:44:51.0037 0x30ec ScDeviceEnum - ok
19:44:51.0037 0x30ec scfilter - ok
19:44:51.0037 0x30ec Schedule - ok
19:44:51.0037 0x30ec scmbus - ok
19:44:51.0037 0x30ec SCPolicySvc - ok
19:44:51.0068 0x30ec sdbus - ok
19:44:51.0084 0x30ec SDFRd - ok
19:44:51.0100 0x30ec SDRSVC - ok
19:44:51.0100 0x30ec sdstor - ok
19:44:51.0100 0x30ec seclogon - ok
19:44:51.0115 0x30ec SecurityHealthService - ok
19:44:51.0115 0x30ec SEMgrSvc - ok
19:44:51.0115 0x30ec SENS - ok
19:44:51.0131 0x30ec SensorDataService - ok
19:44:51.0131 0x30ec SensorService - ok
19:44:51.0147 0x30ec SensrSvc - ok
19:44:51.0147 0x30ec SerCx - ok
19:44:51.0147 0x30ec SerCx2 - ok
19:44:51.0147 0x30ec Serenum - ok
19:44:51.0162 0x30ec Serial - ok
19:44:51.0162 0x30ec sermouse - ok
19:44:51.0178 0x30ec SessionEnv - ok
19:44:51.0178 0x30ec sfloppy - ok
19:44:51.0256 0x30ec [ 21AB491BBCC8C1B26FDC402A374AB196, DD973C9963C840200D153A15078152D499639730D065BB8122C6BE65D4372300 ] Sftfs C:\WINDOWS\system32\DRIVERS\Sftfslh.sys
19:44:51.0272 0x30ec Sftfs - ok
19:44:51.0350 0x30ec [ 4E1BB8A9CCDB4BAF41F7F9A930EB121D, D994B20DACEB187BEB6530309E2185040B58105E4FD5AC1DA435712F9DE027D0 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
19:44:51.0365 0x30ec sftlist - ok
19:44:51.0397 0x30ec [ 3B8D43FEEFF7A187534DDDFD675FE123, 9308D5C552FE3AF1121A3F7B7595547C6B892FF500377953F3B623511D84698C ] Sftplay C:\WINDOWS\system32\DRIVERS\Sftplaylh.sys
19:44:51.0412 0x30ec Sftplay - ok
19:44:51.0428 0x30ec [ F1D1B1DC7A8765A09D7640FBF8D20970, 72E59B04BC44DAFFB88987C16CF3F9DC35438B15879E102FD83013673E0DB66F ] Sftredir C:\WINDOWS\system32\DRIVERS\Sftredirlh.sys
19:44:51.0428 0x30ec Sftredir - ok
19:44:51.0459 0x30ec [ B3B9ADE7F8C4AF0C20E712E040588543, 9A6BB11DA046BF6F0239952871263E148FAE91FB21065613645114B5FA054EC5 ] Sftvol C:\WINDOWS\system32\DRIVERS\Sftvollh.sys
19:44:51.0459 0x30ec Sftvol - ok
19:44:51.0490 0x30ec [ CECFDE5D3701B2D914862F5E6C3DFE18, E7627F90630C306324A39DC3C652B37D255F90636AC19D3302EE5B85BD504BD5 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
19:44:51.0490 0x30ec sftvsa - ok
19:44:51.0506 0x30ec SharedAccess - ok
19:44:51.0553 0x30ec ShellHWDetection - ok
19:44:51.0584 0x30ec shpamsvc - ok
19:44:51.0631 0x30ec simptcp - ok
19:44:51.0631 0x30ec SiSRaid2 - ok
19:44:51.0647 0x30ec SiSRaid4 - ok
19:44:51.0693 0x30ec [ B72B80E6FF423C5011E745CB76DA9A08, 18A6B9D46E91AD4D463EB5CB832702392D2E162577F90C328B515FCE69FABD15 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
19:44:51.0709 0x30ec SkypeUpdate - ok
19:44:51.0725 0x30ec smphost - ok
19:44:51.0740 0x30ec SmsRouter - ok
19:44:51.0756 0x30ec SNMPTRAP - ok
19:44:51.0803 0x30ec [ 5177D14A78E60FD61DCFC6B388E7E971, 19BE5CCF035C5E6C42DB299FBF39AB93E8B25AF56E903735D80F52FE7FFE8389 ] Sony PC Companion C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
19:44:51.0818 0x30ec Sony PC Companion - ok
19:44:51.0818 0x30ec spaceport - ok
19:44:51.0850 0x30ec SpatialGraphFilter - ok
19:44:51.0850 0x30ec SpbCx - ok
19:44:51.0865 0x30ec spectrum - ok
19:44:51.0881 0x30ec Spooler - ok
19:44:51.0881 0x30ec sppsvc - ok
19:44:51.0897 0x30ec srv - ok
19:44:51.0912 0x30ec srv2 - ok
19:44:51.0912 0x30ec srvnet - ok
19:44:51.0928 0x30ec SSDPSRV - ok
19:44:51.0959 0x30ec [ 0211AB46B73A2623B86C1CFCB30579AB, 7CC9BA2DF7B9EA6BB17EE342898EDD7F54703B93B6DED6A819E83A7EE9F938B4 ] SSPORT C:\Windows\system32\Drivers\SSPORT.sys
19:44:51.0959 0x30ec SSPORT - ok
19:44:51.0959 0x30ec SstpSvc - ok
19:44:51.0990 0x30ec [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
19:44:52.0006 0x30ec ssudmdm - ok
19:44:52.0022 0x30ec StateRepository - ok
19:44:52.0022 0x30ec stexstor - ok
19:44:52.0022 0x30ec stisvc - ok
19:44:52.0037 0x30ec storahci - ok
19:44:52.0053 0x30ec storflt - ok
19:44:52.0053 0x30ec stornvme - ok
19:44:52.0053 0x30ec storqosflt - ok
19:44:52.0053 0x30ec StorSvc - ok
19:44:52.0053 0x30ec storufs - ok
19:44:52.0069 0x30ec storvsc - ok
19:44:52.0069 0x30ec svsvc - ok
19:44:52.0069 0x30ec swenum - ok
19:44:52.0069 0x30ec swprv - ok
19:44:52.0084 0x30ec Synth3dVsc - ok
19:44:52.0084 0x30ec SysMain - ok
19:44:52.0100 0x30ec SystemEventsBroker - ok
19:44:52.0100 0x30ec TabletInputService - ok
19:44:52.0115 0x30ec TapiSrv - ok
19:44:52.0115 0x30ec Tcpip - ok
19:44:52.0115 0x30ec Tcpip6 - ok
19:44:52.0115 0x30ec tcpipreg - ok
19:44:52.0131 0x30ec tdx - ok
19:44:52.0147 0x30ec terminpt - ok
19:44:52.0147 0x30ec TermService - ok
19:44:52.0162 0x30ec Themes - ok
19:44:52.0178 0x30ec TieringEngineService - ok
19:44:52.0194 0x30ec tiledatamodelsvc - ok
19:44:52.0194 0x30ec TimeBrokerSvc - ok
19:44:52.0194 0x30ec TokenBroker - ok
19:44:52.0194 0x30ec TPM - ok
19:44:52.0194 0x30ec TrkWks - ok
19:44:52.0240 0x30ec TrustedInstaller - ok
19:44:52.0240 0x30ec TsUsbFlt - ok
19:44:52.0240 0x30ec TsUsbGD - ok
19:44:52.0256 0x30ec tunnel - ok
19:44:52.0272 0x30ec tzautoupdate - ok
19:44:52.0272 0x30ec UASPStor - ok
19:44:52.0272 0x30ec UcmCx0101 - ok
19:44:52.0272 0x30ec UcmTcpciCx0101 - ok
19:44:52.0287 0x30ec UcmUcsi - ok
19:44:52.0287 0x30ec Ucx01000 - ok
19:44:52.0303 0x30ec UdeCx - ok
19:44:52.0303 0x30ec udfs - ok
19:44:52.0303 0x30ec UEFI - ok
19:44:52.0303 0x30ec Ufx01000 - ok
19:44:52.0303 0x30ec UfxChipidea - ok
19:44:52.0319 0x30ec ufxsynopsys - ok
19:44:52.0319 0x30ec UI0Detect - ok
19:44:52.0319 0x30ec umbus - ok
19:44:52.0319 0x30ec UmPass - ok
19:44:52.0334 0x30ec UmRdpService - ok
19:44:52.0334 0x30ec UnistoreSvc - ok
19:44:52.0334 0x30ec upnphost - ok
19:44:52.0334 0x30ec UrsChipidea - ok
19:44:52.0334 0x30ec UrsCx01000 - ok
19:44:52.0350 0x30ec UrsSynopsys - ok
19:44:52.0381 0x30ec usbaudio - ok
19:44:52.0381 0x30ec usbccgp - ok
19:44:52.0381 0x30ec usbcir - ok
19:44:52.0397 0x30ec usbehci - ok
19:44:52.0397 0x30ec usbhub - ok
19:44:52.0412 0x30ec USBHUB3 - ok
19:44:52.0412 0x30ec usbohci - ok
19:44:52.0428 0x30ec usbprint - ok
19:44:52.0490 0x30ec [ 96B48485A7CC2C0A63C196A16403C5F3, 4E364DE1FE19D14D5BA4F4360563BB49F4DEC90430771C12376C0B1BB70CFD37 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
19:44:52.0506 0x30ec usbscan - ok
19:44:52.0506 0x30ec usbser - ok
19:44:52.0522 0x30ec USBSTOR - ok
19:44:52.0522 0x30ec usbuhci - ok
19:44:52.0537 0x30ec usbvideo - ok
19:44:52.0537 0x30ec USBXHCI - ok
19:44:52.0553 0x30ec UserDataSvc - ok
19:44:52.0553 0x30ec UserManager - ok
19:44:52.0569 0x30ec UsoSvc - ok
19:44:52.0569 0x30ec VaultSvc - ok
19:44:52.0569 0x30ec vdrvroot - ok
19:44:52.0569 0x30ec vds - ok
19:44:52.0569 0x30ec VerifierExt - ok
19:44:52.0584 0x30ec vhdmp - ok
19:44:52.0584 0x30ec vhf - ok
19:44:52.0584 0x30ec vmbus - ok
19:44:52.0584 0x30ec VMBusHID - ok
19:44:52.0600 0x30ec vmgid - ok
19:44:52.0600 0x30ec vmicguestinterface - ok
19:44:52.0600 0x30ec vmicheartbeat - ok
19:44:52.0600 0x30ec vmickvpexchange - ok
19:44:52.0615 0x30ec vmicrdv - ok
19:44:52.0615 0x30ec vmicshutdown - ok
19:44:52.0615 0x30ec vmictimesync - ok
19:44:52.0615 0x30ec vmicvmsession - ok
19:44:52.0615 0x30ec vmicvss - ok
19:44:52.0631 0x30ec volmgr - ok
19:44:52.0631 0x30ec volmgrx - ok
19:44:52.0631 0x30ec volsnap - ok
19:44:52.0647 0x30ec volume - ok
19:44:52.0647 0x30ec vpci - ok
19:44:52.0647 0x30ec vsmraid - ok
19:44:52.0647 0x30ec VSS - ok
19:44:52.0647 0x30ec VSTXRAID - ok
19:44:52.0662 0x30ec vwifibus - ok
19:44:52.0662 0x30ec vwififlt - ok
19:44:52.0678 0x30ec vwifimp - ok
19:44:52.0678 0x30ec W32Time - ok
19:44:52.0709 0x30ec w3logsvc - ok
19:44:52.0709 0x30ec W3SVC - ok
19:44:52.0725 0x30ec WacomPen - ok
19:44:52.0725 0x30ec WalletService - ok
19:44:52.0725 0x30ec wanarp - ok
19:44:52.0741 0x30ec wanarpv6 - ok
19:44:52.0741 0x30ec WAS - ok
19:44:52.0756 0x30ec wbengine - ok
19:44:52.0756 0x30ec WbioSrvc - ok
19:44:52.0756 0x30ec wcifs - ok
19:44:52.0756 0x30ec Wcmsvc - ok
19:44:52.0772 0x30ec wcncsvc - ok
19:44:52.0772 0x30ec wcnfs - ok
19:44:52.0787 0x30ec WdBoot - ok
19:44:52.0787 0x30ec Wdf01000 - ok
19:44:52.0787 0x30ec WdFilter - ok
19:44:52.0787 0x30ec WdiServiceHost - ok
19:44:52.0787 0x30ec WdiSystemHost - ok
19:44:52.0803 0x30ec wdiwifi - ok
19:44:52.0803 0x30ec WdNisDrv - ok
19:44:52.0819 0x30ec WdNisSvc - ok
19:44:52.0819 0x30ec WebClient - ok
19:44:52.0834 0x30ec Wecsvc - ok
19:44:52.0834 0x30ec WEPHOSTSVC - ok
19:44:52.0834 0x30ec wercplsupport - ok
19:44:52.0834 0x30ec WerSvc - ok
19:44:52.0834 0x30ec WFDSConMgrSvc - ok
19:44:52.0850 0x30ec WFPLWFS - ok
19:44:52.0850 0x30ec WiaRpc - ok
19:44:52.0850 0x30ec WIMMount - ok
19:44:52.0850 0x30ec WinDefend - ok
19:44:52.0866 0x30ec WindowsTrustedRT - ok
19:44:52.0866 0x30ec WindowsTrustedRTProxy - ok
19:44:52.0866 0x30ec WinHttpAutoProxySvc - ok
19:44:52.0866 0x30ec WinMad - ok
19:44:53.0006 0x30ec Winmgmt - ok
19:44:53.0022 0x30ec WinNat - ok
19:44:53.0022 0x30ec WinRM - ok
19:44:53.0037 0x30ec WINUSB - ok
19:44:53.0037 0x30ec WinVerbs - ok
19:44:53.0053 0x30ec wisvc - ok
19:44:53.0069 0x30ec WlanSvc - ok
19:44:53.0116 0x30ec [ 06C8FA1CF39DE6A735B54D906BA791C6, D8FEC7DE227781CDA876904701B2AA995268F74DCD6CB34AA0296C557FC283B6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
19:44:53.0131 0x30ec wlcrasvc - ok
19:44:53.0131 0x30ec wlidsvc - ok
19:44:53.0147 0x30ec wlpasvc - ok
19:44:53.0147 0x30ec WmiAcpi - ok
19:44:53.0162 0x30ec wmiApSrv - ok
19:44:53.0178 0x30ec WMPNetworkSvc - ok
19:44:53.0194 0x30ec [ 1AE1076034392218EE89D2744EC2A071, 695C28E2697B12BBD919687176CE082E94887A5D8B6229F163A26F6EDF401C4C ] Wof C:\WINDOWS\system32\drivers\Wof.sys
19:44:53.0241 0x30ec Wof - ok
19:44:53.0272 0x30ec workfolderssvc - ok
19:44:53.0287 0x30ec WPDBusEnum - ok
19:44:53.0287 0x30ec WpdUpFltr - ok
19:44:53.0303 0x30ec WpnService - ok
19:44:53.0303 0x30ec WpnUserService - ok
19:44:53.0319 0x30ec ws2ifsl - ok
19:44:53.0319 0x30ec wscsvc - ok
19:44:53.0319 0x30ec WSearch - ok
19:44:53.0350 0x30ec [ 82E8F5AA03DF7DBDB8A33F700D5D8CDA, 7EEB1B8F1430AFB06A18DC6107DBDD57EBBF473FF96F3578481EB89724823393 ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
19:44:53.0350 0x30ec wsvd - ok
19:44:53.0366 0x30ec wuauserv - ok
19:44:53.0366 0x30ec WudfPf - ok
19:44:53.0366 0x30ec WUDFRd - ok
19:44:53.0381 0x30ec wudfsvc - ok
19:44:53.0397 0x30ec WUDFWpdFs - ok
19:44:53.0412 0x30ec WwanSvc - ok
19:44:53.0412 0x30ec xbgm - ok
19:44:53.0412 0x30ec XblAuthManager - ok
19:44:53.0412 0x30ec XblGameSave - ok
19:44:53.0428 0x30ec xboxgip - ok
19:44:53.0428 0x30ec XboxGipSvc - ok
19:44:53.0428 0x30ec XboxNetApiSvc - ok
19:44:53.0428 0x30ec xinputhid - ok
19:44:53.0444 0x30ec ================ Scan global ===============================
19:44:53.0491 0x30ec [ Global ] - ok
19:44:53.0491 0x30ec ================ Scan MBR ==================================
19:44:53.0506 0x30ec [ 4624822E540EC83CD0819525C65846BA ] \Device\Harddisk0\DR0
19:44:55.0413 0x30ec \Device\Harddisk0\DR0 - ok
19:44:55.0413 0x30ec ================ Scan VBR ==================================
19:44:55.0428 0x30ec [ 5A106E6A3F3143486253408DA04CBE1B ] \Device\Harddisk0\DR0\Partition1
19:44:55.0428 0x30ec \Device\Harddisk0\DR0\Partition1 - ok
19:44:55.0475 0x30ec [ BC34077CC47F2941E29DE0BB28DB0CE3 ] \Device\Harddisk0\DR0\Partition2
19:44:55.0475 0x30ec \Device\Harddisk0\DR0\Partition2 - ok
19:44:55.0506 0x30ec [ ABABF2FFC8133BABC020654FC3E8F08F ] \Device\Harddisk0\DR0\Partition3
19:44:55.0506 0x30ec \Device\Harddisk0\DR0\Partition3 - ok
19:44:55.0506 0x30ec ================ Scan generic autorun ======================
19:44:55.0506 0x30ec SecurityHealth - ok
19:44:55.0975 0x30ec [ 65E8545F1297CD83534C354A7BED1848, 19B3F3C17A335837454DC1851C6436D0BB2D8B1595AEB4DC71265FB20868B48F ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
19:44:56.0178 0x30ec RTHDVCPL - ok
19:44:56.0366 0x30ec [ BE0481F3AC3BCA5479ACE97586922FEA, E1C30AA1277CB7013B429B3767A5951BEFA46457F145A34AD3564BDA57442439 ] C:\Program Files (x86)\Connectify\Connectify.exe
19:44:56.0522 0x30ec Connectify Hotspot - ok
19:44:56.0569 0x30ec [ 1710A603D1EEBF86D738D1C6283C39B3, 5427A41AB64122FC119A42D7E4954A04A650FE88BD2B7FD2D4CDD1E823433268 ] C:\Program Files\iTunes\iTunesHelper.exe
19:44:56.0569 0x30ec iTunesHelper - ok
19:44:56.0616 0x30ec [ 9D51EA92A612B37E76E5E4621650C50A, 00BD61C8527A80C0F684882379A0AC2E5A54E8BBECC797087B960CDC8454C373 ] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
19:44:56.0616 0x30ec NUSB3MON - ok
19:44:56.0678 0x30ec [ 57B4D34232852BFE4453BE571DF90D21, 3D329499D7BCACAE5F6377F988B90714F5A8301784CDB22D5B54A2266AC50D79 ] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
19:44:56.0694 0x30ec CLMLServer - ok
19:44:57.0053 0x30ec [ D5EB6E4154952E64C215B5D8BCE06432, 7F0B94ED4AA314274EDFEFAA384DA54BAC8A78B832808F3EF03308F78404FFE0 ] C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
19:44:57.0132 0x30ec Dropbox - ok
19:44:57.0257 0x30ec [ 6EACC43D0542EF88226FB34B0B12EDB0, 6345E4B49D7F804F6DE042F981AB172822B6AB74C42209BEFB0582B019430884 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
19:44:57.0272 0x30ec SunJavaUpdateSched - ok
19:44:57.0538 0x30ec OneDriveSetup - ok
19:44:57.0538 0x30ec OneDriveSetup - ok
19:44:57.0632 0x30ec [ D8BDC69358924D3EC576BADA7DEAEE4A, DBFD1E043D3E542E2EB2F28B2D3188858FA383349BD03C3CA86BBA745E4F2CA1 ] C:\Program Files (x86)\virenschutz\winpatrol\winpatrol.exe
19:44:57.0632 0x30ec WinPatrol - ok
19:44:58.0429 0x30ec [ 40F7401928355A1515199676A5D00CDC, 4F16DE77F0BD7D1F9F61AE5712B3FD7BD53D19DCCEF88925E10180EF040A8E0B ] C:\Users\Andrea und Hans-Jörg\AppData\Local\Apps\2.0\RT16E079.BTE\A36OHZT3.1YV\frit..tion_b5355c80db433451_0002.0003_6ff5e44d5e38db65\AVMAutoStart.exe
19:44:58.0444 0x30ec AVMUSBFernanschluss - ok
19:44:58.0554 0x30ec [ C5D30E88C97825CF0652B60C42F103AD, D605DC9021021714BDA36EF48C335F85C77F85474A21B6E5258270E1703B8DC8 ] C:\Users\Andrea und Hans-Jörg\AppData\Local\Microsoft\OneDrive\OneDrive.exe
19:44:58.0600 0x30ec OneDrive - ok
19:44:58.0975 0x30ec OneDriveSetup - ok
19:44:59.0210 0x30ec [ FD9A7F99A09DB266D0C1361B0ACCBD7E, 579160BDACDFE39AE5DDD7B5C2964453E89BA8D933F3FB16C6E3897EA3BDED29 ] C:\Users\otto\AppData\Local\Microsoft\OneDrive\OneDrive.exe
19:44:59.0257 0x30ec OneDrive - ok
19:44:59.0444 0x30ec WAB Migrate - ok
19:44:59.0444 0x30ec OneDriveSetup - ok
19:44:59.0554 0x30ec [ FCDE60F22FF7B5BEB55770208565B199, 841ED4610B6EF9968CFCFFCF252674297B661DF012BABB0D22938F9445B5AFF5 ] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
19:44:59.0569 0x30ec KiesPDLR - ok
19:44:59.0569 0x30ec WAB Migrate - ok
19:44:59.0569 0x30ec OneDriveSetup - ok
19:44:59.0569 0x30ec WAB Migrate - ok
19:44:59.0569 0x30ec Waiting for KSN requests completion. In queue: 12
19:45:00.0616 0x30ec AV detected via SS2: Computer Schutz by F-Secure, C:\Program Files (x86)\Kabel BW\apps\ComputerSecurity\Anti-Virus\fsavwsch.exe ( 11.0.22350.0 ), 0x41000 ( enabled : updated )
19:45:00.0663 0x30ec AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.11.15063.332 ), 0x60100 ( disabled : updated )
19:45:00.0679 0x30ec Win FW state via NFP2: enabled ( trusted )
19:45:00.0820 0x30ec ============================================================
19:45:00.0820 0x30ec Scan finished
19:45:00.0820 0x30ec ============================================================
19:45:00.0820 0x30c0 Detected object count: 0
19:45:00.0820 0x30c0 Actual detected object count: 0 |