Laptop very slow

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #76
    Originally posted by siq
    Should I scan every single file? There are 34 files for H:\641c8f59b6c1076160953ca76b alone
    No, can you post a screen shot of what is inside please. Then just scan a couple of them for me, if there are any .exe or .dll in the folder. I had no idea that there were that many files inside.

    Might be a good idea to scan the external HDD’s with Zemana to be honest.

    Zemana Deep Scan

    [ul]
    [li]
    • [/li][li]Right click on Zemana and run as admin.[/li][/ul]
      [ul]
      [li]Click the Cog/Sproket Wheel, at the top right of Zemana[/li][/ul]
      [ul]
      [li]Select Advanced - I have read the warning and wish to proceed.[/li][/ul]
      [ul]
      [li]Place a tick next to Detect Suspicious (Root CA) Certificates.[/li][/ul]
      [ul]
      [li]Then click the house icon in Zemana.[/li][/ul]
      [ul]
      [li]Then hit your start button at the lower left hand corner of your desktop.[/li][/ul]
      [ul]
      [li]Then left click on Computer.[/li][/ul]
      [ul]
      [li]Drag Local Disk C: or whichever drive you decide to check first.[/li]

      [li] Into the area of Zemana that reads Drag and drop files here to scan them.[/li][/ul]
      [ul]
      [li]http://i.imgur.com/bOVO6lY.png[/li][/ul]
      [ul]
      [li]Once the scan has completed click graph icon on the top right of the programs User interface.[/li][/ul]
      [ul]
      [li]Double click to open the latest log-file.[/li][/ul]
      [ul]
      [li]Copy it to your clipboard.[/li][/ul]
      [ul]
      [li]Post the log here in your next reply.[/li][/ul]
    • Originally posted by siq
      Also which program produced the shortcut.txt?
      [li][/li]

    FRST will have produced a shortcut.txt you can see by clicking this link when I requested it. Once you have caught up, then I will provide instructions to remove the telelmetry diagtrack gwx stuff from the machine.

    Comment

    • siq
      PCHF Member
      • Jan 2017
      • 49

      #77
      [MEDIA=imgur]a/XUkEM[/MEDIA]

      [MEDIA=imgur]Ar7awnf[/MEDIA]

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #78
        Seems like these are all files related to Microsoft
        I’d say scan them with Zemana when you have time.
        Also, right click those folders one at a time and scan with Malwarebytes.
        There is waaay to much stuff to be scanning at virustotal.
        I have a feeling that they are fine to be honest, just scan them with Zemana and Malwarebytes to be sure.

        Here is your fixlist to remove the Telemetry nonsense.

        Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

        Comment

        • Malnutrition
          PCHF Moderator
          • Jul 2016
          • 7041

          #79
          After you run the Fix above…

          Fresh FRST Logs.


          Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

          [ul]
          [li]Right-click on FRST icon and select Run as Administrator to start the tool.[/li](XP users click run after receipt of Windows Security Warning - Open File).
          [li]Make sure that Addition option is checked, as well as Shortcut.txt.[/li]
          [li]Press Scan button and wait.[/li][li]The tool will produce three logfiles on your desktop: FRST.txt, and Addition.txt – & Shortcut.txt[/li][/ul]
          Please Copy & Paste them into your next reply. But attach Shortcut.txt

          Comment

          • siq
            PCHF Member
            • Jan 2017
            • 49

            #80
            [HEADING=1]Fix result of Farbar Recovery Scan Tool (x64) Version: 15-02-2017 02
            Ran by Philipp (17-02-2017 06:39:06) Run:4
            Running from C:\Users\Philipp\Desktop\Neuer Ordner
            Loaded Profiles: Philipp (Available Profiles: Philipp)
            Boot Mode: Normal[/HEADING]
            fixlist content:


            start
            CloseProcesses:
            createrestorepoint:
            emptytemp:
            C:\Windows\winsxs\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23459_none_ba4cea3a f46ee78c
            C:\Windows\winsxs\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23459_none_0bb bac1e2b49b4a7
            C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e
            C:\Windows\Logs\Gwx
            C:\Windows\System32\Tasks\Microsoft\Windows\Setup\ gwx
            C:\System Volume Information\SystemRestore\FRStaging\Windows\System 32\Tasks\Microsoft\Windows\Setup\GWXTriggers
            C:\Windows\System32\Tasks\Microsoft\Windows\Setup\ GWXTriggers
            C:\Windows\winsxs\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_19563044b a7b9b99
            C:\Windows\winsxs\FileMaps$$_system32_gwx_06654c71 d047de88.cdf-ms
            C:\Windows\winsxs\FileMaps$$_system32_gwx_download _27d68082ad334184.cdf-ms
            C:\Windows\winsxs\FileMaps$$_system32_gwx_download swap_5098c1f0e1204caf.cdf-ms
            C:\Windows\winsxs\FileMaps$$_syswow64_gwx_1bf23be3 a76673bc.cdf-ms
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-ins_31bf3856ad364e35_6.1.7601.23459_none_a8ecb4308 17f12e3.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23459_none_ba4cea3a f46ee78c.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23459_none_0bb bac1e2b49b4a7.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e.manifest
            C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWX.exe
            C:\Windows\winsxs\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_19563044b a7b9b99\GWX.exe
            C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXConfigManager.exe
            C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXDetector.exe
            C:\Windows\winsxs\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23459_none_0bb bac1e2b49b4a7\GWXGC.exe
            C:\Windows\Migration\WTR\GWXMig.inf
            C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXUI.dll
            C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXUX.exe
            C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXUXWorker.exe
            C:\Windows\System32\winevt\Logs\Microsoft-Windows-GWX-Ins%4Operational.evtx
            C:\System Volume Information\SystemRestore\FRStaging\Windows\System 32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refre shgwxconfig-B
            C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_19563044b a7b9b99.manifest
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18444_none_e5b 1b7ec100d8e3b
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18467_none_e59 f18f2101b1222
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18803_none_e5d bfeea0fedf9bc
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18868_none_e5a 020d4101a2015
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18917_none_e5d 5320c0ff27830
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18942_none_e5a fc0d6100f4d50
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18944_none_e5b 1c16a100d7ffe
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23468_none_e62 99d592937e7bd
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18444_none_66295be4 60b59c2a
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18467_none_6616bcea 60c32011
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18803_none_6653a2e2 609607ab
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18868_none_6617c4cc 60c22e04
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18917_none_664cd604 609a861f
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18942_none_662764ce 60b75b3f
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18944_none_66296562 60b58ded
            F:\Windows\winsxs\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7600.16385_none_2e61438 480527d71
            C:\Windows\winsxs\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b
            F:\Windows\winsxs\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845 bb1d97efda
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de8 2236c5fac8
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d
            C:\Windows\AppCompat\Appraiser\Telemetry
            C:\Windows\winsxs\FileMaps$$_appcompat_appraiser_t elemetry_94274e99519f58a9.cdf-ms
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18444_none_e5b 1b7ec100d8e3b.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18467_none_e59 f18f2101b1222.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18803_none_e5d bfeea0fedf9bc.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18868_none_e5a 020d4101a2015.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18917_none_e5d 5320c0ff27830.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18942_none_e5a fc0d6100f4d50.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18944_none_e5b 1c16a100d7ffe.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23412_none_e65 9ab392914c3fe.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23468_none_e62 99d592937e7bd.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18444_none_66295be4 60b59c2a.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18467_none_6616bcea 60c32011.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18803_none_6653a2e2 609607ab.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18868_none_6617c4cc 60c22e04.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18917_none_664cd604 609a861f.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18942_none_662764ce 60b75b3f.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18944_none_66296562 60b58ded.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.23412_none_66d14f31 79bcd1ed.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.23468_none_66a14151 79dff5ac.manifest
            F:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7600.16385_none_2e61438 480527d71.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b.manifest
            F:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845 bb1d97efda.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de8 2236c5fac8.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149.manifest
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d.manifest
            C:\System Volume Information\SystemRestore\FRStaging\Windows\AppCom pat\Appraiser\APPRAISER_TelemetryBaseline_RS1.bin
            C:\Windows\AppCompat\Appraiser\APPRAISER_Telemetry Baseline_RS1.bin
            C:\System Volume Information\SystemRestore\FRStaging\Windows\AppCom pat\Appraiser\APPRAISER_TelemetryBaseline_TH2.bin
            C:\Windows\AppCompat\Appraiser\APPRAISER_Telemetry Baseline_TH2.bin
            C:\System Volume Information\SystemRestore\FRStaging\Windows\AppCom pat\Appraiser\APPRAISER_TelemetryBaseline_UNV.bin
            C:\Windows\AppCompat\Appraiser\APPRAISER_Telemetry Baseline_UNV.bin
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-inventory.data_31bf3856ad364e35_6.1.7601.23468_non e_b78b2be646720e6a\Appraiser_TelemetryRunList.xml
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18868_none_e83 d75d9e59ba1ea\CompatTelemetry.inf
            C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx
            F:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx
            C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-Skype.json
            C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-WindowsDefault.json
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845 bb1d97efda\telemetry.ASM-WindowsDefault.json
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01\telemetry.ASM-WindowsDefault.json
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de8 2236c5fac8\telemetry.ASM-WindowsDefault.json
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d\telemetry.ASM-WindowsDefault.json
            C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-WindowsDefault.json.bk
            C:\Windows\System32\Tasks\Microsoft\Windows\Applic ation Experience
            C:\Windows\System32\Tasks\Microsoft\Windows\Custom er Experience Improvement Program
            C:\Windows\System32\Tasks\Microsoft\Windows\Setup\ gwx
            C:\Windows\System32\Tasks\Microsoft\Windows\Setup\ GWXTriggers
            C:\Windows\System32\Tasks\Microsoft\Windows\Custom er Experience Improvement Program\Consolidator
            C:\Windows\System32\Tasks\Microsoft\Windows\DiskDi agnostic\Microsoft-Windows-DiskDiagnosticDataCollector
            C:\Windows\System32\Tasks\Microsoft\Windows\DiskDi agnostic\Microsoft-Windows-DiskDiagnosticResolver
            C:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLog ger\AutoLogger-Diagtrack-Listener.etl
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18803_none_e87 953efe56f7b91\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18868_none_e83 d75d9e59ba1ea\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18917_none_e87 28711e573fa05\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18942_none_e84 d15dbe590cf25\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18944_none_e84 f166fe58f01d3\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23468_none_e8c 6f25efeb96992\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845 bb1d97efda\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de8 2236c5fac8\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d\diagtrack.dll
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18803_none_e87 953efe56f7b91\diagtrackrunner.exe
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23468_none_e8c 6f25efeb96992\diagtrackrunner.exe
            C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDia gtrack-Listener.etl
            emptytemp:
            reboot:
            end


            Processes closed successfully.
            Restore point was successfully created.
            C:\Windows\winsxs\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23459_none_ba4cea3a f46ee78c => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23459_none_0bb bac1e2b49b4a7 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e => moved successfully
            C:\Windows\Logs\Gwx => moved successfully
            C:\Windows\System32\Tasks\Microsoft\Windows\Setup\ gwx => moved successfully
            C:\System Volume Information\SystemRestore\FRStaging\Windows\System 32\Tasks\Microsoft\Windows\Setup\GWXTriggers => moved successfully
            C:\Windows\System32\Tasks\Microsoft\Windows\Setup\ GWXTriggers => moved successfully
            C:\Windows\winsxs\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_19563044b a7b9b99 => moved successfully
            C:\Windows\winsxs\FileMaps$$_system32_gwx_06654c71 d047de88.cdf-ms => moved successfully
            C:\Windows\winsxs\FileMaps$$_system32_gwx_download _27d68082ad334184.cdf-ms => moved successfully
            C:\Windows\winsxs\FileMaps$$_system32_gwx_download swap_5098c1f0e1204caf.cdf-ms => moved successfully
            C:\Windows\winsxs\FileMaps$$_syswow64_gwx_1bf23be3 a76673bc.cdf-ms => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-ins_31bf3856ad364e35_6.1.7601.23459_none_a8ecb4308 17f12e3.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23459_none_ba4cea3a f46ee78c.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23459_none_0bb bac1e2b49b4a7.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e.manifest => moved successfully
            “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWX.exe” => not found.
            “C:\Windows\winsxs\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_19563044b a7b9b99\GWX.exe” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXConfigManager.exe” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXDetector.exe” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23459_none_0bb bac1e2b49b4a7\GWXGC.exe” => not found.
            C:\Windows\Migration\WTR\GWXMig.inf => moved successfully
            “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXUI.dll” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXUX.exe” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_0f0185f28 61ad99e\GWXUXWorker.exe” => not found.
            C:\Windows\System32\winevt\Logs\Microsoft-Windows-GWX-Ins%4Operational.evtx => moved successfully
            C:\System Volume Information\SystemRestore\FRStaging\Windows\System 32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refre shgwxconfig-B => moved successfully
            C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23459_none_19563044b a7b9b99.manifest => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18444_none_e5b 1b7ec100d8e3b => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18467_none_e59 f18f2101b1222 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18803_none_e5d bfeea0fedf9bc => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18868_none_e5a 020d4101a2015 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18917_none_e5d 5320c0ff27830 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18942_none_e5a fc0d6100f4d50 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18944_none_e5b 1c16a100d7ffe => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23468_none_e62 99d592937e7bd => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18444_none_66295be4 60b59c2a => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18467_none_6616bcea 60c32011 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18803_none_6653a2e2 609607ab => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18868_none_6617c4cc 60c22e04 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18917_none_664cd604 609a861f => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18942_none_662764ce 60b75b3f => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18944_none_66296562 60b58ded => moved successfully
            F:\Windows\winsxs\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7600.16385_none_2e61438 480527d71 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b => moved successfully
            F:\Windows\winsxs\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845 bb1d97efda => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de8 2236c5fac8 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149 => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d => moved successfully
            C:\Windows\AppCompat\Appraiser\Telemetry => moved successfully
            C:\Windows\winsxs\FileMaps$$_appcompat_appraiser_t elemetry_94274e99519f58a9.cdf-ms => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18444_none_e5b 1b7ec100d8e3b.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18467_none_e59 f18f2101b1222.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18803_none_e5d bfeea0fedf9bc.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18868_none_e5a 020d4101a2015.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18917_none_e5d 5320c0ff27830.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18942_none_e5a fc0d6100f4d50.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18944_none_e5b 1c16a100d7ffe.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23412_none_e65 9ab392914c3fe.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23468_none_e62 99d592937e7bd.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18444_none_66295be4 60b59c2a.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18467_none_6616bcea 60c32011.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18803_none_6653a2e2 609607ab.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18868_none_6617c4cc 60c22e04.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18917_none_664cd604 609a861f.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18942_none_662764ce 60b75b3f.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18944_none_66296562 60b58ded.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.23412_none_66d14f31 79bcd1ed.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.23468_none_66a14151 79dff5ac.manifest => moved successfully
            F:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7600.16385_none_2e61438 480527d71.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b.manifest => moved successfully
            F:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845 bb1d97efda.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de8 2236c5fac8.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149.manifest => moved successfully
            C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d.manifest => moved successfully
            C:\System Volume Information\SystemRestore\FRStaging\Windows\AppCom pat\Appraiser\APPRAISER_TelemetryBaseline_RS1.bin => moved successfully
            C:\Windows\AppCompat\Appraiser\APPRAISER_Telemetry Baseline_RS1.bin => moved successfully
            C:\System Volume Information\SystemRestore\FRStaging\Windows\AppCom pat\Appraiser\APPRAISER_TelemetryBaseline_TH2.bin => moved successfully
            C:\Windows\AppCompat\Appraiser\APPRAISER_Telemetry Baseline_TH2.bin => moved successfully
            C:\System Volume Information\SystemRestore\FRStaging\Windows\AppCom pat\Appraiser\APPRAISER_TelemetryBaseline_UNV.bin => moved successfully
            C:\Windows\AppCompat\Appraiser\APPRAISER_Telemetry Baseline_UNV.bin => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..ence-inventory.data_31bf3856ad364e35_6.1.7601.23468_non e_b78b2be646720e6a\Appraiser_TelemetryRunList.xml => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18868_none_e83 d75d9e59ba1ea\CompatTelemetry.inf => moved successfully
            Could not move “C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx” => Scheduled to move on reboot.
            F:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx => moved successfully
            C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-Skype.json => moved successfully
            C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-WindowsDefault.json => moved successfully
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845 bb1d97efda\telemetry.ASM-WindowsDefault.json” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01\telemetry.ASM-WindowsDefault.json” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de8 2236c5fac8\telemetry.ASM-WindowsDefault.json” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d\telemetry.ASM-WindowsDefault.json” => not found.
            C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-WindowsDefault.json.bk => moved successfully
            C:\Windows\System32\Tasks\Microsoft\Windows\Applic ation Experience => moved successfully
            C:\Windows\System32\Tasks\Microsoft\Windows\Custom er Experience Improvement Program => moved successfully
            “C:\Windows\System32\Tasks\Microsoft\Windows\Setup \gwx” => not found.
            “C:\Windows\System32\Tasks\Microsoft\Windows\Setup \GWXTriggers” => not found.
            “C:\Windows\System32\Tasks\Microsoft\Windows\Custo mer Experience Improvement Program\Consolidator” => not found.
            C:\Windows\System32\Tasks\Microsoft\Windows\DiskDi agnostic\Microsoft-Windows-DiskDiagnosticDataCollector => moved successfully
            C:\Windows\System32\Tasks\Microsoft\Windows\DiskDi agnostic\Microsoft-Windows-DiskDiagnosticResolver => moved successfully
            C:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLog ger\AutoLogger-Diagtrack-Listener.etl => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18803_none_e87 953efe56f7b91\diagtrack.dll => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18868_none_e83 d75d9e59ba1ea\diagtrack.dll => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18917_none_e87 28711e573fa05\diagtrack.dll => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18942_none_e84 d15dbe590cf25\diagtrack.dll => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18944_none_e84 f166fe58f01d3\diagtrack.dll => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23468_none_e8c 6f25efeb96992\diagtrack.dll => moved successfully
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18839_none_fe0845 bb1d97efda\diagtrack.dll” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad\diagtrack.dll” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01\diagtrack.dll” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23040_none_fe7de8 2236c5fac8\diagtrack.dll” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149\diagtrack.dll” => not found.
            “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d\diagtrack.dll” => not found.
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18803_none_e87 953efe56f7b91\diagtrackrunner.exe => moved successfully
            C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23468_none_e8c 6f25efeb96992\diagtrackrunner.exe => moved successfully
            “C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDi agtrack-Listener.etl” => not found.

            =========== EmptyTemp: ==========

            BITS transfer queue => 8388608 B
            DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5998882 B
            Java, Flash, Steam htmlcache => 88944953 B
            Windows/system/drivers => 0 B
            Edge => 0 B
            Chrome => 367823561 B
            Firefox => 0 B
            Opera => 0 B

            Temp, IE cache, history, cookies, recent:
            Users => 0 B
            Default => 0 B
            Public => 0 B
            ProgramData => 0 B
            systemprofile => 82679 B
            systemprofile32 => 759 B
            LocalService => 0 B
            NetworkService => 0 B
            Philipp => 4315605 B
            UpdatusUser => 0 B

            RecycleBin => 365255 B
            EmptyTemp: => 453.9 MB temporary data Removed.

            ================================

            Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 17-02-2017 06:40:22)

            C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx => Is moved successfully

            ==== End of Fixlog 06:40:22 ====

            Comment

            • siq
              PCHF Member
              • Jan 2017
              • 49

              #81
              Zemana’s trial has ended, I can’t scan the drives

              Comment

              • Malnutrition
                PCHF Moderator
                • Jul 2016
                • 7041

                #82
                Originally posted by siq
                Zemana’s trial has ended, I can’t scan the drives
                The trial does not matter, the only thing that expires is the real time protection.
                You should still be able to scan the drives.
                How is the machine running otherwise?

                Comment

                • siq
                  PCHF Member
                  • Jan 2017
                  • 49

                  #83

                  Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-02-2017 02
                  [/quote]


                  Ran by Philipp (administrator) on PHILIPP-PC (17-02-2017 07:00:00)
                  Running from C:\Users\Philipp\Desktop\Neuer Ordner
                  Loaded Profiles: Philipp (Available Profiles: Philipp)
                  Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Deutsch (Deutschland)
                  Internet Explorer Version 9 (Default browser: Chrome)
                  Boot Mode: Normal
                  Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

                  ==================== Processes (Whitelisted) =================

                  (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

                  (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
                  (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
                  (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
                  (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
                  (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
                  (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
                  (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
                  (Microsoft Corporation) C:\Windows\System32\wlanext.exe
                  () C:\Program Files\Everything\Everything.exe
                  (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
                  (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
                  (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
                  () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
                  (Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
                  (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
                  (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                  (Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
                  (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
                  (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
                  (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
                  (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
                  (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
                  (Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
                  (Spotify Ltd) C:\Users\Philipp\AppData\Roaming\Spotify\Spotify.e xe
                  (Spotify Ltd) C:\Users\Philipp\AppData\Roaming\Spotify\SpotifyWe bHelper.exe
                  (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
                  (Spotify Ltd) C:\Users\Philipp\AppData\Roaming\Spotify\SpotifyCr ashService.exe
                  (Spotify Ltd) C:\Users\Philipp\AppData\Roaming\Spotify\Spotify.e xe
                  (Spotify Ltd) C:\Users\Philipp\AppData\Roaming\Spotify\Spotify.e xe
                  (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  (Farbar) C:\Users\Philipp\Desktop\Neuer Ordner\EnglishFRST64.exe
                  (Microsoft Corporation) C:\Windows\System32\dllhost.exe

                  ==================== Registry (Whitelisted) ====================

                  (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

                  HKLM...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
                  HKLM-x32...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111312 2016-06-13] (AVAST Software)
                  HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\Run: [Spotify] => C:\Users\Philipp\AppData\Roaming\Spotify\Spotify.e xe [7133808 2017-02-04] (Spotify Ltd)
                  HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [9292504 2016-12-21] (Piriform Ltd)
                  HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\Run: [Spotify Web Helper] => C:\Users\Philipp\AppData\Roaming\Spotify\SpotifyWe bHelper.exe [1446000 2017-02-04] (Spotify Ltd)
                  ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] → {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
                  ShellIconOverlayIdentifiers: [ GoogleDriveSynced] → {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
                  ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] → {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
                  ShellIconOverlayIdentifiers: [00avast] → {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-07] (AVAST Software)

                  ==================== Internet (Whitelisted) ====================

                  (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

                  Tcpip..\Interfaces{416F4EA8-7EBE-4A41-BD73-DD7E680B9773}: [DhcpNameServer] 192.168.0.1
                  [HEADING=1]Internet Explorer:[/HEADING]
                  BHO: Windows Live ID Sign-in Helper → {9030D464-4C02-4ABF-8ECC-5164760863C6} → C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
                  BHO: Office Document Cache Handler → {B4F3A835-0E21-4959-BA22-42B3008E02FF} → C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
                  BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm → {9030D464-4C02-4ABF-8ECC-5164760863C6} → C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
                  BHO-x32: Office Document Cache Handler → {B4F3A835-0E21-4959-BA22-42B3008E02FF} → C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
                  [HEADING=1]FireFox:[/HEADING]
                  FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\q87ndktt.default [2017-02-03]
                  FF Extension: (Firefox Hotfix) - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\q87ndktt.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-11-26]
                  FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\q87ndktt.default\searchplugins\google-avast.xml [2015-05-14]
                  FF HKLM-x32...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
                  FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-08-07] [not signed]
                  FF Plugin: @adobe.com/FlashPlayer → C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_ 194.dll [2017-01-14] ()
                  FF Plugin: @esn/npbattlelog,version=2.5.1 → C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll [2014-09-01] (EA Digital Illusions CE AB)
                  FF Plugin: @esn/npbattlelog,version=2.6.2 → C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2014-12-03] (EA Digital Illusions CE AB)
                  FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 → C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
                  FF Plugin-x32: @adobe.com/FlashPlayer → C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_ 194.dll [2017-01-14] ()
                  FF Plugin-x32: @esn/npbattlelog,version=2.5.1 → C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll [2014-09-01] (EA Digital Illusions CE AB)
                  FF Plugin-x32: @esn/npbattlelog,version=2.6.2 → C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2014-12-03] (EA Digital Illusions CE AB)
                  FF Plugin-x32: @microsoft.com/GENUINE → disabled [No File]
                  FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 → C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
                  FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 → C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
                  FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 → C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
                  FF Plugin-x32: Adobe Reader → C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
                  [HEADING=1]Chrome:[/HEADING]
                  CHR HomePage: Default → hxxp://www.google.com/
                  CHR StartupUrls: Default → “hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP”
                  CHR DefaultSearchKeyword: Default → http://www.google.com/
                  CHR Profile: C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default [2017-02-17]
                  CHR Extension: (Google Präsentationen) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhon fmgoek [2017-02-09]
                  CHR Extension: (Theme Creator) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc [2017-02-12]
                  CHR Extension: (Google Docs) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfi lokake [2017-02-09]
                  CHR Extension: (Google Drive) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigk jlhalf [2017-02-09]
                  CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp [2017-02-12]
                  CHR Extension: (YouTube) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldk acnbeo [2017-02-09]
                  CHR Extension: (uBlock Origin) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm [2017-02-12]
                  CHR Extension: (Avast SafePrice) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck [2017-02-09]
                  CHR Extension: (Google Tabellen) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpeb giejap [2017-02-09]
                  CHR Extension: (Google Docs Offline) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdl olhkhi [2017-02-11]
                  CHR Extension: (AdBlock) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbi glidom [2017-02-16]
                  CHR Extension: (Avast Online Security) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki [2017-02-09]
                  CHR Extension: (Tab Cookies) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm [2017-02-12]
                  CHR Extension: (DotVPN — a better way to VPN) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpiecbcckbofpmkkkdibbllpin ceiihk [2017-02-12]
                  CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda [2017-02-09]
                  CHR Extension: (Google Mail) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoe jaedia [2017-02-09]
                  CHR Extension: (Chrome Media Router) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm [2017-02-09]
                  CHR HKLM-x32...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-07]
                  CHR HKLM-x32...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-07]

                  ==================== Services (All) ========================

                  (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

                  R3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [72192 2015-10-29] (Microsoft Corporation)
                  S4 ALG; C:\Windows\System32\alg.exe [79360 2009-07-14] (Microsoft Corporation)
                  S3 AppIDSvc; C:\Windows\System32\appidsvc.dll [34816 2016-04-09] (Microsoft Corporation)
                  R3 Appinfo; C:\Windows\System32\appinfo.dll [70144 2016-04-14] (Microsoft Corporation)
                  S3 aspnet_state; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\as pnet_state.exe [50864 2014-04-11] (Microsoft Corporation)
                  R2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [680960 2015-02-03] (Microsoft Corporation)
                  R2 AudioSrv; C:\Windows\System32\Audiosrv.dll [680960 2015-02-03] (Microsoft Corporation)
                  S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-07] (AVAST Software)
                  S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-08-07] (Avast Software)
                  S4 AxInstSV; C:\Windows\System32\AxInstSV.dll [114688 2010-11-21] (Microsoft Corporation)
                  S4 BDESVC; C:\Windows\System32\bdesvc.dll [100864 2009-07-14] (Microsoft Corporation)
                  R2 BFE; C:\Windows\System32\bfe.dll [705024 2010-11-21] (Microsoft Corporation)
                  S3 BITS; C:\Windows\System32\qmgr.dll [849920 2010-11-21] (Microsoft Corporation)
                  S3 Browser; C:\Windows\System32\browser.dll [136704 2012-07-04] (Microsoft Corporation)
                  S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2016-12-18] (BitRaider, LLC)
                  R3 bthserv; C:\Windows\system32\bthserv.dll [83968 2009-07-14] (Microsoft Corporation)
                  S4 CertPropSvc; C:\Windows\System32\certprop.dll [80384 2010-11-21] (Microsoft Corporation)
                  S4 clr_optimization_v2.0.50727_32; C:\Windows\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe [67224 2014-03-20] (Microsoft Corporation)
                  S4 clr_optimization_v2.0.50727_64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ms corsvw.exe [90776 2014-03-20] (Microsoft Corporation)
                  S2 clr_optimization_v4.0.30319_32; C:\Windows\Microsoft.NET\Framework\v4.0.30319\msco rsvw.exe [103608 2014-04-11] (Microsoft Corporation)
                  S2 clr_optimization_v4.0.30319_64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ms corsvw.exe [124088 2014-04-11] (Microsoft Corporation)
                  R2 CryptSvc; C:\Windows\system32\cryptsvc.dll [188416 2015-06-25] (Microsoft Corporation)
                  R2 CryptSvc; C:\Windows\SysWOW64\cryptsvc.dll [143872 2015-06-25] (Microsoft Corporation)
                  R2 DcomLaunch; C:\Windows\system32\rpcss.dll [511488 2016-02-02] (Microsoft Corporation)
                  S3 defragsvc; C:\Windows\System32\defragsvc.dll [291328 2009-07-14] (Microsoft Corporation)
                  R2 Dhcp; C:\Windows\system32\dhcpcore.dll [317952 2010-11-21] (Microsoft Corporation)
                  R2 Dhcp; C:\Windows\SysWOW64\dhcpcore.dll [254464 2010-11-21] (Microsoft Corporation)
                  R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1390592 2015-07-23] (Microsoft Corporation)
                  R2 Dnscache; C:\Windows\System32\dnsrslvr.dll [183296 2011-03-03] (Microsoft Corporation)
                  S3 dot3svc; C:\Windows\System32\dot3svc.dll [252416 2010-11-21] (Microsoft Corporation)
                  S4 DPS; C:\Windows\system32\dps.dll [162816 2010-11-21] (Microsoft Corporation)
                  R3 EapHost; C:\Windows\System32\eapsvc.dll [111104 2009-07-14] (Microsoft Corporation)
                  S4 EFS; C:\Windows\System32\lsass.exe [30720 2016-05-12] (Microsoft Corporation)
                  S3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [696832 2010-11-21] (Microsoft Corporation)
                  S3 ehSched; C:\Windows\ehome\ehsched.exe [127488 2009-07-14] (Microsoft Corporation)
                  R2 eventlog; C:\Windows\System32\wevtsvc.dll [1646080 2010-11-21] (Microsoft Corporation)
                  R2 EventSystem; C:\Windows\system32\es.dll [402944 2009-07-14] (Microsoft Corporation)
                  R2 EventSystem; C:\Windows\SysWOW64\es.dll [271360 2009-07-14] (Microsoft Corporation)
                  R2 Everything; C:\Program Files\Everything\Everything.exe [1441792 2014-08-06] () [File not signed]
                  S4 Fax; C:\Windows\system32\fxssvc.exe [689152 2010-11-21] (Microsoft Corporation)
                  S4 fdPHost; C:\Windows\system32\fdPHost.dll [16384 2009-07-14] (Microsoft Corporation)
                  S4 FDResPub; C:\Windows\system32\fdrespub.dll [34816 2009-07-14] (Microsoft Corporation)
                  R2 FontCache; C:\Windows\system32\FntCache.dll [1148416 2015-11-10] (Microsoft Corporation)
                  S3 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\Pres entationFontCache.exe [42856 2010-11-21] (Microsoft Corporation)
                  R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155376 2015-10-04] (NVIDIA Corporation)
                  R2 gpsvc; C:\Windows\System32\gpsvc.dll [794624 2016-05-12] (Microsoft Corporation)
                  S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-02-09] (Google Inc.)
                  S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-02-09] (Google Inc.)
                  S4 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [2627080 2016-11-11] (LogMeIn Inc.)
                  S4 hidserv; C:\Windows\system32\hidserv.dll [38912 2009-07-14] (Microsoft Corporation)
                  S4 hidserv; C:\Windows\SysWOW64\hidserv.dll [49152 2009-07-14] (Microsoft Corporation)
                  S3 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2015-02-09] (Hi-Rez Studios) [File not signed]
                  S4 hkmsvc; C:\Windows\system32\kmsvc.dll [90624 2010-11-21] (Microsoft Corporation)
                  S3 HomeGroupListener; C:\Windows\system32\ListSvc.dll [232448 2010-11-21] (Microsoft Corporation)
                  S3 HomeGroupProvider; C:\Windows\system32\provsvc.dll [187904 2010-11-21] (Microsoft Corporation)
                  S3 HomeGroupProvider; C:\Windows\SysWOW64\provsvc.dll [165376 2010-11-21] (Microsoft Corporation)
                  S4 idsvc; C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe [859280 2014-06-30] (Microsoft Corporation)
                  S3 IKEEXT; C:\Windows\System32\ikeext.dll [859648 2013-10-12] (Microsoft Corporation)
                  S4 IPBusEnum; C:\Windows\system32\ipbusenum.dll [101888 2009-07-14] (Microsoft Corporation)
                  S4 iphlpsvc; C:\Windows\System32\iphlpsvc.dll [569344 2012-10-03] (Microsoft Corporation)
                  R3 KeyIso; C:\Windows\system32\lsass.exe [30720 2016-05-12] (Microsoft Corporation)
                  S3 KtmRm; C:\Windows\system32\msdtckrm.dll [368640 2009-07-14] (Microsoft Corporation)
                  R2 LanmanServer; C:\Windows\system32\srvsvc.dll [236032 2010-11-21] (Microsoft Corporation)
                  R2 LanmanWorkstation; C:\Windows\System32\wkssvc.dll [118784 2010-11-21] (Microsoft Corporation)
                  S4 lltdsvc; C:\Windows\System32\lltdsvc.dll [300032 2009-07-14] (Microsoft Corporation)
                  R2 lmhosts; C:\Windows\System32\lmhsvc.dll [23552 2009-07-14] (Microsoft Corporation)
                  S3 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-11-11] (LogMeIn, Inc.)
                  S4 Mcx2Svc; C:\Windows\system32\Mcx2Svc.dll [84992 2010-11-21] (Microsoft Corporation)
                  R2 MMCSS; C:\Windows\system32\mmcss.dll [67584 2009-07-14] (Microsoft Corporation)
                  R2 MpsSvc; C:\Windows\system32\mpssvc.dll [828416 2010-11-21] (Microsoft Corporation)
                  S3 MSDTC; C:\Windows\System32\msdtc.exe [141824 2009-07-14] (Microsoft Corporation)
                  S4 MSiSCSI; C:\Windows\system32\iscsiexe.dll [156672 2009-07-14] (Microsoft Corporation)
                  S3 msiserver; C:\Windows\System32\msiexec.exe [128000 2016-04-14] (Microsoft Corporation)
                  S3 msiserver; C:\Windows\SysWOW64\msiexec.exe [73216 2016-04-14] (Microsoft Corporation)
                  S4 napagent; C:\Windows\system32\qagentRT.dll [476160 2010-11-21] (Microsoft Corporation)
                  S4 Netlogon; C:\Windows\system32\lsass.exe [30720 2016-05-12] (Microsoft Corporation)
                  R2 Netman; C:\Windows\System32\netman.dll [360448 2009-07-14] (Microsoft Corporation)
                  S4 NetMsmqActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SM SvcHost.exe [139944 2014-04-11] (Microsoft Corporation)
                  S4 NetPipeActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SM SvcHost.exe [139944 2014-04-11] (Microsoft Corporation)
                  R3 netprofm; C:\Windows\System32\netprofm.dll [459776 2009-07-14] (Microsoft Corporation)
                  R3 netprofm; C:\Windows\SysWOW64\netprofm.dll [360448 2009-07-14] (Microsoft Corporation)
                  S4 NetTcpActivator; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SM SvcHost.exe [139944 2014-04-11] (Microsoft Corporation)
                  S4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SM SvcHost.exe [139944 2014-04-11] (Microsoft Corporation)
                  R2 NlaSvc; C:\Windows\System32\nlasvc.dll [303616 2014-12-06] (Microsoft Corporation)
                  R2 nsi; C:\Windows\system32\nsisvc.dll [25600 2009-07-14] (Microsoft Corporation)
                  R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-06-15] (NVIDIA Corporation)
                  R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568816 2015-10-04] (NVIDIA Corporation)
                  R2 nvsvc; C:\Windows\system32\nvvsvc.exe [933168 2015-08-18] (NVIDIA Corporation)
                  S3 ose; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [149352 2010-01-09] (Microsoft Corporation)
                  S3 osppsvc; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EX E [4925184 2010-01-09] (Microsoft Corporation)
                  S4 p2pimsvc; C:\Windows\system32\pnrpsvc.dll [327168 2009-07-14] (Microsoft Corporation)
                  S4 p2psvc; C:\Windows\system32\p2psvc.dll [438784 2009-07-14] (Microsoft Corporation)
                  S4 PcaSvc; C:\Windows\System32\pcasvc.dll [188416 2015-02-03] (Microsoft Corporation)
                  S3 PerfHost; C:\Windows\SysWow64\perfhost.exe [20992 2009-07-14] (Microsoft Corporation)
                  S3 pla; C:\Windows\system32\pla.dll [1389056 2010-11-21] (Microsoft Corporation)
                  S3 pla; C:\Windows\SysWOW64\pla.dll [1508864 2010-11-21] (Microsoft Corporation)
                  R2 PlugPlay; C:\Windows\system32\umpnpmgr.dll [404480 2011-05-24] (Microsoft Corporation)
                  S3 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-07-06] ()
                  S4 PNRPAutoReg; C:\Windows\system32\pnrpauto.dll [25088 2009-07-14] (Microsoft Corporation)
                  S4 PNRPsvc; C:\Windows\system32\pnrpsvc.dll [327168 2009-07-14] (Microsoft Corporation)
                  S3 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [502272 2016-05-12] (Microsoft Corporation)
                  R2 Power; C:\Windows\system32\umpo.dll [163840 2009-07-14] (Microsoft Corporation)
                  R2 ProfSvc; C:\Windows\system32\profsvc.dll [210432 2014-12-19] (Microsoft Corporation)
                  S3 ProtectedStorage; C:\Windows\system32\lsass.exe [30720 2016-05-12] (Microsoft Corporation)
                  S4 QWAVE; C:\Windows\system32\qwave.dll [242688 2009-07-14] (Microsoft Corporation)
                  S4 QWAVE; C:\Windows\SysWOW64\qwave.dll [210944 2009-07-14] (Microsoft Corporation)
                  S3 RasAuto; C:\Windows\System32\rasauto.dll [99328 2009-07-14] (Microsoft Corporation)
                  S3 RasMan; C:\Windows\System32\rasmans.dll [344064 2010-11-21] (Microsoft Corporation)
                  R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [186048 2014-12-09] ()
                  S4 RemoteAccess; C:\Windows\System32\mprdim.dll [97792 2009-07-14] (Microsoft Corporation)
                  S4 RemoteAccess; C:\Windows\SysWOW64\mprdim.dll [75264 2009-07-14] (Microsoft Corporation)
                  S4 RemoteRegistry; C:\Windows\system32\regsvc.dll [159232 2009-07-14] (Microsoft Corporation)
                  R2 RpcEptMapper; C:\Windows\System32\RpcEpMap.dll [67072 2009-07-14] (Microsoft Corporation)
                  S4 RpcLocator; C:\Windows\system32\locator.exe [10240 2009-07-14] (Microsoft Corporation)
                  R2 RpcSs; C:\Windows\system32\rpcss.dll [511488 2016-02-02] (Microsoft Corporation)
                  R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [239176 2013-11-02] (Realtek Semiconductor)
                  R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [105448 2014-12-06] (Razer Inc.)
                  R2 SamSs; C:\Windows\system32\lsass.exe [30720 2016-05-12] (Microsoft Corporation)
                  S4 SCardSvr; C:\Windows\System32\SCardSvr.dll [190976 2009-07-14] (Microsoft Corporation)
                  R2 Schedule; C:\Windows\system32\schedsvc.dll [1110016 2015-08-05] (Microsoft Corporation)
                  S4 SCPolicySvc; C:\Windows\System32\certprop.dll [80384 2010-11-21] (Microsoft Corporation)
                  S3 SDRSVC; C:\Windows\System32\SDRSVC.dll [170496 2010-11-21] (Microsoft Corporation)
                  S3 seclogon; C:\Windows\system32\seclogon.dll [30720 2016-02-09] (Microsoft Corporation)
                  R2 SENS; C:\Windows\System32\sens.dll [64512 2009-07-14] (Microsoft Corporation)
                  R2 SENS; C:\Windows\SysWOW64\sens.dll [49664 2009-07-14] (Microsoft Corporation)
                  S4 SensrSvc; C:\Windows\system32\sensrsvc.dll [29184 2009-07-14] (Microsoft Corporation)
                  S4 SessionEnv; C:\Windows\system32\sessenv.dll [121856 2010-11-21] (Microsoft Corporation)
                  S4 SessionEnv; C:\Windows\SysWOW64\sessenv.dll [113664 2010-11-21] (Microsoft Corporation)
                  S3 SharedAccess; C:\Windows\System32\ipnathlp.dll [359424 2009-07-14] (Microsoft Corporation)
                  R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [370688 2010-11-21] (Microsoft Corporation)
                  R2 ShellHWDetection; C:\Windows\SysWOW64\shsvcs.dll [328192 2010-11-21] (Microsoft Corporation)
                  S3 SkypeUpdate; C:\Program Files (x86)\Skype\Updater\Updater.exe [324224 2016-09-20] (Skype Technologies)
                  S4 SNMPTRAP; C:\Windows\System32\snmptrap.exe [14336 2009-07-14] (Microsoft Corporation)
                  R2 Spooler; C:\Windows\System32\spoolsv.exe [559104 2012-02-11] (Microsoft Corporation)
                  S2 sppsvc; C:\Windows\system32\sppsvc.exe [3524608 2010-11-21] (Microsoft Corporation)
                  S3 sppuinotify; C:\Windows\system32\sppuinotify.dll [65536 2009-07-14] (Microsoft Corporation)
                  R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [193024 2009-07-14] (Microsoft Corporation)
                  S3 SstpSvc; C:\Windows\system32\sstpsvc.dll [75264 2009-07-14] (Microsoft Corporation)
                  S3 Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [1464096 2017-01-19] (Valve Corporation)
                  R2 stisvc; C:\Windows\System32\wiaservc.dll [580096 2010-11-21] (Microsoft Corporation)
                  R3 swprv; C:\Windows\System32\swprv.dll [524288 2009-07-14] (Microsoft Corporation)
                  S3 SysMain; C:\Windows\system32\sysmain.dll [1743360 2015-07-15] (Microsoft Corporation)
                  S4 TabletInputService; C:\Windows\System32\TabSvc.dll [92672 2010-11-21] (Microsoft Corporation)
                  S3 TapiSrv; C:\Windows\System32\tapisrv.dll [316928 2010-11-21] (Microsoft Corporation)
                  S3 TapiSrv; C:\Windows\SysWOW64\tapisrv.dll [242176 2010-11-21] (Microsoft Corporation)
                  S4 TermService; C:\Windows\System32\termsrv.dll [683520 2014-10-14] (Microsoft Corporation)
                  R2 Themes; C:\Windows\system32\themeservice.dll [44544 2009-07-14] (Microsoft Corporation)
                  S3 THREADORDER; C:\Windows\system32\mmcss.dll [67584 2009-07-14] (Microsoft Corporation)
                  S4 TrkWks; C:\Windows\System32\trkwks.dll [119808 2009-07-14] (Microsoft Corporation)
                  S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [194048 2010-11-21] (Microsoft Corporation)
                  S4 UI0Detect; C:\Windows\system32\UI0Detect.exe [40960 2009-07-14] (Microsoft Corporation)
                  R2 UMVPFSrv; C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
                  R3 upnphost; C:\Windows\System32\upnphost.dll [353792 2009-07-14] (Microsoft Corporation)
                  R3 upnphost; C:\Windows\SysWOW64\upnphost.dll [266752 2009-07-14] (Microsoft Corporation)
                  R2 UxSms; C:\Windows\System32\uxsms.dll [38912 2009-07-14] (Microsoft Corporation)
                  S4 VaultSvc; C:\Windows\system32\lsass.exe [30720 2016-05-12] (Microsoft Corporation)
                  S3 vds; C:\Windows\System32\vds.exe [533504 2010-11-21] (Microsoft Corporation)
                  R3 VSS; C:\Windows\system32\vssvc.exe [1600512 2010-11-21] (Microsoft Corporation)
                  S3 W32Time; C:\Windows\system32\w32time.dll [381952 2009-07-14] (Microsoft Corporation)
                  S3 WatAdminSvc; C:\Windows\system32\Wat\WatAdminSvc.exe [1255736 2013-08-27] (Microsoft Corporation)
                  S3 wbengine; C:\Windows\system32\wbengine.exe [1504256 2010-11-21] (Microsoft Corporation)
                  S4 WbioSrvc; C:\Windows\System32\wbiosrvc.dll [202240 2009-07-14] (Microsoft Corporation)
                  S4 wcncsvc; C:\Windows\System32\wcncsvc.dll [367104 2010-11-21] (Microsoft Corporation)
                  S4 wcncsvc; C:\Windows\SysWOW64\wcncsvc.dll [276992 2010-11-21] (Microsoft Corporation)
                  S4 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [40960 2009-07-14] (Microsoft Corporation)
                  S4 WcsPlugInService; C:\Windows\SysWOW64\WcsPlugInService.dll [32768 2009-07-14] (Microsoft Corporation)
                  S4 WdiServiceHost; C:\Windows\system32\wdi.dll [91136 2015-01-09] (Microsoft Corporation)
                  S4 WdiServiceHost; C:\Windows\SysWOW64\wdi.dll [76800 2015-01-09] (Microsoft Corporation)
                  S4 WdiSystemHost; C:\Windows\system32\wdi.dll [91136 2015-01-09] (Microsoft Corporation)
                  S4 WdiSystemHost; C:\Windows\SysWOW64\wdi.dll [76800 2015-01-09] (Microsoft Corporation)
                  S4 WebClient; C:\Windows\System32\webclnt.dll [260096 2015-07-01] (Microsoft Corporation)
                  S4 WebClient; C:\Windows\SysWOW64\webclnt.dll [206848 2015-07-01] (Microsoft Corporation)
                  S3 Wecsvc; C:\Windows\system32\wecsvc.dll [237568 2009-07-14] (Microsoft Corporation)
                  S4 wercplsupport; C:\Windows\System32\wercplsupport.dll [84480 2009-07-14] (Microsoft Corporation)
                  S4 WerSvc; C:\Windows\System32\WerSvc.dll [76800 2009-07-14] (Microsoft Corporation)
                  R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
                  S4 WinHttpAutoProxySvc; C:\Windows\system32\winhttp.dll [444928 2016-05-11] (Microsoft Corporation)
                  R2 Winmgmt; C:\Windows\system32\wbem\WMIsvc.dll [242688 2009-07-14] (Microsoft Corporation)
                  S4 WinRM; C:\Windows\system32\WsmSvc.dll [2020352 2014-10-03] (Microsoft Corporation)
                  S4 WinRM; C:\Windows\SysWOW64\WsmSvc.dll [1177088 2014-10-03] (Microsoft Corporation)
                  R2 Wlansvc; C:\Windows\System32\wlansvc.dll [886784 2009-07-14] (Microsoft Corporation)
                  R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480 2012-07-17] (Microsoft Corp.)
                  S3 wmiApSrv; C:\Windows\system32\wbem\WmiApSrv.exe [203264 2009-07-14] (Microsoft Corporation)
                  R2 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [1525248 2010-11-21] (Microsoft Corporation)
                  S4 WPCSvc; C:\Windows\System32\wpcsvc.dll [12288 2009-07-14] (Microsoft Corporation)
                  S4 WPCSvc; C:\Windows\SysWOW64\wpcsvc.dll [10752 2009-07-14] (Microsoft Corporation)
                  S4 WPDBusEnum; C:\Windows\system32\wpdbusenum.dll [117248 2010-11-21] (Microsoft Corporation)
                  R2 wscsvc; C:\Windows\System32\wscsvc.dll [97280 2009-07-14] (Microsoft Corporation)
                  R2 WSearch; C:\Windows\system32\SearchIndexer.exe [591872 2011-05-04] (Microsoft Corporation)
                  R2 WSearch; C:\Windows\SysWOW64\SearchIndexer.exe [427520 2011-05-04] (Microsoft Corporation)
                  R2 wuauserv; C:\Windows\system32\wuaueng.dll [2610688 2016-02-12] (Microsoft Corporation)
                  S3 wudfsvc; C:\Windows\System32\WUDFSvc.dll [84992 2012-07-26] (Microsoft Corporation)
                  S4 WwanSvc; C:\Windows\System32\wwansvc.dll [228864 2014-01-28] (Microsoft Corporation)
                  R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
                  S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}

                  ===================== Drivers (Whitelisted) ======================

                  (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

                  R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-07] (AVAST Software)
                  R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-07] (AVAST Software)
                  R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-07] (AVAST Software)
                  R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-07] (AVAST Software)
                  R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2016-06-13] (AVAST Software)
                  R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2016-06-13] (AVAST Software)
                  R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-07] (AVAST Software)
                  S3 aswTap; C:\Windows\System32\DRIVERS\aswTap.sys [44640 2016-10-11] (The OpenVPN Project)
                  R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-07] (AVAST Software)
                  R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2014-11-02] ()
                  S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [129152 2016-04-24] (Samsung Electronics Co., Ltd.)
                  R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-06-24] (Disc Soft Ltd)
                  R0 FSProFilter2; C:\Windows\System32\Drivers\FSPFltd2.sys [57648 2011-06-03] (FSPro Labs)
                  R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-07-24] (REALiX™)
                  R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-08-07] (AVAST Software)
                  R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
                  R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-10-04] (NVIDIA Corporation)
                  R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
                  R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-12-09] (Razer, Inc.)
                  R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33448 2015-07-31] (Synaptics Incorporated)
                  S3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2015-01-23] (Spotflux, Inc.)
                  U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-02-03] ()
                  R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-08-07] (Avast Software)
                  R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-01-31] (Zemana Ltd.)
                  R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-01-31] (Zemana Ltd.)

                  ==================== NetSvcs (Whitelisted) ===================

                  (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

                  ==================== One Month Created files and folders ========

                  (If an entry is included in the fixlist, the file/folder will be moved.)

                  2017-02-17 06:37 - 2017-02-17 06:37 - 00014134 _____ C:\Users\Philipp\Downloads\fixlist (3).txt
                  2017-02-15 01:18 - 2017-02-15 01:24 - 00000000 ____D C:\Users\Philipp\Desktop\paint
                  2017-02-15 01:13 - 2017-02-15 01:13 - 00001114 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
                  2017-02-15 01:13 - 2017-02-15 01:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
                  2017-02-14 18:15 - 2017-02-14 18:15 - 00071916 _____ C:\Users\Philipp\Downloads\myLectures07e7f69d-04dc-436b-8b1b-f7effeab929f.pdf
                  2017-02-14 04:30 - 2017-02-14 04:30 - 00012288 ___SH C:\Users\Philipp\Desktop\Thumbs.db
                  2017-02-14 04:27 - 2017-02-14 04:27 - 02793495 _____ C:\Users\Philipp\Downloads\geek (4).zip
                  2017-02-14 04:24 - 2017-02-14 04:24 - 00000000 ____D C:\Users\Philipp\Desktop\Neuer Ordner (6)
                  2017-02-14 04:23 - 2017-02-14 04:24 - 00494011 _____ C:\Users\Philipp\Downloads\eso.zip
                  2017-02-14 04:22 - 2017-02-14 04:22 - 00007484 _____ C:\Users\Philipp\Desktop\UsbFix_Report.txt
                  2017-02-14 04:18 - 2017-02-14 04:18 - 03812120 _____ (SOSVirus) C:\Users\Philipp\Downloads\UsbFix_9.026.exe
                  2017-02-14 04:18 - 2017-02-14 04:18 - 00001486 _____ C:\Users\Philipp\Desktop\UsbFix.lnk
                  2017-02-14 04:18 - 2017-02-14 04:18 - 00000000 ____D C:\UsbFix
                  2017-02-14 04:08 - 2017-02-15 06:02 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Everything
                  2017-02-14 04:08 - 2017-02-14 04:08 - 00000127 _____ C:\Windows\wininit.ini
                  2017-02-14 04:08 - 2017-02-14 04:08 - 00000000 ____D C:\Program Files\Everything
                  2017-02-14 04:07 - 2017-02-14 04:07 - 01014086 _____ () C:\Users\Philipp\Downloads\Everything-1.3.4.686.x64.Multilingual-Setup.exe
                  2017-02-14 03:57 - 2017-02-14 03:57 - 00005363 _____ C:\Users\Philipp\Downloads\fixlist (2).txt
                  2017-02-13 22:21 - 2017-02-13 22:21 - 00087344 _____ C:\Users\Philipp\AppData\Local\GDIPFONTCACHEV1.DAT
                  2017-02-13 20:31 - 2017-02-13 20:31 - 00071916 _____ C:\Users\Philipp\Downloads\myLecturesfbdfb393-c1c2-4fb6-9db2-3ae950fe99e3.pdf
                  2017-02-13 20:27 - 2017-02-13 20:27 - 00007971 _____ C:\Users\Philipp\Downloads\R__ckmeldung zum Sommersemester 2017 __ Re-registration for the summer semester 2017.zip
                  2017-02-11 06:21 - 2017-02-11 06:21 - 00003560 ____N C:\bootsqm.dat
                  2017-02-11 05:29 - 2017-02-11 05:29 - 00002060 _____ C:\Users\Philipp\Downloads\fixlist (1).txt
                  2017-02-11 03:56 - 2017-02-11 03:56 - 00000222 _____ C:\Users\Philipp\Desktop\Europa Universalis IV.url
                  2017-02-09 14:04 - 2017-02-09 14:04 - 00002225 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
                  2017-02-09 14:04 - 2017-02-09 14:04 - 00002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
                  2017-02-09 14:02 - 2017-02-09 14:02 - 01622528 _____ C:\Users\Philipp\Downloads\ResetBrowser.exe
                  2017-02-09 13:55 - 2017-02-09 13:57 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\ZHP
                  2017-02-09 13:55 - 2017-02-09 13:55 - 00582463 _____ C:\Users\Philipp\Desktop\9lab-log-2017-02-09 (03-21-46).txt
                  2017-02-09 13:55 - 2017-02-09 13:55 - 00000824 _____ C:\Users\Philipp\Desktop\ZHPDiag.lnk
                  2017-02-09 13:54 - 2017-02-09 13:54 - 02660864 _____ C:\Users\Philipp\Downloads\ZHPDiag3.exe
                  2017-02-09 03:19 - 2017-02-09 03:19 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\9-lab
                  2017-02-09 03:19 - 2017-02-09 03:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
                  2017-02-09 03:19 - 2017-02-09 03:19 - 00000000 ____D C:\ProgramData\9-lab
                  2017-02-09 03:19 - 2017-02-09 03:19 - 00000000 ____D C:\Program Files\9-lab
                  2017-02-09 03:18 - 2017-02-09 03:19 - 06466144 _____ C:\Users\Philipp\Downloads\rmtool-setup-x64.exe
                  2017-02-08 19:02 - 2017-02-08 19:02 - 00354524 _____ C:\Users\Philipp\Downloads\Klausur_Bedingungen.pdf
                  2017-02-08 18:59 - 2017-02-08 18:59 - 00620683 _____ C:\Users\Philipp\Downloads\Altklausuren-20170208.zip
                  2017-02-08 17:35 - 2017-02-08 17:35 - 00184899 _____ C:\Users\Philipp\Downloads\Mathe 2016-2 (2).pdf
                  2017-02-08 17:35 - 2017-02-08 17:35 - 00152637 _____ C:\Users\Philipp\Downloads\Mathe 2016-1.pdf
                  2017-02-07 18:30 - 2017-02-07 18:30 - 00148179 _____ C:\Users\Philipp\Downloads\Mathe 2015-2.pdf
                  2017-02-07 04:55 - 2017-02-07 04:55 - 00000000 ____D C:\Users\Philipp\AppData\Local\TeamSpeak 3
                  2017-02-07 04:55 - 2017-02-07 04:55 - 00000000 ____D C:\Users\Philipp.TeamSpeak 3
                  2017-02-07 04:55 - 2017-02-07 04:55 - 00000000 ____D C:\Users\Philipp.QtWebEngineProcess
                  2017-02-07 04:54 - 2017-02-14 04:06 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
                  2017-02-07 04:54 - 2017-02-07 04:54 - 00000965 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
                  2017-02-07 04:54 - 2017-02-07 04:54 - 00000927 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
                  2017-02-07 04:51 - 2017-02-07 04:52 - 77761888 _____ (TeamSpeak Systems GmbH) C:\Users\Philipp\Downloads\TeamSpeak3-Client-win64-3.1.0.1.exe
                  2017-02-07 02:48 - 2017-02-07 02:48 - 02433448 _____ (SosVirus) C:\Users\Philipp\Downloads\quickdiag_3_31.01.17.1 (1).exe
                  2017-02-06 22:56 - 2017-02-07 02:55 - 00000000 ____D C:\QuickDiag
                  2017-02-06 22:56 - 2017-02-06 22:56 - 02433448 _____ (SosVirus) C:\Users\Philipp\Downloads\quickdiag_3_31.01.17.1. exe
                  2017-02-06 22:54 - 2017-02-06 22:54 - 00599298 _____ C:\Users\Philipp\Downloads\PHILIPP-PC_2017-02-05_04-10-00.7z
                  2017-02-06 22:52 - 2017-02-06 22:52 - 00034776 _____ C:\Users\Philipp\Desktop\gg.txt
                  2017-02-06 18:06 - 2017-02-06 18:06 - 00148634 _____ C:\Users\Philipp\Downloads\Mathe 2015-1 (2).pdf
                  2017-02-06 16:27 - 2017-02-06 16:27 - 02870984 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_enu. exe
                  2017-02-05 22:09 - 2017-02-05 22:09 - 00148634 _____ C:\Users\Philipp\Downloads\Mathe 2015-1 (1).pdf
                  2017-02-05 17:12 - 2017-02-05 17:12 - 00000000 ____D C:\Users\Philipp\Desktop\Neuer Ordner (5)
                  2017-02-05 17:11 - 2017-02-05 17:11 - 11674025 _____ C:\Users\Philipp\Downloads\Bachelor 1.Semester.zip
                  2017-02-05 17:10 - 2017-02-05 17:10 - 00661755 _____ C:\Users\Philipp\Downloads\CG-Klausur-2016-1-A-Lösung.pdf
                  2017-02-05 04:07 - 2017-02-09 03:52 - 00000000 ____D C:\Users\Philipp\Desktop\Neuer Ordner (4)
                  2017-02-05 04:07 - 2017-02-05 04:07 - 03055407 _____ C:\Users\Philipp\Downloads\uvs_v387eng (1).zip
                  2017-02-05 04:02 - 2017-02-05 04:02 - 00000000 ____D C:\Users\Philipp\Desktop\LOG
                  2017-02-05 03:58 - 2017-02-05 03:58 - 00462976 _____ (Alex Dragokas) C:\Users\Philipp\Downloads\clearlnk_2.9.0.11.exe
                  2017-02-05 03:58 - 2017-02-05 03:58 - 00462976 _____ (Alex Dragokas) C:\Users\Philipp\Desktop\clearlnk_2.9.0.11.exe
                  2017-02-03 02:20 - 2017-02-03 02:20 - 03055407 _____ C:\Users\Philipp\Downloads\uvs_v387eng.zip
                  2017-02-03 02:20 - 2017-02-03 02:20 - 00000000 ____D C:\Users\Philipp\Desktop\Neuer Ordner (3)
                  2017-02-03 01:56 - 2017-02-09 13:51 - 00000222 _____ C:\Users\Philipp\Desktop\The Binding of Isaac Rebirth.url
                  2017-02-03 01:53 - 2017-02-03 01:53 - 00071760 _____ C:\Users\Philipp\Downloads\CollectionLog-2017.02.03-01.46.zip
                  2017-02-03 01:38 - 2017-02-03 01:38 - 12362452 _____ C:\Users\Philipp\Downloads\AutoLogger (3).zip
                  2017-02-03 01:38 - 2017-02-03 01:38 - 00000000 ____D C:\Users\Philipp\Desktop\Neuer Ordner (2)
                  2017-02-03 01:36 - 2017-02-03 01:36 - 12362451 _____ C:\Users\Philipp\Downloads\AutoLogger (2).zip
                  2017-02-03 01:36 - 2017-02-03 01:36 - 01381582 _____ (Igor Pavlov) C:\Users\Philipp\Downloads\7z1604-x64.exe
                  2017-02-03 01:36 - 2017-02-03 01:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
                  2017-02-03 01:36 - 2017-02-03 01:36 - 00000000 ____D C:\Program Files\7-Zip
                  2017-02-03 01:31 - 2017-02-03 01:32 - 12362452 _____ C:\Users\Philipp\Downloads\AutoLogger(1).zip
                  2017-02-03 01:13 - 2017-02-03 01:13 - 12362452 _____ C:\Users\Philipp\Downloads\AutoLogger (1).zip
                  2017-02-03 01:10 - 2017-02-03 01:11 - 12362452 _____ C:\Users\Philipp\Downloads\AutoLogger.zip
                  2017-02-03 01:02 - 2017-02-17 07:00 - 00000000 ____D C:\Users\Philipp\Desktop\Neuer Ordner
                  2017-02-03 01:01 - 2017-02-03 01:06 - 00000000 ____D C:\Users\Philipp\AppData\Local\CrashDumps
                  2017-02-03 00:14 - 2017-02-03 00:14 - 02793495 _____ C:\Users\Philipp\Downloads\geek (3).zip
                  2017-02-03 00:13 - 2017-02-03 00:14 - 34821984 _____ (Adlice Software ) C:\Users\Philipp\Downloads\setup (2).exe
                  2017-02-03 00:13 - 2017-02-03 00:13 - 02793495 _____ C:\Users\Philipp\Downloads\geek (2).zip
                  2017-02-02 23:54 - 2017-02-02 23:54 - 02700800 _____ C:\Users\Philipp\Downloads\ZHPCleaner.exe
                  2017-02-02 23:52 - 2017-02-02 23:52 - 00797760 _____ C:\Users\Philipp\Downloads\delfix_1.013 (1).exe
                  2017-02-02 23:51 - 2017-02-02 23:56 - 00002800 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
                  2017-02-02 23:51 - 2017-02-02 23:51 - 00000820 _____ C:\Users\Public\Desktop\CCleaner.lnk
                  2017-02-02 23:51 - 2017-02-02 23:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
                  2017-02-02 23:51 - 2017-02-02 23:51 - 00000000 ____D C:\Program Files\CCleaner
                  2017-02-02 23:49 - 2017-02-02 23:49 - 00031755 _____ C:\Users\Philipp\Downloads\fixlist.txt
                  2017-02-02 03:59 - 2017-02-02 03:59 - 00918286 _____ C:\Users\Philipp\Downloads\07Der_Vergleich (1).pdf
                  2017-02-02 03:57 - 2017-02-02 03:57 - 00889813 _____ C:\Users\Philipp\Downloads\06Variablen_Analyseeben en (1).pdf
                  2017-02-01 01:39 - 2017-02-17 07:00 - 00000000 ____D C:\FRST
                  2017-02-01 01:37 - 2017-02-01 01:37 - 02420736 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe
                  2017-02-01 01:36 - 2017-02-01 01:36 - 00001160 _____ C:\DelFix.txt
                  2017-02-01 01:35 - 2017-02-01 01:36 - 00797760 _____ C:\Users\Philipp\Downloads\delfix_1.013.exe
                  2017-01-31 22:04 - 2017-01-31 22:04 - 00290304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\subinacl.exe
                  2017-01-31 22:03 - 2017-01-31 22:10 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Geek Uninstaller
                  2017-01-31 22:03 - 2017-01-31 22:04 - 00752296 _____ C:\Users\Philipp\Downloads\Adware Removal Tool by TSA.exe
                  2017-01-31 22:03 - 2017-01-31 22:03 - 06960664 _____ (Geek Unіnstaller) C:\Users\Philipp\Downloads\geek.exe
                  2017-01-31 21:59 - 2017-01-31 21:59 - 02793495 _____ C:\Users\Philipp\Downloads\geek.zip
                  2017-01-31 21:59 - 2017-01-31 21:59 - 02793495 _____ C:\Users\Philipp\Downloads\geek (1).zip
                  2017-01-31 20:17 - 2017-01-31 20:17 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\ProductData
                  2017-01-31 18:17 - 2017-02-03 00:24 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
                  2017-01-31 18:16 - 2017-02-03 00:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
                  2017-01-31 18:16 - 2017-02-03 00:17 - 00000000 ____D C:\Program Files\RogueKiller
                  2017-01-31 18:16 - 2017-01-31 20:08 - 00000000 ____D C:\ProgramData\RogueKiller
                  2017-01-31 18:15 - 2017-01-31 18:15 - 34821984 _____ (Adlice Software ) C:\Users\Philipp\Downloads\setup (1).exe
                  2017-01-31 16:21 - 2017-02-17 07:00 - 00052744 _____ C:\Windows\ZAM.krnl.trace
                  2017-01-31 16:21 - 2017-02-17 07:00 - 00020971 _____ C:\Windows\ZAM_Guard.krnl.trace
                  2017-01-31 16:21 - 2017-02-15 15:52 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
                  2017-01-31 16:21 - 2017-01-31 16:21 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys
                  2017-01-31 16:21 - 2017-01-31 16:21 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam64.sys
                  2017-01-31 16:20 - 2017-01-31 16:20 - 00000000 ____D C:\Users\Philipp\AppData\Local\Zemana
                  2017-01-31 16:19 - 2017-01-31 16:19 - 05510592 _____ ( ) C:\Users\Philipp\Downloads\Zemana.AntiMalware.Setu p.exe
                  2017-01-31 01:54 - 2017-01-31 16:03 - 00000000 ____D C:\ProgramData\Malwarebytes’ Anti-Malware (portable)
                  2017-01-31 01:54 - 2017-01-31 01:54 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
                  2017-01-31 01:54 - 2017-01-31 01:54 - 00000000 __D C:\ProgramData\Malwarebytes
                  2017-01-31 01:50 - 2017-01-31 01:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
                  2017-01-31 01:47 - 2017-01-31 01:48 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Philipp\Downloads\mbar-1.09.3.1001 (1).exe
                  2017-01-31 01:46 - 2017-01-31 01:47 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Philipp\Downloads\mbar-1.09.3.1001.exe
                  2017-01-27 05:30 - 2017-01-27 05:30 - 00000772 _____ C:\Windows\SysWOW64\ping.cfg
                  2017-01-26 04:39 - 2017-01-26 04:39 - 00184899 _____ C:\Users\Philipp\Downloads\Mathe 2016-2 (1).pdf
                  2017-01-26 04:29 - 2017-01-26 04:29 - 00069916 _____ C:\Users\Philipp\Desktop\Detailansicht.pdf
                  2017-01-26 01:09 - 2017-01-26 01:09 - 00114273 _____ C:\Users\Philipp\Desktop\Arabesk.pdf
                  2017-01-25 22:04 - 2017-01-25 22:04 - 00137693 _____ C:\Users\Philipp\Downloads\Einf VL 1617 Croissant 1. Termin.pdf
                  2017-01-25 22:03 - 2017-01-25 22:03 - 00126742 _____ C:\Users\Philipp\Downloads\Einf S 1617 Giersdorf 1. Termin.pdf
                  2017-01-25 21:56 - 2017-01-25 21:56 - 00001507 _____ C:\Users\Philipp\Downloads\POL_P1 Einf__hrung in die Politische Wissenschaft 2016_2017
                  Erinnerung
                  IPW Klausuranmeldung 1. Termin bis zum 28.01.2017 noch m__glich.zip
                  2017-01-23 03:07 - 2017-01-23 03:07 - 00072070 _____ C:\Users\Philipp\Downloads\myLecturesbd591452-0f7b-498a-a1b4-94404c41b45f.pdf
                  2017-01-23 03:04 - 2017-01-23 03:04 - 00072070 _____ C:\Users\Philipp\Downloads\myLectures9ef007c7-4303-4a20-96c7-4148656a23f5.pdf
                  2017-01-18 18:37 - 2017-01-29 00:14 - 00000000 ____D C:\Users\Philipp\AppData\LocalLow\Mozilla
                  2017-01-18 18:30 - 2017-01-18 18:30 - 00000017 _____ C:\Users\Public\Documents\cfg.ini

                  ==================== One Month Modified files and folders ========

                  (If an entry is included in the fixlist, the file/folder will be moved.)

                  2017-02-17 06:48 - 2009-07-14 05:45 - 00029120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
                  2017-02-17 06:48 - 2009-07-14 05:45 - 00029120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
                  2017-02-17 06:46 - 2015-03-15 11:18 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Spotify
                  2017-02-17 06:46 - 2011-04-12 08:43 - 00699666 _____ C:\Windows\system32\perfh007.dat
                  2017-02-17 06:46 - 2011-04-12 08:43 - 00149774 _____ C:\Windows\system32\perfc007.dat
                  2017-02-17 06:46 - 2009-07-14 06:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
                  2017-02-17 06:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
                  2017-02-17 06:41 - 2015-03-15 11:19 - 00000000 ____D C:\Users\Philipp\AppData\Local\Spotify
                  2017-02-17 06:41 - 2013-08-21 17:42 - 00000000 ____D C:\Program Files (x86)\Steam
                  2017-02-17 06:40 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
                  2017-02-17 06:34 - 2013-08-27 15:44 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Skype
                  2017-02-15 15:53 - 2013-08-18 15:36 - 00000000 ____D C:\Users\Philipp
                  2017-02-14 17:45 - 2014-01-18 20:58 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\TS3Client
                  2017-02-14 04:30 - 2014-05-29 12:23 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
                  2017-02-14 04:30 - 2013-09-02 12:36 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
                  2017-02-14 04:29 - 2013-11-10 12:42 - 00000000 ____D C:\Program Files (x86)\Samsung
                  2017-02-12 02:14 - 2016-11-13 23:19 - 00000000 ____D C:\Users\Philipp\Desktop\Arda
                  2017-02-11 03:56 - 2016-11-01 15:15 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Steam
                  2017-02-09 14:04 - 2013-08-18 18:10 - 00000000 ____D C:\Program Files (x86)\Google
                  2017-02-09 03:52 - 2015-06-26 18:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CLICK & LEARN DiDi 360° DVD
                  2017-02-05 04:02 - 2014-06-22 12:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2
                  2017-02-05 04:02 - 2014-05-30 20:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
                  2017-02-05 04:02 - 2014-05-11 11:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Die Siedler
                  2017-02-03 01:06 - 2013-10-11 19:38 - 00000000 ____D C:\Users\Philipp\AppData\Local\LogMeIn Hamachi
                  2017-01-31 22:17 - 2013-08-27 15:50 - 00000000 ____D C:\ProgramData\Skype
                  2017-01-31 22:09 - 2014-10-21 17:53 - 00000000 ____D C:\Program Files (x86)\Java
                  2017-01-28 00:33 - 2014-09-13 11:08 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\DVDVideoSoft
                  2017-01-28 00:32 - 2014-01-18 20:57 - 00000000 ____D C:\Users\Philipp\AppData\Local\TeamSpeak 3 Client
                  2017-01-28 00:29 - 2016-11-26 19:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
                  2017-01-28 00:29 - 2014-03-20 18:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
                  2017-01-28 00:29 - 2014-03-06 14:30 - 00000000 ____D C:\ProgramData\Freemake
                  2017-01-28 00:19 - 2016-06-13 14:16 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
                  2017-01-28 00:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
                  2017-01-22 14:05 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
                  2017-01-21 21:55 - 2015-06-02 17:20 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
                  2017-01-19 19:14 - 2017-01-17 14:50 - 00000019 _____ C:\Users\Public\Documents\cc.ini

                  ==================== Bamital & volsnap ======================

                  (There is no automatic fix for files that do not pass verification.)

                  C:\Windows\system32\winlogon.exe => File is digitally signed
                  C:\Windows\system32\wininit.exe => File is digitally signed
                  C:\Windows\SysWOW64\wininit.exe => File is digitally signed
                  C:\Windows\explorer.exe => File is digitally signed
                  C:\Windows\SysWOW64\explorer.exe => File is digitally signed
                  C:\Windows\system32\svchost.exe => File is digitally signed
                  C:\Windows\SysWOW64\svchost.exe => File is digitally signed
                  C:\Windows\system32\services.exe => File is digitally signed
                  C:\Windows\system32\User32.dll => File is digitally signed
                  C:\Windows\SysWOW64\User32.dll => File is digitally signed
                  C:\Windows\system32\userinit.exe => File is digitally signed
                  C:\Windows\SysWOW64\userinit.exe => File is digitally signed
                  C:\Windows\system32\rpcss.dll => File is digitally signed
                  C:\Windows\system32\dnsapi.dll => File is digitally signed
                  C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
                  C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

                  LastRegBack: 2017-02-14 18:08

                  ==================== End of FRST.txt ============================

                  Comment

                  • siq
                    PCHF Member
                    • Jan 2017
                    • 49

                    #84

                    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-02-2017 02
                    [/quote]

                    [HEADING=1]Ran by Philipp (17-02-2017 07:00:34)
                    Running from C:\Users\Philipp\Desktop\Neuer Ordner
                    Windows 7 Home Premium Service Pack 1 (X64) (2013-08-18 14:36:22)
                    Boot Mode: Normal[/HEADING]
                    ==================== Accounts: =============================

                    Administrator (S-1-5-21-3041798318-2634963116-1215314133-500 - Administrator - Disabled)
                    Gast (S-1-5-21-3041798318-2634963116-1215314133-501 - Limited - Enabled)
                    HomeGroupUser$ (S-1-5-21-3041798318-2634963116-1215314133-1002 - Limited - Enabled)
                    Philipp (S-1-5-21-3041798318-2634963116-1215314133-1000 - Administrator - Enabled) => C:\Users\Philipp

                    ==================== Security Center ========================

                    (If an entry is included in the fixlist, it will be removed.)

                    AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
                    AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                    AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

                    ==================== Installed Programs ======================

                    (Only the adware programs with “Hidden” flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

                    7-Zip 16.04 (x64) (HKLM...\7-Zip) (Version: 16.04 - Igor Pavlov)
                    9-lab Removal Tool (HKLM-x32...\9-lab Removal Tool) (Version: - )
                    Adobe Acrobat Reader DC - Deutsch (HKLM-x32...{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated)
                    Adobe Flash Player 24 NPAPI (HKLM-x32...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
                    Anno 1701 (HKLM-x32...{A2433A63-5F5D-40E5-B529-9123C2B3E734}) (Version: 1.04 - Sunflowers)
                    AutoSensitivity (HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\0a099336274e1166) (Version: 1.4.0.23 - Igor Kulman)
                    Avast Free Antivirus (HKLM-x32...\Avast) (Version: 10.3.2225 - AVAST Software)
                    Battle.net (HKLM-x32...\Battle.net) (Version: - Blizzard Entertainment)
                    Battlefield 1942™ (HKLM-x32...{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts)
                    Battlefield 3™ (HKLM-x32...{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts)
                    Battlelog Web Plugins (HKLM-x32...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB)
                    BattlEye Uninstall (HKLM-x32...\BattlEye for A2) (Version: - )
                    BitRaider Streaming Client (HKLM-x32...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
                    Brother MFL-Pro Suite MFC-9320CW (HKLM-x32...{A1BBEE16-49B1-42F2-95B8-54C8C6A1C0C3}) (Version: 2.0.1.0 - Brother Industries, Ltd.)
                    Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32...\Steam App 10190) (Version: - Infinity Ward)
                    Call of Duty: Modern Warfare 2 (HKLM-x32...\Steam App 10180) (Version: - Infinity Ward)
                    Call of Duty: Modern Warfare 3 (HKLM-x32...\Steam App 42680) (Version: - Infinity Ward)
                    CCleaner (HKLM...\CCleaner) (Version: 5.26 - Piriform)
                    CLICK & LEARN DiDi 360° DVD (HKLM-x32...{5713D2DD-01F2-40D0-827D-917A88E7637A}_is1) (Version: CLICK & LEARN DiDi 360° 5.2 DVD - DEGENER)
                    Company of Heroes 2 (HKLM-x32...\Steam App 231430) (Version: - Relic Entertainment)
                    Counter-Strike: Global Offensive (HKLM-x32...\Steam App 730) (Version: - Valve)
                    Cry of Fear (HKLM-x32...\Steam App 223710) (Version: - Team Psykskallar)
                    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
                    DAEMON Tools Lite (HKLM-x32...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
                    Dropbox (HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)
                    Edna & Harvey: Harvey’s New Eyes (HKLM-x32...\Steam App 219910) (Version: - Daedalic Entertainment)
                    Edna & Harvey: The Breakout (HKLM-x32...\Steam App 255320) (Version: - Daedalic Entertainment)
                    ETDWare PS/2-X64 10.7.14.12_WHQL (HKLM...\Elantech) (Version: 10.7.14.12 - ELAN Microelectronic Corp.)
                    Europa Universalis IV (HKLM...\Steam App 236850) (Version: - Paradox Development Studio)
                    Everything 1.3.4.686 (x64) (HKLM...\Everything) (Version: - )
                    Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
                    Golf With Your Friends (HKLM...\Steam App 431240) (Version: - Blacklight Interactive)
                    Google Chrome (HKLM-x32...{742D8ED2-E248-3870-AFA1-F7A1166F217C}) (Version: 56.0.2924.87 - Google, Inc.)
                    Google Drive (HKLM-x32...{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.)
                    Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
                    Guild Wars 2 (HKLM-x32...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.)
                    Hearthstone (HKLM-x32...\Hearthstone) (Version: - Blizzard Entertainment)
                    Hi-Rez Studios Authenticate and Update Service (HKLM-x32...{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
                    Left 4 Dead 2 (HKLM-x32...\Steam App 550) (Version: - Valve)
                    LogMeIn Hamachi (HKLM-x32...\LogMeIn Hamachi) (Version: 2.2.0.541 - LogMeIn, Inc.)
                    LogMeIn Hamachi (x32 Version: 2.2.0.541 - LogMeIn, Inc.) Hidden
                    Metin2 (HKLM-x32...\Metin2_is1) (Version: - Gameforge 4D GmbH)
                    Metro 2033 (HKLM-x32...\Steam App 43110) (Version: - 4A Games)
                    Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM...{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
                    Microsoft .NET Framework 4.5.2 (HKLM...{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
                    Microsoft ASP.NET MVC 4 Runtime (HKLM-x32...{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
                    Microsoft Office Access 2003 Runtime (HKLM-x32...{901C0407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
                    Microsoft Office Home and Business 2010 (HKLM-x32...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
                    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32...{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
                    Microsoft Visual C++ 2005 Redistributable (HKLM-x32...{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
                    Microsoft Visual C++ 2005 Redistributable (HKLM-x32...{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
                    Microsoft Visual C++ 2005 Redistributable (HKLM-x32...{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
                    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM...{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
                    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32...{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
                    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32...{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
                    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32...{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
                    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32...{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
                    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM...{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
                    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32...{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
                    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32...{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
                    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32...{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
                    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32...{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
                    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32...{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
                    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32...{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation)
                    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32...{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
                    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
                    Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
                    Microsoft-Maus- und Tastatur-Center (HKLM...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
                    Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
                    My Lockbox 3.0.5 (HKLM...\My Lockbox_is1) (Version: 3.0.5 - )
                    NVIDIA GeForce Experience 2.5.15.46 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.46 - NVIDIA Corporation)
                    NVIDIA Grafiktreiber 341.81 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.81 - NVIDIA Corporation)
                    NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
                    NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
                    Oblivion (HKLM-x32...{35CB6715-41F8-4F99-8881-6FC75BF054B0}) (Version: 1.00.0000 - Bethesda Softworks)
                    OpenVPN 2.3.12-I602 (HKLM-x32...\OpenVPN) (Version: 2.3.12-I602 - )
                    Origin (HKLM-x32...\Origin) (Version: 9.4.7.2799 - Electronic Arts, Inc.)
                    PDF-Viewer (HKLM...{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.312.1 - Tracker Software Products Ltd)
                    ProtectDisc Driver, Version 11 (HKLM-x32...\ProtectDisc Driver 11) (Version: 11.0.0.12 - ProtectDisc Software GmbH)
                    PunkBuster Services (HKLM-x32...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
                    Razer Cortex (HKLM-x32...\Razer Cortex_is1) (Version: 5.2.22.0 - Razer Inc.)
                    Realtek High Definition Audio Driver (HKLM-x32...{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.)
                    RogueKiller version 12.9.6.0 (HKLM...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.9.6.0 - Adlice Software)
                    Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32...{90140000-003D-0000-0000-0000000FF1CE}Office14.SingleImage{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
                    SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden
                    SHIELD Wireless Controller Driver (Version: 2.5.15.46 - NVIDIA Corporation) Hidden
                    Skype™ 7.31 (HKLM-x32...{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.31.104 - Skype Technologies S.A.)
                    Smite (HKLM-x32...{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 2.0.2574.0 - Hi-Rez Studios)
                    Spotify (HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\Spotify) (Version: 1.0.48.103.g15edf1ec - Spotify AB)
                    Star Wars: The Old Republic (HKLM-x32...{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
                    Steam (HKLM-x32...\Steam) (Version: 2.10.91.91 - Valve Corporation)
                    System Requirements Lab CYRI (HKLM-x32...{F3FCB08B-E752-444D-86A0-0634A4F3B23D}) (Version: 6.0.8.0 - Husdawg, LLC)
                    Tabletop Simulator (HKLM...\Steam App 286160) (Version: - Berserk Games)
                    TeamSpeak 3 Client (HKLM...\TeamSpeak 3 Client) (Version: 3.1.0 - TeamSpeak Systems GmbH)
                    The Binding of Isaac: Rebirth (HKLM...\Steam App 250900) (Version: - Nicalis, Inc.)
                    The Elder Scrolls V: Skyrim (HKLM-x32...\Steam App 72850) (Version: - Bethesda Game Studios)
                    Total War: ROME II - Emperor Edition (HKLM-x32...\Steam App 214950) (Version: - Creative Assembly)
                    Uplay (HKLM-x32...\Uplay) (Version: 7.1 - Ubisoft)
                    UsbFix (HKLM-x32...\Usbfix) (Version: 9.001 - www.SOSVirus.Net)
                    Visual Studio 2012 x64 Redistributables (HKLM...{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
                    Visual Studio 2012 x86 Redistributables (HKLM-x32...{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
                    VLC media player (HKLM...\VLC media player) (Version: 2.1.5 - VideoLAN)
                    Windows Live Essentials (HKLM-x32...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
                    WinPcap 4.1.2 (HKLM-x32...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
                    WinRAR 5.01 (64-bit) (HKLM...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
                    XviD MPEG-4 Codec (HKLM-x32...\XviD) (Version: - )
                    Xvid Video Codec (HKLM-x32...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)
                    Zemana AntiMalware (HKLM-x32...{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.72.101 - Zemana Ltd.)

                    ==================== Custom CLSID (Whitelisted): ==========================

                    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb ox.exe (Dropbox, Inc.)
                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxExt64.24.dll (Dropbox, Inc.)
                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxExt64.24.dll (Dropbox, Inc.)
                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxExt64.24.dll (Dropbox, Inc.)
                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxExt64.24.dll (Dropbox, Inc.)
                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxExt64.24.dll (Dropbox, Inc.)
                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxExt64.24.dll (Dropbox, Inc.)
                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxExt64.24.dll (Dropbox, Inc.)
                    CustomCLSID: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000_Classes\CLSID{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxExt64.24.dll (Dropbox, Inc.)

                    ==================== Scheduled Tasks (Whitelisted) =============

                    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

                    Task: {02261E59-DCE8-496A-BB04-F4AF99A91189} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyb oardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
                    Task: {0AB570FA-847C-4FB2-9C8C-82067DFA95B4} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
                    Task: {242A82F7-340D-4A9E-B805-6765C513E536} - \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector → No File <==== ATTENTION
                    Task: {47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4} - \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip → No File <==== ATTENTION
                    Task: {67928E07-523E-411F-A980-D440E2B4FD2F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-08-07] (AVAST Software)
                    Task: {8CE2EA77-D7B1-4BC3-B2C1-599DD6DA6212} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-01-27] (AVAST Software)
                    Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent → No File <==== ATTENTION
                    Task: {B4901BDE-F802-4F1D-883E-F469CCBBA02B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-21] (Piriform Ltd)
                    Task: {B7B9216F-9AA0-4CE0-BFFC-D28E2C8B3346} - \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver → No File <==== ATTENTION
                    Task: {C016366B-7126-46CA-B36B-592A3D95A60B} - \Microsoft\Windows\Customer Experience Improvement Program\Consolidator → No File <==== ATTENTION
                    Task: {DFBAA4C3-EF76-49C3-9AA5-6D5543BDA370} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
                    Task: {EC260CC4-BC9B-446B-8A3E-32018B438A45} - \GoogleUpdateTaskMachineUA → No File <==== ATTENTION
                    Task: {FDD56C73-F0D5-41B6-B767-6EFFD7966428} - \Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask → No File <==== ATTENTION

                    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

                    ==================== Shortcuts =============================

                    (The entries could be listed to be restored or removed.)

                    ==================== Loaded Modules (Whitelisted) ==============

                    2015-08-28 10:07 - 2015-08-18 01:07 - 00115376 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
                    2017-02-14 04:08 - 2014-08-06 02:04 - 01441792 _____ () C:\Program Files\Everything\Everything.exe
                    2014-12-09 23:22 - 2014-12-09 23:22 - 00186048 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
                    2014-03-07 18:49 - 2005-04-22 12:36 - 00143360 _____ () C:\Windows\system32\BrSNMP64.dll
                    2017-01-31 16:21 - 2017-02-15 01:13 - 00154480 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
                    2015-08-07 13:03 - 2015-08-07 13:03 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll
                    2015-08-07 13:03 - 2015-08-07 13:03 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
                    2015-04-01 09:31 - 2015-10-04 09:24 - 00012080 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
                    2015-03-15 11:19 - 2017-02-04 13:00 - 51777648 _____ () C:\Users\Philipp\AppData\Roaming\Spotify\libcef.dl l
                    2015-04-07 16:25 - 2015-04-07 16:25 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
                    2015-03-15 11:19 - 2017-02-04 13:00 - 01803888 _____ () C:\Users\Philipp\AppData\Roaming\Spotify\libglesv2 .dll
                    2015-03-15 11:19 - 2017-02-04 13:00 - 00086128 _____ () C:\Users\Philipp\AppData\Roaming\Spotify\libegl.dl l
                    2017-02-09 14:04 - 2017-02-01 10:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libgl esv2.dll
                    2017-02-09 14:04 - 2017-02-01 10:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libeg l.dll

                    ==================== Alternate Data Streams (Whitelisted) =========

                    (If an entry is included in the fixlist, only the ADS will be removed.)

                    ==================== Safe Mode (Whitelisted) ===================

                    (If an entry is included in the fixlist, it will be removed from the registry. The “AlternateShell” will be restored.)

                    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\Hamachi2Svc => “”=“Service”

                    ==================== Association (Whitelisted) ===============

                    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

                    ==================== Internet Explorer trusted/restricted ===============

                    (If an entry is included in the fixlist, it will be removed from the registry.)

                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\2004synchronationals.org → 2004synchronationals.org
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\2009download-best-soft.com → 2009download-best-soft.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\2019wyt.com → 2019wyt.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\2020search.com → 2020search.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\20health.com → 20health.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\20x2p.com → 20x2p.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\23drf.com → 23drf.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\24-7find.com → 24-7find.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\24qas.info → 24qas.info
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\24teen.com → 24teen.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\2828hfdy.com → 2828hfdy.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\2pursuit.com → 2pursuit.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\30search.com → 30search.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\31234.com → 31234.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\3344g.com → 3344g.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\33search.cc → 33search.cc
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\34f.com → 34f.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\34yo.com → 34yo.com
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\356563.net → 356563.net
                    IE restricted site: HKU\S-1-5-21-3041798318-2634963116-1215314133-1000...\366ent.com → 366ent.com

                    There are 4748 more sites.

                    ==================== Hosts content: ===============================

                    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

                    2009-07-14 03:34 - 2016-12-15 00:14 - 00000822 ____A C:\Windows\system32\Drivers\etc\hosts

                    ==================== Other Areas ============================

                    (Currently there is no automatic fix for this section.)

                    HKU\S-1-5-21-3041798318-2634963116-1215314133-1000\Control Panel\Desktop\Wallpaper → C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Themes\TranscodedWallpaper.jpg
                    DNS Servers: 192.168.0.1
                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
                    Windows Firewall is enabled.

                    ==================== MSCONFIG/TASK MANAGER disabled items ==

                    MSCONFIG\startupreg: ControlCenter3 => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
                    MSCONFIG\startupreg: DAEMON Tools Lite => “F:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe” -autorun
                    MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe
                    MSCONFIG\startupreg: mylbx => H:\Program Files\My Lockbox\mylbx.exe /a
                    MSCONFIG\startupreg: NvBackend => “C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe”
                    MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
                    MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSyst emStart
                    MSCONFIG\startupreg: Spotify Web Helper => “C:\Users\Philipp\AppData\Roaming\Spotify\SpotifyW ebHelper.exe”
                    MSCONFIG\startupreg: ZAM => “C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe” /minimized
                    MSCONFIG\startupreg: ZPNConnect => C:\Program Files (x86)\ZPN Connect\ZpnCli.exe

                    ==================== FirewallRules (Whitelisted) ===============

                    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

                    FirewallRules: [TCP Query User{C08FF0F5-29DB-44EC-A0B2-1C041D8E7B20}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
                    FirewallRules: [UDP Query User{8E29BF71-6DD4-46F6-BB43-E4A5A70541EC}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
                    FirewallRules: [{84793CE6-48FB-47E7-9FE5-5EFCA3C4075F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
                    FirewallRules: [{707F8E1A-48A4-4141-AFA3-31B41DEAC47E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
                    FirewallRules: [TCP Query User{35FC1ED5-3753-40E6-95BC-5D51A37C2F41}C:\users\philipp\appdata\roaming\spot ify\spotify.exe] => (Allow) C:\users\philipp\appdata\roaming\spotify\spotify.e xe
                    FirewallRules: [UDP Query User{C1027FE9-43B8-46E2-A032-94AEFF321FFB}C:\users\philipp\appdata\roaming\spot ify\spotify.exe] => (Allow) C:\users\philipp\appdata\roaming\spotify\spotify.e xe
                    FirewallRules: [TCP Query User{6C130734-1935-4313-871F-DCB53C61BCA4}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
                    FirewallRules: [UDP Query User{035EDB85-A203-4F1D-A2B1-B54726C46097}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
                    FirewallRules: [{A695A406-F7E0-4EE3-A219-473219B9AE7B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Golf With Your Friends\Golf With Your Friends.exe
                    FirewallRules: [{FAE4ED6E-6F0F-474A-AC9F-06427C266F03}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Golf With Your Friends\Golf With Your Friends.exe
                    FirewallRules: [{1349D63D-B14D-4441-BDE7-B939D4B55C16}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age2HD\Launcher.exe
                    FirewallRules: [{F9500A2B-3B69-44D2-9743-79C6E306EBB7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Age2HD\Launcher.exe

                    ==================== Restore Points =========================

                    09-02-2017 02:40:25 GG
                    09-02-2017 14:02:40 ResetBrowser
                    11-02-2017 05:30:52 Restore Point Created by FRST
                    14-02-2017 03:59:02 Restore Point Created by FRST
                    14-02-2017 04:28:30 Removed Easy SpeedUp Manager
                    14-02-2017 04:30:31 Entfernt Samsung Update Plus
                    17-02-2017 06:39:10 Restore Point Created by FRST

                    ==================== Faulty Device Manager Devices =============

                    Name: Bluetooth-Gerät (PAN)
                    Description: Bluetooth-Gerät (PAN)
                    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
                    Manufacturer: Microsoft
                    Service: BthPan
                    Problem: : This device is disabled. (Code 22)
                    Resolution: In Device Manager, click “Action”, and then click “Enable Device”. This starts the Enable Device wizard. Follow the instructions.

                    Name: Bluetooth-Peripheriegerät
                    Description: Bluetooth-Peripheriegerät
                    Class Guid:
                    Manufacturer:
                    Service:
                    Problem: : The drivers for this device are not installed. (Code 28)
                    Resolution: To install the drivers for this device, click “Update Driver”, which starts the Hardware Update wizard.

                    Name: Microsoft-6zu4-Adapter
                    Description: Microsoft-6zu4-Adapter
                    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
                    Manufacturer: Microsoft
                    Service: tunnel
                    Problem: : This device cannot start. (Code10)
                    Resolution: Device failed to start. Click “Update Driver” to update the drivers for this device.
                    On the “General Properties” tab of the device, click “Troubleshoot” to start the troubleshooting wizard.

                    Name: Microsoft-ISATAP-Adapter
                    Description: Microsoft-ISATAP-Adapter
                    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
                    Manufacturer: Microsoft
                    Service: tunnel
                    Problem: : This device cannot start. (Code10)
                    Resolution: Device failed to start. Click “Update Driver” to update the drivers for this device.
                    On the “General Properties” tab of the device, click “Troubleshoot” to start the troubleshooting wizard.

                    Name: Microsoft-ISATAP-Adapter #2
                    Description: Microsoft-ISATAP-Adapter
                    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
                    Manufacturer: Microsoft
                    Service: tunnel
                    Problem: : This device cannot start. (Code10)
                    Resolution: Device failed to start. Click “Update Driver” to update the drivers for this device.
                    On the “General Properties” tab of the device, click “Troubleshoot” to start the troubleshooting wizard.

                    Name: Microsoft-ISATAP-Adapter #3
                    Description: Microsoft-ISATAP-Adapter
                    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
                    Manufacturer: Microsoft
                    Service: tunnel
                    Problem: : This device cannot start. (Code10)
                    Resolution: Device failed to start. Click “Update Driver” to update the drivers for this device.
                    On the “General Properties” tab of the device, click “Troubleshoot” to start the troubleshooting wizard.

                    Name: Microsoft-ISATAP-Adapter #4
                    Description: Microsoft-ISATAP-Adapter
                    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
                    Manufacturer: Microsoft
                    Service: tunnel
                    Problem: : This device cannot start. (Code10)
                    Resolution: Device failed to start. Click “Update Driver” to update the drivers for this device.
                    On the “General Properties” tab of the device, click “Troubleshoot” to start the troubleshooting wizard.

                    Name: Teredo Tunneling Pseudo-Interface
                    Description: Microsoft-Teredo-Tunneling-Adapter
                    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
                    Manufacturer: Microsoft
                    Service: tunnel
                    Problem: : This device cannot start. (Code10)
                    Resolution: Device failed to start. Click “Update Driver” to update the drivers for this device.
                    On the “General Properties” tab of the device, click “Troubleshoot” to start the troubleshooting wizard.

                    ==================== Event log errors: =========================
                    [HEADING=1]Application errors:[/HEADING]
                    Error: (02/17/2017 06:41:58 AM) (Source: WinMgmt) (EventID: 10) (User: )
                    Description: Ereignisfilter mit Abfrage “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” konnte im Namespace “//./root/CIMV2” nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

                    Error: (02/17/2017 06:39:08 AM) (Source: VSS) (EventID: 8194) (User: )
                    Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle “IVssWriterCallback” ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
                    .
                    Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.

                    Vorgang:
                    Generatordaten werden gesammelt

                    Kontext:
                    Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
                    Generatorname: System Writer
                    Generatorinstanz-ID: {224fd5d3-3fc9-4f68-9205-c97f89ee091c}

                    Error: (02/16/2017 05:33:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
                    Description: Ereignisfilter mit Abfrage “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” konnte im Namespace “//./root/CIMV2” nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

                    Error: (02/15/2017 03:54:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
                    Description: Ereignisfilter mit Abfrage “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” konnte im Namespace “//./root/CIMV2” nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

                    Error: (02/14/2017 05:46:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
                    Description: Ereignisfilter mit Abfrage “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” konnte im Namespace “//./root/CIMV2” nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

                    Error: (02/14/2017 04:29:39 AM) (Source: NetBalancer 8.6.3 150430.1046) (EventID: 0) (User: )
                    Description: System.Runtime.Remoting.RemotingException: Fehler beim Verbinden mit einem IPC-Port: Das System kann die angegebene Datei nicht finden.

                    Server stack trace:
                    bei System.Runtime.Remoting.Channels.Ipc.IpcPort.Conne ct(String portName, Boolean secure, TokenImpersonationLevel impersonationLevel, Int32 timeout)
                    bei System.Runtime.Remoting.Channels.Ipc.ConnectionCac he.GetConnection(String portName, Boolean secure, TokenImpersonationLevel level, Int32 timeout)
                    bei System.Runtime.Remoting.Channels.Ipc.IpcClientTran sportSink.ProcessMessage(IMessage msg, ITransportHeaders requestHeaders, Stream requestStream, ITransportHeaders& responseHeaders, Stream& responseStream)
                    bei System.Runtime.Remoting.Channels.BinaryClientForma tterSink.SyncProcessMessage(IMessage msg)

                    Exception rethrown at [0]:
                    bei System.Runtime.Remoting.Proxies.RealProxy.HandleRe turnMessage(IMessage reqMsg, IMessage retMsg)
                    bei System.Runtime.Remoting.Proxies.RealProxy.PrivateI nvoke(MessageData& msgData, Int32 type)
                    bei dc.h()
                    bei gl.c(String a)
                    bei gp.a(String a, IEnumerable[ICODE]1 A, IEnumerable[/ICODE]1 b)
                    bei gp.b.a(String a)
                    bei gp.a(String a)

                    Error: (02/14/2017 03:59:00 AM) (Source: VSS) (EventID: 8194) (User: )
                    Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle “IVssWriterCallback” ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
                    .
                    Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.

                    Vorgang:
                    Generatordaten werden gesammelt

                    Kontext:
                    Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
                    Generatorname: System Writer
                    Generatorinstanz-ID: {d88b0619-4273-4cf2-8dbd-665ca3991a0e}

                    Error: (02/14/2017 03:01:48 AM) (Source: Application Error) (EventID: 1000) (User: )
                    Description: Name der fehlerhaften Anwendung: isaac-ng.exe, Version: 0.0.0.0, Zeitstempel: 0x54daa53a
                    Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.1, Zeitstempel: 0x4d5f0c22
                    Ausnahmecode: 0x40000015
                    Fehleroffset: 0x0008d6fd
                    ID des fehlerhaften Prozesses: 0x1298
                    Startzeit der fehlerhaften Anwendung: 0x01d286639e8028aa
                    Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Steam\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe
                    Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Steam\steamapps\common\The Binding of Isaac Rebirth\MSVCR100.dll
                    Berichtskennung: 8a751081-f259-11e6-9ace-e8113241327d

                    Error: (02/13/2017 08:10:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
                    Description: Ereignisfilter mit Abfrage “SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA “Win32_Processor” AND TargetInstance.LoadPercentage > 99” konnte im Namespace “//./root/CIMV2” nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

                    Error: (02/13/2017 08:08:49 PM) (Source: NetBalancerService) (EventID: 0) (User: )
                    Description: Event-ID 0
                    [HEADING=1]System errors:[/HEADING]
                    Error: (02/17/2017 07:01:21 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
                    Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID
                    {C97FCC79-E628-407D-AE68-A06AD6D8B4D1}
                    und APPID
                    {344ED43D-D086-4961-86A6-1106F4ACAD9B}
                    gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden.

                    Error: (02/17/2017 06:51:21 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
                    Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID
                    {C97FCC79-E628-407D-AE68-A06AD6D8B4D1}
                    und APPID
                    {344ED43D-D086-4961-86A6-1106F4ACAD9B}
                    gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden.

                    Error: (02/17/2017 06:41:21 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
                    Description: Durch die Berechtigungseinstellungen (Anwendungsspezifisch) wird der SID (S-1-5-18) für Benutzer NT-AUTORITÄT\SYSTEM von Adresse LocalHost (unter Verwendung von LRPC) keine Berechtigung zum Start (Lokal) für die COM-Serveranwendung mit CLSID
                    {C97FCC79-E628-407D-AE68-A06AD6D8B4D1}
                    und APPID
                    {344ED43D-D086-4961-86A6-1106F4ACAD9B}
                    gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungsprogramm für Komponentendienste geändert werden.

                    Error: (02/17/2017 06:39:46 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
                    Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

                    Modulpfad: C:\Windows\System32\bcmihvsrv64.dll

                    Error: (02/17/2017 06:39:46 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
                    Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

                    Modulpfad: C:\Windows\System32\bcmihvsrv64.dll

                    Error: (02/17/2017 06:39:44 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
                    Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

                    Modulpfad: C:\Windows\System32\bcmihvsrv64.dll

                    Error: (02/17/2017 06:39:36 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
                    Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes “Windows Search” Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
                    Es wird bereits eine Instanz des Dienstes ausgeführt.

                    Error: (02/17/2017 06:39:06 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
                    Description: Der Dienst “Windows Media Player-Netzwerkfreigabedienst” wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

                    Error: (02/17/2017 06:39:06 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
                    Description: Dienst “Office Software Protection Platform” wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

                    Error: (02/17/2017 06:39:06 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
                    Description: Der Dienst “Windows Search” wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
                    [HEADING=1]CodeIntegrity:[/HEADING]
                    Date: 2017-02-03 17:18:23.507
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\wow64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_be0f60e a19636b51\appidapi.dll” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 17:18:23.281
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\wow64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_be0f60e a19636b51\appidapi.dll” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 17:18:23.030
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\wow64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_be0f60e a19636b51\appidapi.dll” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 17:18:22.792
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\wow64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_be0f60e a19636b51\appidapi.dll” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 16:38:13.180
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\amd64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_b3bab69 7e502a956\appid.sys” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 16:38:12.961
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\amd64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_b3bab69 7e502a956\appid.sys” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 16:38:12.740
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\amd64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_b3bab69 7e502a956\appid.sys” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 16:38:12.513
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\amd64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_b3bab69 7e502a956\appid.sys” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 16:38:11.397
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\amd64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_b3bab69 7e502a956\appidapi.dll” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    Date: 2017-02-03 16:38:11.182
                    Description: Die Abbildintegrität der Datei “\Device\HarddiskVolume4\Windows\winsxs\amd64_micr osoft-windows-appid_31bf3856ad364e35_6.1.7600.21490_none_b3bab69 7e502a956\appidapi.dll” konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

                    ==================== Memory info ===========================

                    Processor: Intel(R) Core™ i7 CPU Q 720 @ 1.60GHz
                    Percentage of memory in use: 41%
                    Total physical RAM: 6076.41 MB
                    Available physical RAM: 3572 MB
                    Total Virtual: 12151 MB
                    Available Virtual: 9619.38 MB

                    ==================== Drives ================================

                    Drive c: () (Fixed) (Total:232.79 GB) (Free:53 GB) NTFS
                    Drive f: () (Fixed) (Total:231 GB) (Free:52.76 GB) NTFS
                    Drive g: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)]
                    Drive h: () (Fixed) (Total:344.27 GB) (Free:106.09 GB) NTFS

                    ==================== MBR & Partition Table ==================

                    ================================================== ======
                    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 21133B35)
                    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
                    Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)

                    ================================================== ======
                    Disk: 1 (Size: 596.2 GB) (Disk ID: 9054A324)
                    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
                    Partition 2: (Not Active) - (Size=231 GB) - (Type=07 NTFS)
                    Partition 3: (Not Active) - (Size=344.3 GB) - (Type=OF Extended)
                    Partition 4: (Not Active) - (Size=20.8 GB) - (Type=27)

                    ==================== End of Addition.txt ============================

                    Comment

                    • siq
                      PCHF Member
                      • Jan 2017
                      • 49

                      #85

                      Users shortcut scan result (x64) Version: 15-02-2017 02
                      [/quote]


                      Ran by Philipp (17-02-2017 07:02:22)
                      Running from C:\Users\Philipp\Desktop\Neuer Ordner
                      Boot Mode: Normal

                      ==================== Shortcuts =============================

                      (The entries could be listed to be restored or removed.)

                      Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer{C514 11C0-11DB-AD74-0008-BDAB669A0C20}\SupportTasks\1\Guild Wars 2 Support Webseite.lnk → hxxp://support.guildwars2.com
                      Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer{C514 11C0-11DB-AD74-0008-BDAB669A0C20}\SupportTasks\0\Guild Wars 2 Webseite.lnk → hxxp://www.guildwars2.com
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{FD5BDEE8-D6ED-4E72-B506-CC5D1DB1ACCD}\SupportTasks\1\Support.lnk → hxxp://techsupport.ea.com
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{FD5BDEE8-D6ED-4E72-B506-CC5D1DB1ACCD}\SupportTasks\0\Weitere Spiele von Microsoft.lnk → hxxp://www.ea.com/eagames/official/battlefield1942/home.jsp
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{EAB94306-85E6-4822-B5EC-999D05A05E9B}\SupportTasks\0\Support.lnk → hxxp://www.activision.com/support
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{C076B0C0-DACD-4842-BB85-C50DE47A071E}\SupportTasks\0\Weitere Spiele von Microsoft.lnk → hxxp://www.rockstargames.com/sanandreas
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{BB53BDFE-2F9D-45C2-91A7-769FE9AAC7FD}\SupportTasks\1\Support.lnk → hxxp://techsupport.ea.com
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{BB53BDFE-2F9D-45C2-91A7-769FE9AAC7FD}\SupportTasks\0\Weitere Spiele von Microsoft.lnk → hxxp://www.ea.com/eagames/official/battlefield1942/home.jsp
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{6C8CA64D-9551-4E66-8ADF-B22E4576EAF7}\SupportTasks\1\Support.lnk → hxxp://techsupport.ea.com
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{6C8CA64D-9551-4E66-8ADF-B22E4576EAF7}\SupportTasks\0\Weitere Spiele von Microsoft.lnk → hxxp://www.ea.com/eagames/official/battlefield1942/home.jsp

                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk → C:\Windows\Installer{AC76BA86-7AD7-1031-7B44-AC0F074E4100}\SC_Reader.ico (Flexera Software LLC)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk → C:\Windows\ehome\ehshell.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk → C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk → C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk → C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (TeamSpeak Systems GmbH)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk → C:\Windows\System32\WindowsAnytimeUpgradeUI.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk → C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk → C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware\Zemana AntiMalware.lnk → C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\AviC (FourCC Changer).lnk → F:\XviD\AviC.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\MiniCalc Help.txt.lnk → F:\XviD\MiniCalc.txt ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\MiniCalc.lnk → F:\XviD\MiniCalc.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\ReadMe.txt.lnk → F:\XviD\ReadMe.txt ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\Uninstall XviD.lnk → F:\XviD\UninstXviD.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk → C:\Program Files\WinRAR\Rar.txt ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk → C:\Program Files\WinRAR\WhatsNew.txt ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk → C:\Program Files\WinRAR\WinRAR.chm ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk → C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap\Uninstall WinPcap 4.1.3.lnk → C:\Program Files (x86)\WinPcap\uninstall.exe (No File)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk → F:\Program Files (x86)\VLC\Documentation.url ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk → F:\Program Files (x86)\VLC\NEWS.txt ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk → F:\Program Files (x86)\VLC\VideoLAN Website.url ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk → F:\Program Files (x86)\VLC\vlc.exe (VideoLAN)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk → C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk → C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller\RogueKiller.lnk → C:\Program Files\RogueKiller\RogueKiller64.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer\Razer Cortex\Razer Cortex.lnk → C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe (Razer Inc.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer\PDF-Viewer.lnk → F:\Program Files (x86)\Tracker Software\PDF Viewer\PDFXCview.exe (Tracker Software Products (Canada) Ltd.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer\Uninstall.lnk → F:\Program Files (x86)\Tracker Software\PDF Viewer\unins000.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk → C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe (NVIDIA Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft-Maus- und Tastatur-Center\Microsoft-Maus- und Tastatur-Center.lnk → C:\Windows\Installer{23D2AFC7-C01E-4413-9D9A-0BABF52569BF}\DeviceCenter.ico ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\xlicons.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\joticon.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\outicon.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\pptico.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\wordicon.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Digitales Zertifikat für VBA-Projekte.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\misc.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Clip Organizer.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\cagicon.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office 2010 Upload Center.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\msouc.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office 2010-Spracheinstellungen.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\misc.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Microsoft Office Picture Manager.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\oisicon.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 2010-Tools\Office Anytime Upgrade.lnk → C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Office Setup Controller\promo.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk → C:\Windows\System32\recdisc.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk → C:\Windows\System32\msra.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi\LogMeIn Hamachi.lnk → C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2\Guild Wars 2.lnk → H:\Program Files (x86)\Guild Wars 2\Gw2.exe (ArenaNet)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk → C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Battlefield 1942™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 000000474653493D532079AF6DBF439DCDF2B6F38BC2920000 0000000000000000110042006100740074006C006500660069 0065006C006400200031003900340032002221280000000900 00A01C00000031535053E28A5846BC4C3843BBFC139326986D CE000000000000000000000000
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Battlefield 3™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 000000474653494C83B220D7DAF9498B84C91E43D3B2CD0000 00000000000000000E0042006100740074006C006500660069 0065006C00640020003300222128000000090000A01C000000 31535053E28A5846BC4C3843BBFC139326986DCE0000000000 00000000000000
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chess.lnk → C:\Program Files\Microsoft Games\Chess\Chess.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Die Siedler 7 .lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 000000474653492928525B8DEF3A4E871F361A973FB4170000 00000000000000000E00440069006500200053006900650064 006C006500720020003700200028000000090000A01C000000 31535053E28A5846BC4C3843BBFC139326986DCE0000000000 00000000000000
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Far Cry 3.lnk → L ᐁ À 䘀 6耟迟麨䡰놃낖︬刍 䙇䥓詂鶝縭䐱窾禙畏↠ ɞFernab jeglicher Zivilisation liegt eine von Gewalt beherrschte Insel. Hier bist du gestrandet, mitten in einem blutigen Krieg zwischen wahnsinnigen Warlords und eingeborenen Rebellen, und die Mündung deiner Waffe stellt deine einzige Überlebenschance dar.
                      Entdecke die dunklen Geheimnisse der Insel und trage den Kampf zu deinen Feinden. Improvisiere, nutze deine Umgebung zu deinem Vorteil und sei vor allem schlauer als der Haufen skrupelloser Ausbeuter um dich herum. Lass dich von der Schönheit dieser Insel des Wahnsinns nicht täuschen …
                      Glück allein wird nicht reichen, um hier lebend rauszukommen.( ꀀ 匱卐諢䙘䲼䌸ﲻ錓頦칭
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\FreeCell.lnk → C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk → C:\Windows\System32\gameux.dll (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Hearts.lnk → C:\Program Files\Microsoft Games\Hearts\Hearts.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Backgammon.lnk → C:\Program Files\Microsoft Games\Multiplayer\Backgammon\bckgzm.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Checkers.lnk → C:\Program Files\Microsoft Games\Multiplayer\Checkers\chkrzm.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Spades.lnk → C:\Program Files\Microsoft Games\Multiplayer\Spades\shvlzm.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Mahjong.lnk → C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Minesweeper.lnk → C:\Program Files\Microsoft Games\Minesweeper\Minesweeper.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\More Games from Microsoft.lnk → C:\Program Files\Microsoft Games\More Games\MoreGames.dll (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Purble Place.lnk → C:\Program Files\Microsoft Games\Purble Place\PurblePlace.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Solitaire.lnk → C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Spider Solitaire.lnk → C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\STAR WARS™ The Old Republic™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 00000047465349A3A007B095D74A4882569DDC930A995E0000 00000000000000001D00530054004100520020005700410052 00530022213A00200054006800650020004F006C0064002000 520065007000750062006C0069006300222128000000090000 A01C00000031535053E28A5846BC4C3843BBFC139326986DCE 000000000000000000000000
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\The Elder Scrolls V Skyrim.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 000000474653492C784695408D994B98CB4D031F9B96C10000 00000000000000001B00540068006500200045006C00640065 00720020005300630072006F006C006C007300200056003A00 200053006B007900720069006D0028000000090000A01C0000 0031535053E28A5846BC4C3843BBFC139326986DCE00000000 0000000000000000
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA\BioWare\Star Wars - The Old Republic\Uninstall Star Wars - The Old Republic.lnk → C:\Program Files (x86)\Common Files\BioWare\Uninstall Star Wars - The Old Republic.exe (BioWare, LucasArts)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk → F:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk → F:\Program Files (x86)\DAEMON Tools Lite\SPTDinst-x64.exe (Duplex Secure Ltd.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CLICK & LEARN DiDi 360° DVD\CLICK & LEARN DiDi 360° Benutzerhandbuch.lnk → H:\DiDi_DVD\DiDi.chm ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CLICK & LEARN DiDi 360° DVD\Datenbank wiederherstellen.lnk → H:\DiDi_DVD\cldlDVD.exe (DEGENER Verlag GmbH)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CLICK & LEARN DiDi 360° DVD\Deinstallieren.lnk → H:\DiDi_DVD\unins000.exe ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk → C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Read Me.lnk → C:\Program Files (x86)\Brother\Brmfl08j\RM09aGer.rtf ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Scanner-Einstellungen\Read Me.lnk → C:\Program Files (x86)\Brother\Brmfl08j\ScanRead.txt ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Scanner-Einstellungen\Scanner Utility.lnk → C:\Program Files (x86)\Brother\Brmfl08j\BrScUtil.exe (Brother Industries Ltd.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\PC-FAX-Empfang\PC-Fax-Empfang verwenden.lnk → C:\Program Files (x86)\Brother\Brmfl08j\howtousepcfaxrx.htm ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\PC-Fax senden\PC-Fax-Senden verwenden.lnk → C:\Program Files (x86)\Brother\Brmfl08j\howtousebrotherpc.htm ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Read Me.lnk → C:\Program Files (x86)\Brother\Brmfl08j\RM09aGer.rtf ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Scanner-Einstellungen\Read Me.lnk → C:\Program Files (x86)\Brother\Brmfl08j\ScanRead.txt ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Scanner-Einstellungen\Scanner Utility.lnk → C:\Program Files (x86)\Brother\Brmfl08j\BrScUtil.exe (Brother Industries Ltd.)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\PC-FAX-Empfang\PC-Fax-Empfang verwenden.lnk → C:\Program Files (x86)\Brother\Brmfl08j\howtousepcfaxrx.htm ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\PC-Fax senden\PC-Fax-Senden verwenden.lnk → C:\Program Files (x86)\Brother\Brmfl08j\howtousebrotherpc.htm ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Battle.net.lnk → C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe (Blizzard Entertainment)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software\Avast Free Antivirus.lnk → C:\Program Files\AVAST Software\Avast\avastui.exe (AVAST Software)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk → C:\Windows\System32\comexp.msc ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk → C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk → C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk → C:\Windows\System32\MdSched.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk → C:\Windows\System32\services.msc ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk → C:\Windows\System32\msconfig.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk → C:\Windows\System32\WF.msc ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Bluetooth File Transfer Wizard.lnk → C:\Windows\System32\fsquirt.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk → C:\Windows\System32\calc.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk → C:\Windows\System32\displayswitch.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk → C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk → C:\Windows\System32\mspaint.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk → C:\Windows\System32\mstsc.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk → C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk → C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk → C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk → C:\Windows\System32\mobsync.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk → C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk → C:\Windows\SysWOW64\Windowspowershell\v1.0\powersh ell.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk → C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerSh ell_ISE.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\PowerSh ell_ISE.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk → C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk → C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk → C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk → C:\Windows\System32\charmap.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk → C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk → C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk → C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk → C:\Windows\System32\rstrui.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk → C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk → C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool\9-lab Removal Tool.lnk → C:\Program Files\9-lab\Removal Tool\rmtool.exe (9-lab LLC)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk → C:\Program Files\7-Zip\7zFM.exe (Igor Pavlov)
                      Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk → C:\Program Files\7-Zip\7-zip.chm ()
                      Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer{C514 11C0-11DB-AD74-0008-BDAB669A0C20}\PlayTasks\0\Play.lnk → H:\Program Files (x86)\Guild Wars 2\Gw2.exe (ArenaNet)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Maintenance\Help.lnk → C:\Windows\System32\shell32.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Notepad.lnk → C:\Windows\System32\notepad.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Run.lnk → C:\Windows\System32\shell32.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\System Tools\computer.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\System Tools\Control Panel.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk → C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Accessibility\Magnify.ln k → C:\Windows\System32\Magnify.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Accessibility\Narrator.l nk → C:\Windows\System32\Narrator.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk → C:\Windows\System32\osk.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Shows Desktop.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Window Switcher.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\Links\Desktop.lnk → C:\Users\Philipp\Desktop ()
                      Shortcut: C:\Users\Philipp\Links\Downloads.lnk → C:\Users\Philipp\Downloads ()
                      Shortcut: C:\Users\Philipp\Links\Dropbox.lnk → C:\Users\Philipp\Dropbox ()
                      Shortcut: C:\Users\Philipp\Links\RecentPlaces.lnk → L ᐁ À 䘀 耟穭⊇㞡䘚낑�깚馼 ć ꀀz 匱卐뜥䟯ယ怂麌곫1
                      ἀ က 娀甀氀攀琀稀琀 戀攀猀甀挀栀琀 ⴀ Ѐ
                      Systemordner 匱卐檦⡣锽ᇒ횵쀀�퀘e ἀ ⤀ 㨀㨀笀㈀㈀㠀㜀㜀䄀㘀䐀ⴀ㌀㜀䄀㄀ⴀ㐀㘀㄀䄀ⴀ㤀㄀䈀 ⴀ䐀䈀䐀䄀㔀䄀䄀䔀䈀䌀㤀㤀紀
                      Shortcut: C:\Users\Philipp\Documents\StarCraft II\CrankPhil.590@2.lnk → C:\Users\Philipp\Documents\StarCraft II\Accounts\136888747\2-S2-1-4345313 ()
                      Shortcut: C:\Users\Philipp\Documents\StarCraft II\CrankPhil.847@2.lnk → C:\Users\Philipp\Documents\StarCraft II\Accounts\136889080\2-S2-1-3392550 ()
                      Shortcut: C:\Users\Philipp\Desktop\Sound.lnk → C:\Program Files\Steam\steam\games\0f76d51806079eff9a2722e45d 7cfc207f58cd92.ic (No File)
                      Shortcut: C:\Users\Philipp\Desktop\UsbFix.lnk → C:\UsbFix\UsbFix.exe ()
                      Shortcut: C:\Users\Philipp\Desktop\ZHPDiag.lnk → C:\Users\Philipp\AppData\Roaming\ZHP\ZHPDiag3.exe ()
                      Shortcut: C:\Users\Philipp\Desktop\Ph\Sound.lnk → 0x4C0000000114020000000000C00000000000004681000800 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000133381281F003128D5DFA32323280400000000001F2800 003153505305D5CDD59C2E1B10939708002B2CF9AE57270000 12000000004100750074006F004C0069007300740000004200 00001E000000700072006F0070003400320039003400390036 0037003200390035000000000010270000AEA54E38E1AD8A4E 8A9B7BEA78FFF1E90600008000000000010000000200008001 00000001000000020000000000000000000000160014001F80 1353F9DA4DE4AF46BE1BCBACEA2C3065000000000000000000 00000000000000000000000000010000000100008001000000 04006900740065006D0000000000000000004083A190000000 00000000000000000000000000000000000000000000000000 CBB487EFCEF2854786584CA6C63E38C6FFFFFFFF00000000FF FFFFFF00000000010000001E002000500072006F0067007200 61006D006D0065002F004400610074006500690065006E0020 0064007500720063006800730075006300680065006E000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000004000000456E74650000000000 00000000000000000000000000000000000000000000000100 00000100000001000000000000000100000007000000000000 00000000000000000000000000000000000000000000000000 00000000420000000100000007000000020000000300000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 000000000000000000000000000000160000004F525441414E 41444F4C555F57692D46695F31383334000000000000000000 00010000000100000001000000000000000100000006000000 00000000000000000000000000000000000000000000000000 000000000000003E0000000100000007000000040000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0000000000000000000000000000000000000B000000476C6F 62655375726665720000000000000000000000000000000000 00000000010000000100000001000000000000000100000006 00000000000000000000000000000000000000000000000000 00000000000000000000100000000100000007000000020000 00000000000000000000000000070000000200000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0000000000000000000000000000000000000000001E000000 48502D5072696E742D44332D4F66666963656A65742050726F 20383630300000010000000100000001000000000000000100 00000600000000000000000000000000000000000000000000 000000000000000000000000003E0000000100000007000000 040000000000000000000000000000003E0000000100000007 00000004000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000016 00000053555045524F4E4C494E455F57692D46695F32343732 00000000000000000000010000000100000001000000000000 00010000000700000000000000000000000000000000000000 00000000000000000000000000000000260000000100000007 00000004000000000000000000000000000000000000000000 00002600000001000000070000000400000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000E00000043656C696B4B6F7079616C616D610000000000 00000000000000000000000000010000000100000001000000 00000000010000000700000000000000000000000000000000 000000000000000000000000000000000000000C0000000100 00000700000004000000000000000000000000000000000000 000000000000000000000000000C0000000100000007000000 04000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0000000000050000004354445F320000000000000000000000 00000000000000000000000000000000010000000100000001 00000000000000010000000700000000000000000000000000 000000000000000000000000000000000000000000000E0000 00010000000700000004000000000000000000000000000000 0000000000000000000000000000000000000000000000000E 00000001000000070000000400000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000B0000004354445F4D6973616669720000 00000000000000000000000000000000000000010000000100 00000100000000000000010000000700000000000000000000 00000000000000000000000000000000000000000000000000 14000000010000000700000004000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000140000000100000007000000040000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000600000059415247494300000000 00000000000000000000000000000000000000000000010000 00010000000100000000000000010000000700000000000000 00000000000000000000000000000000000000000000000000 0000003E000000010000000700000004000000000000000000 00000000000001000000070000000000000000000000000000 0000000000000000000000000000000000000000003E000000 01000000070000000400000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 000000000000000000000000000004000000456E7465000000 00000000000000000000000000000000000000000000000000 01000000010000000100000000000000010000000700000000 00000000000000000000000000000000000000000000000000 00000000000042000000010000000700000004000000000000 00000000000000000001000000000000000100000007000000 00000000000000000000000000000000000000000000000000 00000000000000420000000100000007000000040000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000B00000048415953 414C5A5958454C000000000000000000000000000000000000 00000001000000010000000100000000000000010000000600 00000000000000000000000000000000000000000000000000 0000000000000000000A000000010000000400000002000000 00000000000000000000000001000000010000000100000000 00000001000000060000000000000000000000000000000000 0000000000000000000000000000000000000A000000010000 00040000000200000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000001400000041 6972546965735F416972353635305F4B435234000000000000 00000000000001000000010000000100000000000000010000 00070000000000000000000000000000000000000000000000 00000000000000000000000008000000010000000700000004 00000000000000000000000000000000000000010000000100 00000100000001000000000000000100000007000000000000 00000000000000000000000000000000000000000000000000 00000000080000000100000007000000040000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000001600 00004E65744D415354455220557964756E65742D3244443600 00000000000000000001000000010000000100000000000000 01000000070000000000000000000000000000000000000000 0000000000000000000000000000000A000000010000000700 00000400000000000000000000000000324444360000000000 00000000000100000001000000010000000100000000000000 01000000070000000000000000000000000000000000000000 0000000000000000000000000000000A000000010000000700 00000400000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0008000000656E6B6F7274656B000000000000000000000000 00000000000000000000000001000000010000000100000000 00000001000000070000000000000000000000000000000000 00000000000000000000000000000000000010000000010000 00070000000400000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 000000004C4D454DD022000070F34804000000000000000000 0000005202005084997A00700E480B0000000050C6460B0000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000049005900 2E006500590031020033FB997A00700E480B0000000050C646 0B00000000740025002A006D004500770037002C0063005700 6C007B00510068003400600063002D005500410071007E003F 006C004400750053005E005D005D0063004300710031005A00 4E004600760037003F006200520061005E006A006200790039 002E00210040002B0055005000330024004400510070003800 5E00740026007500570033005E0075006F00400061004C0030 007700770066006500240067003F007A00750072006E004900 7E0056005A00260048004B003000280070007A006A005A003F 00550040006A006C0043003800390073006E006B0073006E00 440048005900780034002C0033007600430041005D00540027 004D0078003D006300630072005E004F0063005E0026003200 5B005A006D0064004000750071004200340027006200620058 00460026007300780027006D00540045005300760032004100 2D0075004400430076006400440069004F0056005E006E006B 0047006A002B00210069003F003D0074002700750056007500 56005B006500280035006C0041007B007B00410047007E0070 007D003800610052007B0021004E002C0026006E005A004D00 5B007600650052003F0034004200290057003F002B002B006F 00550078007E0028007D00760052004E004800770040005F00 480048005F0025004100700071007E007200520027004E0077 0072004500520072005A003300340048003900000024000000 004100750074006F006C006900730074004300610063006800 6500540069006D006500000040000000005E43216CC8CF0173 00000022000000004100750074006F006C0069007300740043 0061006300680065004B006500790000001F00000020000000 2000500072006F006700720061006D006D0065002F00440061 0074006500690065006E002000640075007200630068007300 75006300680065006E00300000000000000000000000000074 1A595E96DFD3488D671733BCEE28BA671B730433D90A4590E6 4ACD2E9408FE2A0000001300EFBE0000002000000000000000 0000000000000000000000000000000000010000005728AF04 00007F04811914105504200000000020000000000000000000 00000000000000000000000000000003010000390000003153 505330F125B7EF471A10A5F102608C9EEBAC1D0000000A0000 00001F0000000600000073006F0075006E0064000000000000 00CE0300003153505340E83E1E2BBC6C4782372ACD1A839B22 950300000200000000420000001E000000700072006F007000 3400320039003400390036003700320039003500000000005D 03000059030000550300003153505305D5CDD59C2E1B109397 08002B2CF9AE2100000010000000004B00650079003A005000 49004400000013000000050000006102000014000000004300 6F006E0064006900740069006F006E000000420000001E0000 00700072006F00700034003200390034003900360037003200 390035000000000015020000895CF152175AE148BBCD46A3F8 9C7CC2010000007B085495B6CEAB4599FF50E8428E860D669B 4BC63DE5564CB9AEFEDE4EE95DB10100000000000000000000 0049020000000000005BE9BD216CC8CF0101000000895CF152 175AE148BBCD46A3F89C7CC2010000007B085495B6CEAB4599 FF50E8428E860D669B4BC63DE5564CB9AEFEDE4EE95DB10100 0000000000000000000049020000000000005BE9BD216CC8CF 0101000000895CF152175AE148BBCD46A3F89C7CC201000000 7B085495B6CEAB4599FF50E8428E860D669B4BC63DE5564CB9 AEFEDE4EE95DB1000000000600000073006F0075006E006400 06000000640065002D004400450000000000000000005BE9BD 216CC8CF010000000000000000000000000000000000000000 00000000000000001F000600000073006F0075006E00640000 00000006000000640065002D00440045000000020000000001 0000000600000073006F0075006E0064004400000040E83E1E 2BBC6C4782372ACD1A839B220C0000000D0000001F00060000 0073006F0075006E0064000000000006000000640065002D00 4400450000000200000000010000000600000073006F007500 6E0064000400000040E83E1E2BBC6C4782372ACD1A839B220C 0000000D0000001F000600000073006F0075006E0064000000 000006000000640065002D0044004500000002000000000100 00000600000073006F0075006E006400040000000000007500 000014000000004B00650079003A0046004D00540049004400 0000080000004E0000007B0031004500330045004500380034 0030002D0042004300320042002D0034003700360043002D00 38003200330037002D00320041004300440031004100380033 0039004200320032007D0000000000270000000A000000004E 0061006D0065000000080000000C00000073006F0075006E00 640000001B0000000A00000000540079007000650000001300 00000700000000000000000000000000001D00000008000000 001F0000000600000073006F0075006E006400000000000000 4A00000031535053A66A63283D95D211B5D600C04FD918D011 000000190000000013000000040000301D0000000B00000000 1F0000000600000053007400610063006B0000000000000000 00000000002A0000001900EFBECBB487EFCEF2854786584CA6 C63E38C6000000000000000000000000000000008504E10500 00DB0581191410B10520000000000000000000000000000000 00000000000000000000000000000001000075010000315350 5340E83E1E2BBC6C4782372ACD1A839B221100000014000000 0003000000010000000D000000030000000001000000750000 0011000000001F000000310000007B00320035003200350036 004300320034002D0033004200370035002D00340039004200 33002D0041003400330033002D003400420042003200460038 003800360035003800390036007D002E004D00650072006700 6500200041006E007900000000000D0000000C000000000100 0000B900000008000000001F000000540000003A003A007B00 320036004500450030003600360038002D0041003000300041 002D0034003400440037002D0039003300370031002D004200 450042003000360034004300390038003600380033007D005C 0030005C003A003A007B004600320044004400460043003800 32002D0038004600310032002D0034004300440044002D0042 003700440043002D0044003400460045003100340032003500 41004100340044007D000000000000009402000031535053A6 6A63283D95D211B5D600C04FD918D0F5010000200000000011 100000E10100002C001F8070A47BED548E5E46825C99712043 E01C180000001C00EFBE020073006F0075006E006400000014 00B3010000AD01338B01237F01240000000000000000000000 00000000000000000000000000000000000000000000000100 00390000003153505330F125B7EF471A10A5F102608C9EEBAC 1D0000000A000000001F0000000600000053006F0075006E00 64000000000000006D00000031535053859E8E9C3034B44891 34A2274B46129E510000000200000000111000004000000014 001F706806EE260AA0D7449371BEB064C986830C0001008421 DE39000000001E0071800000000000000000000082FCDDF212 8FDD4CB7DCD4FE1425AA4D000000000000D500000031535053 5B3075B95F546F4C90011E5A4EF928A9B90000000200000000 1F000000530000004B006F006E006600690067007500720069 006500720065006E0020005300690065002000640061007300 200041007500640069006F00670065007200E400740020006F 006400650072002000E4006E006400650072006E0020005300 690065002000640061007300200053006F0075006E00640073 006300680065006D00610020006600FC007200200064006500 6E00200043006F006D00700075007400650072002E00000000 00000000000000000000000000000000110000001900000000 13000000040000000D0000000B000000000100000065000000 18000000001F000000290000003A003A007B00460032004400 440046004300380032002D0038004600310032002D00340043 00440044002D0042003700440043002D004400340046004500 310034003200350041004100340044007D0000000000000000 00DB000000315350533D3BD14B8BE6EC4489EE7611789D4070 7500000069000000001F000000310000007B00310036003800 350044003400410042002D0041003500310042002D00340041 00460031002D0041003400450035002D004300450045003800 370030003000320034003300310044007D002E004D00650072 0067006500200041006E007900000000002D00000064000000 001F0000000E00000063006F006E00740072006F006C002000 700061006E0065006C0000001D00000066000000001F000000 0600000073006F0075006E0064000000000000004600000031 53505330F125B7EF471A10A5F102608C9EEBAC0D0000000E00 000000010000001D0000000A000000001F0000000600000053 006F0075006E0064000000000000002D00000031535053901C 6949177E1A10A91C08002B2ECDA91100000003000000000300 000000000000000000002D00000031535053C0E85BCF6C23D3 4ABACECD608A2748D71100000064000000000B000000FFFF00 00000000002900000031535053B1166D44AD8D7048A748402E A43D788C0D0000006400000000010000000000000000000000 0000000000000000
                      Shortcut: C:\Users\Philipp\Desktop\Ph\Verknüpfungen\Lösch Programm.lnk → 0x4C0000000114020000000000C00000000000004681000800 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000EF3281281F003128D5DFA32323280400000000001F2800 003153505305D5CDD59C2E1B10939708002B2CF9AE57270000 12000000004100750074006F004C0069007300740000004200 00001E000000700072006F0070003400320039003400390036 0037003200390035000000000010270000AEA54E38E1AD8A4E 8A9B7BEA78FFF1E90600008000000000010000000200008001 00000001000000020000000000000000000000160014001F80 1353F9DA4DE4AF46BE1BCBACEA2C3065000000000000000000 00000000000000000000000000010000000100008001000000 04006900740065006D0000000000000000004083A190000000 00000000000000000000000000000000000000000000000000 CBB487EFCEF2854786584CA6C63E38C6FFFFFFFF00000000FF FFFFFF00000000010000001E002000500072006F0067007200 61006D006D0065002F004400610074006500690065006E0020 0064007500720063006800730075006300680065006E000000 0000000000000000000000000000000000000000000044007D 005C00500072006F0067006900640000003200300045007D00 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 000060EA740500000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000050 562A0400000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000005C0052 0065006700690073007400720079005C004D00610063006800 69006E0065005C0053006F006600740077006100720065005C 0043006C00610073007300650073005C0057006F0077003600 3400330032004E006F00640065005C0043004C005300490044 005C007B00440041004600390035003300310033002D004500 3400340044002D0034003600410046002D0042004500310042 002D0043004200410043004500410032004300330030003600 35007D000000390035003300310033002D0045003400340044 002D0034003600410046002D0042004500310042002D004300 420041004300450041003200430033003000360035007D0000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0000000000000000000080E32B000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 60E87405000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0000000000000000000000000000000000000000005C005200 65006700690073007400720079005C004D0061006300680069 006E0065005C0053006F006600740077006100720065005C00 43006C00610073007300650073005C0057006F007700360034 00330032004E006F00640065005C0043004C00530049004400 5C007B00360045003600380032003700380034002D00310045 00430041002D0034004300460032002D003900380038004400 2D003900360042003600450038003900450039004100340044 007D000000380032003700380034002D003100450043004100 2D0034004300460032002D0039003800380044002D00390036 0042003600450038003900450039004100340044007D000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0000000000000000000000000000000000003904003D369E16 0058011D000000000070857505000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0000000000000000000000000020EB74050000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 000000000000000000000000000000F03E2D04000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000016000016CD9C1600708C84020000000010CE2A000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 000000000001010101B09C161010B891020000000001000200 0000000050A4270000000000090000000000000080A3270000 000000090000000000000080A32700000000000C0000000000 000010E18C02000000000C0000000000000090E58C02000000 000C000000000000000000000000000000F90300FA369E1600 58011D00000000007085750500000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 000000000000000000000000000000000001010101B39B1610 10B8910200000000010003000000000010E18C020000000000 0001000000000090E58C0200000000000001000000000080A3 270000000000000001000000000050A4270000000000000001 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000003900000024000000 004100750074006F006C006900730074004300610063006800 6500540069006D006500000040000000E01830F54D84CC0173 00000022000000004100750074006F006C0069007300740043 0061006300680065004B006500790000001F00000020000000 2000500072006F006700720061006D006D0065002F00440061 0074006500690065006E002000640075007200630068007300 75006300680065006E00300000000000000000000000000074 1A595E96DFD3488D671733BCEE28BA671B730433D90A4590E6 4ACD2E9408FE2A0000001300EFBE0000002000000000000000 00000000000000000000000000000000000100000057287704 00004704811914101D04200000000020000000000000000000 00000000000000000000000000000003010000350000003153 505330F125B7EF471A10A5F102608C9EEBAC190000000A0000 00001F000000030000007000720000000000000000009A0300 003153505340E83E1E2BBC6C4782372ACD1A839B2265030000 0200000000420000001E000000700072006F00700034003200 39003400390036003700320039003500000000002D03000029 030000250300003153505305D5CDD59C2E1B10939708002B2C F9AE2100000010000000004B00650079003A00500049004400 0000130000000500000035020000140000000043006F006E00 64006900740069006F006E000000420000001E000000700072 006F0070003400320039003400390036003700320039003500 00000000EB010000895CF152175AE148BBCD46A3F89C7CC201 0000007B085495B6CEAB4599FF50E8428E860D669B4BC63DE5 564CB9AEFEDE4EE95DB1010000000000000000000000490200 0000000000D54C69F54D84CC0101000000895CF152175AE148 BBCD46A3F89C7CC2010000007B085495B6CEAB4599FF50E842 8E860D669B4BC63DE5564CB9AEFEDE4EE95DB1010000000000 0000000000004902000000000000D54C69F54D84CC01010000 00895CF152175AE148BBCD46A3F89C7CC2010000007B085495 B6CEAB4599FF50E8428E860D669B4BC63DE5564CB9AEFEDE4E E95DB100000000030000007000720006000000640065002D00 440045000000000000000000D54C69F54D84CC010000000000 00000000000000000000000000000000000000000000001F00 03000000700072000000000006000000640065002D00440045 00000002000000000100000003000000700072004400000040 E83E1E2BBC6C4782372ACD1A839B220C0000000D0000001F00 03000000700072000000000006000000640065002D00440045 00000002000000000100000003000000700072000400000040 E83E1E2BBC6C4782372ACD1A839B220C0000000D0000001F00 03000000700072000000000006000000640065002D00440045 00000002000000000100000003000000700072000400000000 7500000014000000004B00650079003A0046004D0054004900 44000000080000004E0000007B003100450033004500450038 00340030002D0042004300320042002D003400370036004300 2D0038003200330037002D0032004100430044003100410038 00330039004200320032007D0000000000230000000A000000 004E0061006D00650000000800000006000000700072000000 00001B0000000A000000005400790070006500000013000000 0700000000000000000000000000001900000008000000001F 000000030000007000720000000000000000004A0000003153 5053A66A63283D95D211B5D600C04FD918D011000000190000 000013000000040000301D0000000B000000001F0000000600 000053007400610063006B000000000000000000000000002A 0000001900EFBECBB487EFCEF2854786584CA6C63E38C60000 00000000000000000000000000004D04F5050000EF05811914 10C50520000000000000000000000000000000000000000000 000000000000000000010000750100003153505340E83E1E2B BC6C4782372ACD1A839B221100000014000000000300000001 0000000D000000030000000001000000750000001100000000 1F000000310000007B00320035003200350036004300320034 002D0033004200370035002D0034003900420033002D004100 3400330033002D003400420042003200460038003800360035 003800390036007D002E004D00650072006700650020004100 6E007900000000000D0000000C0000000001000000B9000000 08000000001F000000540000003A003A007B00320036004500 450030003600360038002D0041003000300041002D00340034 00440037002D0039003300370031002D004200450042003000 360034004300390038003600380033007D005C0030005C003A 003A007B00370042003800310042004500360041002D004300 4500320042002D0034003600370036002D0041003200390045 002D0045004200390030003700410035003100320036004300 35007D000000000000008402000031535053A66A63283D95D2 11B5D600C04FD918D0E5010000200000000011100000D30100 0026001F8070A47BED548E5E46825C99712043E01C12000000 1C00EFBE02007000720000001400AB010000A501338B012377 01240000000000000000000000000000000000000000000000 0000000000000000000000010000610000003153505330F125 B7EF471A10A5F102608C9EEBAC450000000A000000001F0000 0019000000500072006F006700720061006D006D0065002000 75006E0064002000460075006E006B00740069006F006E0065 006E0000000000000000006D00000031535053859E8E9C3034 B4489134A2274B46129E510000000200000000111000004000 000014001F706806EE260AA0D7449371BEB064C986830C0001 008421DE39000000001E007180000000000000000000006ABE 817B2BCE7646A29EEB907A5126C5000000000000A500000031 5350535B3075B95F546F4C90011E5A4EF928A9890000000200 0000001F0000003B0000004400650069006E00730074006100 6C006C0069006500720065006E0020006F0064006500720020 00E4006E006400650072006E00200053006900650020005000 72006F006700720061006D006D006500200061007500660020 00640065006D00200043006F006D0070007500740065007200 2E000000000000000000000000000000000000110000001900 00000013000000040000000D0000000B000000000100000065 00000018000000001F000000290000003A003A007B00370042 003800310042004500360041002D0043004500320042002D00 34003600370036002D0041003200390045002D004500420039 003000370041003500310032003600430035007D0000000000 00000000D7000000315350533D3BD14B8BE6EC4489EE761178 9D40707500000069000000001F000000310000007B00310036 003800350044003400410042002D0041003500310042002D00 34004100460031002D0041003400450035002D004300450045 003800370030003000320034003300310044007D002E004D00 6500720067006500200041006E007900000000002D00000064 000000001F0000000E00000063006F006E00740072006F006C 002000700061006E0065006C0000001900000066000000001F 000000030000007000720000000000000000006E0000003153 505330F125B7EF471A10A5F102608C9EEBAC0D0000000E0000 000001000000450000000A000000001F000000190000005000 72006F006700720061006D006D006500200075006E00640020 00460075006E006B00740069006F006E0065006E0000000000 000000002D00000031535053901C6949177E1A10A91C08002B 2ECDA91100000003000000000300000000000000000000002D 00000031535053C0E85BCF6C23D34ABACECD608A2748D71100 000064000000000B000000FFFF000000000000290000003153 5053B1166D44AD8D7048A748402EA43D788C0D000000640000 00000100000000000000000000000000000000000000
                      Shortcut: C:\Users\Philipp\Desktop\Ph\Verknüpfungen\Sound - Verknüpfung.lnk → 0x4C0000000114020000000000C00000000000004681000800 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000133381281F003128D5DFA32323280400000000001F2800 003153505305D5CDD59C2E1B10939708002B2CF9AE57270000 12000000004100750074006F004C0069007300740000004200 00001E000000700072006F0070003400320039003400390036 0037003200390035000000000010270000AEA54E38E1AD8A4E 8A9B7BEA78FFF1E90600008000000000010000000200008001 00000001000000020000000000000000000000160014001F80 1353F9DA4DE4AF46BE1BCBACEA2C3065000000000000000000 00000000000000000000000000010000000100008001000000 04006900740065006D0000000000000000004083A190000000 00000000000000000000000000000000000000000000000000 CBB487EFCEF2854786584CA6C63E38C6FFFFFFFF00000000FF FFFFFF00000000010000001E002000500072006F0067007200 61006D006D0065002F004400610074006500690065006E0020 0064007500720063006800730075006300680065006E000000 00000000000000000000000000000000000000000000600000 002000F2FD1F00200000000007000000004000240000080000 E40C00007F0400000300000000000000000100000000000001 00000000000000616C000800000000E4010000700100000400 00002A00000013000000000000000000000090010000000000 00030201224D006900630072006F0073006F00660074002000 4E0065007700200054006100690020004C0075006500000000 000000020000000000000001000000030000004D0069006300 72006F0073006F006600740020004E00650077002000540061 00690020004C0075006500000000000000E800000002000000 020000003D0000003F00000001000000E70000000200000002 0000003F0000004000000003000000E5000000020000000000 000040000000FFFFFF7F000000000FF000019FC00000520065 00670075006C006100720000000000FFFFF300FF000FFFFFFF FF400EF402FF00FF9009FA00FF9107FF00EF402FF00AF303FA 00FF000FFFFFFE81000000000000FF1001FF00FF1000FF0000 48CFF00EFFFFFE00FF000FF005EFC00004EFFFFF00FF0000FF 00FF0000FF004EFFFFF00FFFFFFF00FF000FF0004FFA000DF8 6476000800000000FF0000FF0BFF0C0D2A0000001E0000000C 0000000A00000000000000130000002A000000900100000000 000060000000600000000D0064FF0C000D000000002700000B 004000240000080000770A0000AD0400000300000000000000 00000080000000000100000000000000616C000800000000E4 01000070010000040000002100000012000000000000000000 00009001000000000000030201024E00790061006C00610000 00200055004900000077000000FF0000000000000000000000 0000FF000FF000000FF0008EFFA200FF4DFD4000FF08FE9000 0800004E00790061006C006100000020005500490000007700 0000FF8FFFF9009FFFFFB003FFFFF300FF000FFFFFFFFF400E F402FF00FF9009FA00FF9107FF00EF402FF00AF303FA00FF00 0FFFFFFE810000048CFF00FF1001FF00FF1000FF000048CFF0 0EFFFFFE00FF000FF005EFC00004EFFFFF00FF0000FF00FF00 00FF004E00005300740061006E006400610072006400000000 FF1001FE00FF0000FF00DF861FF00FF0000000FF000FF00007 FF400FF206FF00FFB009FA00FF0000FF00FF00000000F904FD 00FF000FF00000CFE00BFFFFEF10FFEFFFF200FF0000FF00BF FFFEF103FFFFF400FF000FF000002FFA00AFE92F90FF2DFC30 00FF0000FF000AFE926476000800000000000000001EFF1F20 210000001A0000000700000001000000000000001200000034 00000090010000000000006000000060000000200004FB1F00 2000000000070000000040002400000800005C080000780400 006F0000A00000000000080000000000009300000000000000 616C000800000000E401000070010000040000002900000018 00000000000000000000009001000000000000030201224D00 6900630072006F0073006F0066007400200050006800610067 0073005000610000000000FF00000000000000000090B27AC0 00F9FFFF00000000000000004D006900630072006F0073006F 00660074002000500068006100670073005000610000000000 000013000000FF400EF402FF00FF9009FA00FF9107FF00EF40 2F000000000000000000000000000000000000000000000000 0000000000000000700EFFFFFE00FF00000000000000000020 BCCBC100F9FFFF000000000000000052006500670075006C00 61007200000000000100000000000000000000000000000000 000000000013000000FF400FF20083FFFF0083FFFF00000000 00000000000061006C00740069007300630068000000FFFFAF 82FFFF370000001F00000080000000F400FF00000000000000 000020BCCBC100F9FFFF000000000000000064760008000000 000201020007FF080929000000210000000800000009000000 00000000180000003D00000090010000000000006000000060 000000090000FE080009000000002700000000400024000008 00003C0A000015060000030000000000200000000008000000 000100000000000000616C000800000000E401000070010000 04000000290000000E00000000000000000000009001000000 0000000302011250006C0061006E0074006100670065006E00 65007400200043006800650072006F006B0065006500000000 000FF0008EFFA200FF4DFD4000FF08FE900008000050006C00 61006E0074006100670065006E006500740020004300680065 0072006F006B00650065000000FFFFFF400EF402FF00FF9009 FA00FF9107FF00EF402FF00AF303FA00FF000FFFFFFE810000 048CFF00FF1001FF00FF1000FF000048CFF00EFFFFFE00FF00 0FF005EFC00004EFFFFF00FF0000FF00FF0000FF004E000053 00740061006E006400610072006400000000FF1001FE00FF00 00FF00DF861FF00FF0000000FF000FF00007FF400FF206FF00 FFB009FA00FF0000FF00FF0000000069007400740065006C00 6500750072006F007000E40069007300630068000000FFFFF4 00FF000FF000002FFA00AFE92F90FF2DFC3000FF0000FF000A FE926476000800000000000000001EFF1F20290000001F0000 000A00000009000000020000000E0000002D00000090010000 000000006000000060000000200015221F0020000000001700 0000004000240000080000270A000089030000030000000000 000000100000000000000100000000000000616C0008000000 00E40100007001000004000000350000000D00000000000000 00000000900100000000000003020122520061006100760069 0000006F006600740020004A00680065006E00670048006500 690000000000000000000FF0008E283F2CC200F9FFFF703E2C C200F900005200610061007600690000006F00660074002000 4A00680065006E00670048006500690000000000E80000003F 00000000000000000000800000000000000000020000000000 00000100000003000000E50000000200000002000000010000 000300000001000000E7000000020000000200000003000000 3D0000000000000052006500670075006C0061007200000000 00000001000000E700000002000000000000003F000000FFFF FF7F0000000006FF00FFB009FA00FF0000FF00FF0000000079 00720069006C006C0069007300630068000000F200FF0000FF 00BFFFFEF103FFFFF400FF000FF000002FFA00AFE92F90FF2D FC3000FF0000FF000AFE926476000800000000000000001EFF 1F2035000000200000001500000015000000040000000D0000 003A000000900100000000000060000000600000002000CC25 1F00200000000027000000004000240000080000480D000045 03000003000200000000000000000000000000010000000000 0000616C000800000000E40100007001000004000000330000 00160000000000000000000000900100000000000003020122 5300650067006F006500200053006300720069007000740000 0065006E00670048006500690000000FF000000FF0008EFFA2 00FF4DFD4000FF08FE90000800005300650067006F00650020 00530063007200690070007400000065006E00670048006500 690000000FFFFFFFFF400EF402FF00FF9009FA00FF9107FF00 EF402FF00AF303FA00FF000FFFFFFE810000048CFF00FF1001 FF00FF1000FF000048CFF00EFFFFFE00FF000FF005EFC00004 EFFFFF00FF0000FF00FF0000FF004E00005300740061006E00 6400610072006400000000FF1001FE00FF0000FF00DF861FF0 0FF0000000FF000FF00007FF400FF206FF00FFB009FA00FF00 00FF00FF000000007200690065006300680069007300630068 000000F200FF0000FF00BFFFFEF103FFFFF400FF000FF00000 2FFA00AFE92F90FF2DFC3000FF0000FF000AFE926476000800 000000000000001EFF1F203300000023000000100000001300 00000000000016000000370000009001000000000000600000 0060000000200002FB1F002000000000270000000040002400 00080000AC0C0000720500008F020000000000000000000000 0000009F00000000000000616C000800000000E40100007001 0000040000002B000000110000000000000000000000900100 0000000000030201225300650067006F006500200055004900 00002000590061004800650069000000000000000000FF000F F000000FF0008EFFA200FF4DFD4000FF08FE90000800005300 650067006F0065002000550049000000200059006100480065 0069000000B003FFFFF300FF000FFFFFFFFF400EF402FF00FF 9009FA00FF9107FF00EF402FF00AF303FA00FF000FFFFFFE81 0000048CFF00FF1001FF00FF1000FF000048CFF00EFFFFFE00 FF000FF005EFC00004EFFFFF00FF0000FF00FF0000FF004E00 005300740061006E006400610072006400000000FF1001FE00 FF0000FF00DF861FF00FF0000000FF000FF00007FF400FF206 FF00FFB009FA00FF0000FF00FF00000000FC0072006B006900 730063006800000010FFEFFFF200FF0000FF00BFFFFEF103FF FFF400FF000FF000002FFA00AFE92F90FF2DFC3000FF0000FF 000AFE926476000800000000000000000BFF0C0D2B00000023 000000080000000B00000000000000110000003E0000009001 00000000000060000000600000000D00FDFF0C000D00000000 27000000004000240000080000A40A00004F040000FF2200E1 7FE400C02900000000000000DF01002000000020616C000800 000000E401000070010000040000002B000000120000000000 0000000000005802000000000000030201225300650067006F 0065002000550049002000530065006D00690062006F006C00 64000000000000005801010000000000420102000000000040 010100000000005300650067006F0065002000550049002000 530065006D00690062006F006C006400000000000000440205 00000000004800120000000000EE0005000000000020040700 00000000180602000000000016060100000000005A05050000 00000048040200000000001004040000000000260501000000 0000880202000000000052006500670075006C006100720000 000000020000000000DC01020000000000E401020000000000 E20002000000000062010500000000005A0101000000000000 00010000000000900001000000000006020100000000008001 020000000000C6000100000000002401020000000000020102 00000000007601020000000000647600080000000074010200 0BFF0C0D2B00000023000000080000000B0000000000000012 0000003A000000580200000000000060000000600000000D00 23FE0C000D0000000027000203004000240000080000A40A00 0085040000FF0200E07BA4004001000000000000009F010020 00000000616C000800000000E401000070010000040000002B 0000001100000000000000000000002C010000000000000302 01225300650067006F00650020005500490020004C00690067 006800740000000000000000000000FF000FF000000FF0008E FFA200FF4DFD4000FF08FE90000800005300650067006F0065 0020005500490020004C0069006700680074000000FFFFB003 FFFFF300FF000FFFFFFFFF400EF402FF00FF9009FA00FF9107 FF00EF402FF00AF303FA00FF000FFFFFFE810000048CFF00FF 1001FF00FF1000FF000048CFF00EFFFFFE00FF000FF005EFC0 0004EFFFFF00FF0000FF00FF0000FF004E0000520065006700 75006C00610072000000000000FF1001FE00FF0000FF00DF86 1FF00FF0000000FF000FF00007FF400FF206FF00FFB009FA00 FF0000FF00FF00000000F904FD00FF000FF00000CFE00BFFFF EF10FFEFFFF200FF0000FF00BFFFFEF103FFFFF400FF000FF0 00002FFA00AFE92F90FF2DFC3000FF0000FF000AFE92647600 0800000000000000000BFF0C0D2B0000002300000008000000 0B0000000000000011000000380000002C0100000000000060 000000600000000D0023FE0C000D0000000027000000004000 240000080000A40A000038040000FF0200E07BA40040010000 00000000009F01002000000000616C000800000000E4010000 70010000040000002B00000017000000000000000000000090 01000000000000030201225300650067006F00650020005500 49002000530079006D0062006F006C000000610000000000FF 000FF000000FF0008EFFA200FF4DFD4000FF08FE9000080000 5300650067006F0065002000550049002000530079006D0062 006F006C00000061000000F300FF000FFFFFFFFF400EF402FF 00FF9009FA00FF9107FF00EF402FF00AF303FA00FF000FFFFF FE810000048CFF00FF1001FF00FF1000FF000048CFF00EFFFF FE00FF000FF005EFC00004EFFFFF00FF0000FF00FF0000FF00 4E00005300740061006E006400610072006400000000FF1001 FE00FF0000FF00DF861FF00FF0000000FF000FF00007FF400F F206FF00FFB009FA00FF0000FF00FF00000000F904FD00FF00 0FF00000CFE00BFFFFEF10FFEFFFF200FF0000FF00BFFFFEF1 03FFFFF400FF000FF000002FFA00AFE92F90FF2DFC3000FF00 00FF000AFE926476000800000000000000000BFF0C0D2B0000 0023000000080000000B00000000000000170000003F000000 900100000000000060000000600000000D0013F00C000D0000 000027000000004000240000080000A40A0000A40500006F00 0080EFFB001200C06400020000000100000000000040616C00 0800000000E40100007001000004000000360000000E000000 00000000000000009001000000000000030201225300680072 00750074006900000055000000000000000000FF0000000000 0000000000000000FF000FF000000FF0008EFFA200FF4DFD40 00FF08FE900008000053006800720075007400690000005500 000000FFFFFFF300FF8FFFF9009FFFFFB003FFFFF300FF000F FFFFFFFF400EF402FF00FF9009FA00FF9107FF00EF402FF00A F303FA00FF000FFFFFFE810000048CFF00FF1001FF00FF1000 FF000048CFF00EFFFFFE00FF000FF005EFC00004EFFFFF00FF 0000FF00FF0000FF004E000052006500670075006C00610072 00000061FF00FF1001FE00FF0000FF00DF861FF00FF0000000 FF000FF00007FF400FF206FF00FFB009FA00FF0000FF00FF00 000000F904FD00FF000FF00000CFE00BFFFFEF10FFEFFFF200 FF0000FF00BFFFFEF103FFFFF400FF000FF000002FFA00AFE9 2F90FF2DFC3000FF0000FF000AFE9264760008000000000000 00000BFF0C0D36000000210000001500000016000000050000 000E0000004600000090010000000000006000000060000000 0D00CC250C000D000000002700000000400024000008000073 0D000071030000030004000000000000000000000000000100 000000000000616C000800000000E401000070010000040000 00200000001000000000000000000000009001000000000000 03020102530069006D00530075006E00000069005500000000 000000FF00000000000000000000000000FF000FF000000FF0 008EFFA200FF4DFD4000FF08FE9000080000530069006D0053 0075006E000000690055000000FFFFF300FF8FFFF9009FFFFF B003FFFFF300FF000FFFFFFFFF400EF402FF00FF9009FA00FF 9107FF00EF402FF00AF303FA00FF000FFFFFFE810000048CFF 00FF1001FF00FF1000FF000048CFF00EFFFFFE00FF000FF005 EFC00004EFFFFF00FF0000FF00FF0000FF004E000052006500 670075006C0061007200000061FF00FF1001FE00FF0000FF00 DF861FF00FF0000000FF000FF00007FF400FF206FF00FFB009 FA00FF0000FF00FF00000000F904FD00FF000FF00000CFE00B FFFFEF10FFEFFFF200FF0000FF00BFFFFEF103FFFFF400FF00 0FF000002FFA00AFE92F90FF2DFC3000FF0000FF000AFE9264 76000800000000000000001EFF1F20200000001C0000000400 00000000000005000000100000002000000090010000000000 0060000000600000002000E5FF1F0020000000000700000000 400024000001000000010000800000000300000000008F2806 000000000000000100040000000000616C000800000000E401 00007001000004000000200000001000000000000000000000 009001000000000000030201024000530069006D0053007500 6E00000048004B005300430053000000000000000000000000 00FF000FF000000FF0008EFFA200FF4DFD4000FF08FE900008 00004000530069006D00530075006E00000048004B00530043 0053000000009FFFFFB003FFFFF300FF000FFFFFFFFF400EF4 02FF00FF9009FA00FF9107FF00EF402FF00AF303FA00FF000F FFFFFE810000048CFF00FF1001FF00FF1000FF000048CFF00E FFFFFE00FF000FF005EFC00004EFFFFF00FF0000FF00FF0000 FF004E000052006500670075006C0061007200000061FF00FF 1001FE00FF0000FF00DF861FF00FF0000000FF000FF00007FF 400FF206FF00FFB009FA00FF0000FF00FF00000000F904FD00 FF000FF00000CFE00BFFFFEF10FFEFFFF200FF0000FF00BFFF FEF103FFFFF400FF000FF000002FFA00AFE92F90FF2DFC3000 FF0000FF000AFE926476000800000000000000001EFF1F2020 0000001C000000040000000000000005000000100000002000 0000900100000000000060000000600000002000E5FF1F0020 00000000070000000040002400000100000001000080000000 0300000000008F280600000000000000010004000000000061 6C000800000000E40100007001000004000000200000001000 000000000000000000009001000000000000030201314E0053 0069006D00530075006E0000005F0048004B00530043005300 000001444500000005630900086D0F655F0001436418000000 00000005671800000000004E00530069006D00530075006E00 00005F0048004B005300430053000000000000000000086F69 726A0000000000000002581800000002581800000005630900 086D0F63272E085C4218000000000000000309001745000000 000002592E00000002592E0000000005697272712E05631345 162F42180000000000000000000052006500670075006C0061 00720000000000000005630900000005630B50421942180000 00000000086A00001745000000056718000000056718000000 00000000000900000005630A3F5F014218000000000000002D 72725B000258182D727272725B2D727272725B000000056309 000000056309175B0142180000000000006476000800000000 000000001EFF1F20200000001C000000040000000000000005 00000010000000200000009001000000000000600000006000 00002000E5FF1F002000000000360000000040002400000100 0000010000800000000300000000008F280600000000000000 0100040000000000616C000800000000E40100007001000004 00000020000000100000000000000000000000900100000000 00000302013140004E00530069006D00530075006E00000002 0000000000E20002000000000062010500000000005A010100 000000009200010000000000900001000000000040004E0053 0069006D00530075006E000000010000000000240102000000 00000201020000000000760102000000000078010300000000 007401020000000000FE00020000000000C203020000000000 2C030300000000005E03040000000000F201010000000000DA 00010000000000B202030000000000B4020300000000005200 6500670075006C00610072000000EA000700000000000A030A 0000000000C8030200000000008604050000000000A4000800 00000000240305000000000000000400000000003006030000 000000F005040000000000B400020000000000B60002000000 00002E060200000000002A0602000000000000040100000000 0064760008000000005A0201001EFF1F20200000001C000000 04000000000000000500000010000000200000009001000000 00000060000000600000002000E5FF1F002000000000360003 0200400024000001000000010000800000000300000000008F 2806000000000000000100040000000000616C000800000000 E4010000700100000400000020000000100000000000000000 000000900100000000000003020131530069006D0053007500 6E002D00450078007400420000004200000000000000000000 0000000000000000001100000011000000F4FFFFFF00000000 00000000530069006D00530075006E002D0045007800740042 00000042000000550049000000000000000000000000000000 00000000000000000000000000000000000000000000000000 0000000000000000001300000013000000F4FFFFFF00000000 00000000000000009001000000000001000000005300650067 006F00650000005300740061006E0064006100720064000000 00000000000000000000000000000000000000000000000000 000000000000000000F4FFFFFF000000000000000000000000 9001000000000001000000005300650067006F006500200055 00490000000000000000000000000000000000000000000000 000000000000000000006476000800000000000000001E7F1F 20200000001C00000004000000000000000000000010000000 3B0000009001000000000000600000006000000020007F001F 00200000000036000000004000240000010000000100008000 00000100000000000002000000000000000001000400000000 00616C000800000000E4010000700100000400000020000000 10000000000000000000000090010000000000000302013140 00530069006D00530075006E002D0045007800740042000000 000047683134000000000000000010196AC300F9FFFF000000 000000000000000000000000004000530069006D0053007500 6E002D0045007800740042000000000000F9FFFF90CE68C300 F9FFFF60CE68C300F9FFFF20B7290060F9FFFFA00000000300 00000000000000000000F40300001E00000000000000000000 80000000000000000002000000000000001E00000000000000 F403000002000000000000001E0000005300740061006E0064 0061007200640000000000030000000400000003000000E300 00000200000002000000040000000700000002000000E30000 000200000000000000070000001D00000001000000E3000000 02000000020000001D0000001E000000010000000800000002 000000020000001E000000AE00000001000000647600080000 0000000000001E7F1F20200000001C00000004000000000000 0000000000100000003B000000900100000000000060000000 6000000020007F001F00200000000036000000004000240000 01000000010000800000000100000000000002000000000000 00000100040000000000616C000800000000E4010000700100 00040000002A0000000D000000000000000000000090010000 0000000003020112530079006C006600610065006E00000055 002D00450078007400420000003134000000000000000020FC DBC100F9FFFF00000000000000000000000000000000530079 006C006600610065006E00000055002D004500780074004200 0000FFFFA0FAD2C100F9FFFF70FAD2C100F9FFFF20B7290060 F9FFFFA0000000030000000000000000000000A00000001B00 00000000000000000080000000000000000002000000000000 001B00000000000000A000000002000000000000001B000000 5300740061006E00640061007200640000000000030000003D 00000000000000E800000002000000020000003D0000003F00 000001000000E700000002000000000000003F000000400000 0003000000E5000000020000000000000040000000FFFFFF7F 00000000500000000200000002000000170000001800000003 0000006476000800000000020000001EFF1F202A0000002000 00000A0000000A000000000000000D00000033000000900100 000000000060000000600000002000FCFF1F00200000000017 000000004000240000080000890A00005B0300008706000400 00000000000000000000009F00002000000000616C00080000 0000E401000070010000040000002900000013000000000000 00000000009001000000000000030201224D00690063007200 6F0073006F0066007400200054006100690020004C00650000 00420000000000000000000000000000000000000000000008 7272450000004D006900630072006F0073006F006600740020 0054006100690020004C006500000042000000671800000017 6A000144450563090144450000000000000000000563090143 2E05630901432E02581800000000175B05630901432E000000 000000000000086A00002D45086A00002D4500000000000002 5818000569712E000052006500670075006C00610072000000 00002D45000000000002592E00086D09014445000000000000 00000005630901432E05630901432E00000000056800000000 6500730074006C0069006300680000002E05671802592E0567 18000000056718000000086D09002D5B000000000000000000 00087272450000087272450064760008000000005B002D720B FF0C0D290000001E0000000B00000009000000000000001300 000033000000900100000000000060000000600000000D0064 FF0C000D00000000270000000040002400000800002C0A0000 B2040000030000000000000000000040000000000100000000 000000616C000800000000E401000070010000040000002300 00000D00000000000000000000009001000000000000030201 12540069006D006500730020004E0065007700200052006F00 6D0061006E0000007800740042000000010000000000000002 0000000100000002000000A4040000540069006D0065007300 20004E0065007700200052006F006D0061006E000000780074 004200000013000000A2040000530500000200000002000000 1300000014000000A304000052050000020000000200000014 00000015000000A40400005105000002000000000000001500 0000FFFFFF7F0000000008000000020000005300740061006E 006400610072006400000000000200000000000000AE000000 FFFFFF7F00000000000000001A020000FFFFFF7F0000000000 09FFA2FF000000000061006C00740069007300630068000000 00000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000064760008 00000000000000001EFF1F20230000001C0000000700000003 000000010000000D0000005100000090010000000000006000 0000600000002000FCFF1F0020000000001700000000400024 0000080000DC08000035030000FF2A00E03900000024000000 004100750074006F006C006900730074004300610063006800 6500540069006D00650000004000000010CC9B3FD007CE0173 00000022000000004100750074006F006C0069007300740043 0061006300680065004B006500790000001F00000020000000 2000500072006F006700720061006D006D0065002F00440061 0074006500690065006E002000640075007200630068007300 75006300680065006E00300000000000000000000000000074 1A595E96DFD3488D671733BCEE28BA671B730433D90A4590E6 4ACD2E9408FE2A0000001300EFBE0000002000000000000000 0000000000000000000000000000000000010000005728AF04 00007F04811914105504200000000020000000000000000000 00000000000000000000000000000003010000390000003153 505330F125B7EF471A10A5F102608C9EEBAC1D0000000A0000 00001F0000000600000073006F0075006E0064000000000000 00CE0300003153505340E83E1E2BBC6C4782372ACD1A839B22 950300000200000000420000001E000000700072006F007000 3400320039003400390036003700320039003500000000005D 03000059030000550300003153505305D5CDD59C2E1B109397 08002B2CF9AE2100000010000000004B00650079003A005000 49004400000013000000050000006102000014000000004300 6F006E0064006900740069006F006E000000420000001E0000 00700072006F00700034003200390034003900360037003200 390035000000000015020000895CF152175AE148BBCD46A3F8 9C7CC2010000007B085495B6CEAB4599FF50E8428E860D669B 4BC63DE5564CB9AEFEDE4EE95DB10100000000000000000000 004902000000000000DC4C2B40D007CE0101000000895CF152 175AE148BBCD46A3F89C7CC2010000007B085495B6CEAB4599 FF50E8428E860D669B4BC63DE5564CB9AEFEDE4EE95DB10100 000000000000000000004902000000000000DC4C2B40D007CE 0101000000895CF152175AE148BBCD46A3F89C7CC201000000 7B085495B6CEAB4599FF50E8428E860D669B4BC63DE5564CB9 AEFEDE4EE95DB1000000000600000073006F0075006E006400 06000000640065002D00440045000000000000000000DC4C2B 40D007CE010000000000000000000000000000000000000000 00000000000000001F000600000073006F0075006E00640000 00000006000000640065002D00440045000000020000000001 0000000600000073006F0075006E0064004400000040E83E1E 2BBC6C4782372ACD1A839B220C0000000D0000001F00060000 0073006F0075006E0064000000000006000000640065002D00 4400450000000200000000010000000600000073006F007500 6E0064000400000040E83E1E2BBC6C4782372ACD1A839B220C 0000000D0000001F000600000073006F0075006E0064000000 000006000000640065002D0044004500000002000000000100 00000600000073006F0075006E006400040000000000007500 000014000000004B00650079003A0046004D00540049004400 0000080000004E0000007B0031004500330045004500380034 0030002D0042004300320042002D0034003700360043002D00 38003200330037002D00320041004300440031004100380033 0039004200320032007D0000000000270000000A000000004E 0061006D0065000000080000000C00000073006F0075006E00 640000001B0000000A00000000540079007000650000001300 00000700000000000000000000000000001D00000008000000 001F0000000600000073006F0075006E006400000000000000 4A00000031535053A66A63283D95D211B5D600C04FD918D011 000000190000000013000000040000301D0000000B00000000 1F0000000600000053007400610063006B0000000000000000 00000000002A0000001900EFBECBB487EFCEF2854786584CA6 C63E38C6000000000000000000000000000000008504E10500 00DB0581191410B10520000000000000000000000000000000 00000000000000000000000000000001000075010000315350 5340E83E1E2BBC6C4782372ACD1A839B221100000014000000 0003000000010000000D000000030000000001000000750000 0011000000001F000000310000007B00320035003200350036 004300320034002D0033004200370035002D00340039004200 33002D0041003400330033002D003400420042003200460038 003800360035003800390036007D002E004D00650072006700 6500200041006E007900000000000D0000000C000000000100 0000B900000008000000001F000000540000003A003A007B00 320036004500450030003600360038002D0041003000300041 002D0034003400440037002D0039003300370031002D004200 450042003000360034004300390038003600380033007D005C 0030005C003A003A007B004600320044004400460043003800 32002D0038004600310032002D0034004300440044002D0042 003700440043002D0044003400460045003100340032003500 41004100340044007D000000000000009402000031535053A6 6A63283D95D211B5D600C04FD918D0F5010000200000000011 100000E10100002C001F8070A47BED548E5E46825C99712043 E01C180000001C00EFBE020073006F0075006E006400000014 00B3010000AD01338B01237F01240000000000000000000000 00000000000000000000000000000000000000000000000100 00390000003153505330F125B7EF471A10A5F102608C9EEBAC 1D0000000A000000001F0000000600000053006F0075006E00 64000000000000006D00000031535053859E8E9C3034B44891 34A2274B46129E510000000200000000111000004000000014 001F706806EE260AA0D7449371BEB064C986830C0001008421 DE39000000001E0071800000000000000000000082FCDDF212 8FDD4CB7DCD4FE1425AA4D000000000000D500000031535053 5B3075B95F546F4C90011E5A4EF928A9B90000000200000000 1F000000530000004B006F006E006600690067007500720069 006500720065006E0020005300690065002000640061007300 200041007500640069006F00670065007200E400740020006F 006400650072002000E4006E006400650072006E0020005300 690065002000640061007300200053006F0075006E00640073 006300680065006D00610020006600FC007200200064006500 6E00200043006F006D00700075007400650072002E00000000 00000000000000000000000000000000110000001900000000 13000000040000000D0000000B000000000100000065000000 18000000001F000000290000003A003A007B00460032004400 440046004300380032002D0038004600310032002D00340043 00440044002D0042003700440043002D004400340046004500 310034003200350041004100340044007D0000000000000000 00DB000000315350533D3BD14B8BE6EC4489EE7611789D4070 7500000069000000001F000000310000007B00310036003800 350044003400410042002D0041003500310042002D00340041 00460031002D0041003400450035002D004300450045003800 370030003000320034003300310044007D002E004D00650072 0067006500200041006E007900000000002D00000064000000 001F0000000E00000063006F006E00740072006F006C002000 700061006E0065006C0000001D00000066000000001F000000 0600000073006F0075006E0064000000000000004600000031 53505330F125B7EF471A10A5F102608C9EEBAC0D0000000E00 000000010000001D0000000A000000001F0000000600000053 006F0075006E0064000000000000002D00000031535053901C 6949177E1A10A91C08002B2ECDA91100000003000000000300 000000000000000000002D00000031535053C0E85BCF6C23D3 4ABACECD608A2748D71100000064000000000B000000FFFF00 00000000002900000031535053B1166D44AD8D7048A748402E A43D788C0D0000006400000000010000000000000000000000 0000000000000000
                      Shortcut: C:\Users\Philipp\Desktop\Ph\Verknüpfungen\Windows Fax and Scan.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\Desktop\Ph\standart programms\Google Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
                      Shortcut: C:\Users\Philipp\Desktop\Ph\Neuer Ordner\chrome - Verknüpfung.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
                      Shortcut: C:\Users\Philipp\Desktop\Arda\Character Sheet_Olaf.lnk → C:\Users\Philipp\AppData\Roaming\Skype\My Skype Received Files\Character Sheet_Olaf.pdf ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Spotify.lnk → C:\Users\Philipp\AppData\Roaming\Spotify\Spotify.e xe (Spotify Ltd)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\WinRAR\Console RAR manual.lnk → C:\Program Files\WinRAR\Rar.txt ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\WinRAR\What is new in the latest version.lnk → C:\Program Files\WinRAR\WhatsNew.txt ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\WinRAR\WinRAR help.lnk → C:\Program Files\WinRAR\WinRAR.chm ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\WinRAR\WinRAR.lnk → C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Ubisoft\Uplay\Uninstall.lnk → F:\Program Files (x86)\Ubisoft Game Launcher\Uninstall.exe (Ubisoft)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Ubisoft\Uplay\Uplay.lnk → F:\Program Files (x86)\Ubisoft Game Launcher\Uplay.exe (Ubisoft)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Steam\Steam.lnk → C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\My Lockbox\Homepage…lnk → H:\Program Files\My Lockbox\Homepage.url ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\My Lockbox\My Lockbox Help.lnk → H:\Program Files\My Lockbox\mylbx.chm ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Maintenance\Help.lnk → C:\Windows\System32\shell32.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Games\1503 AD The New World™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 0000004746534987D057178E059E4594E641227DFF0DFA0000 0000000000000000170031003500300033002000410044003A 00200054006800650020004E0065007700200057006F007200 6C006400222128000000090000A01C00000031535053E28A58 46BC4C3843BBFC139326986DCE000000000000000000000000
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Games\Battlefield 1942™ .lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 00000047465349D458E2CE1166614691F00F304BBEE0C90000 0000000000000000120042006100740074006C006500660069 0065006C006400200031003900340032002221200028000000 090000A01C00000031535053E28A5846BC4C3843BBFC139326 986DCE000000000000000000000000
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Games\Grand Theft Auto San Andreas™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 00000047465349C0B076C0CDDA4248BB85C50DE47A071E0000 00000000000000001E004700720061006E0064002000540068 0065006600740020004100750074006F003A00200053006100 6E00200041006E006400720065006100730022212800000009 0000A01C00000031535053E28A5846BC4C3843BBFC13932698 6DCE000000000000000000000000
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Games\Oblivion The Elder Scrolls IV™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 00000047465349BD634B5F1973D94EAAFB62C16646AD580000 00000000000000001F004F0062006C006900760069006F006E 003A002000540068006500200045006C006400650072002000 5300630072006F006C006C0073002000490056002221280000 00090000A01C00000031535053E28A5846BC4C3843BBFC1393 26986DCE000000000000000000000000
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Games\Rome - Total War™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 000000474653490643B9EAE6852248B5EC999D05A05E9B0000 0000000000000000110052006F006D00650020002D00200054 006F00740061006C0020005700610072002221280000000900 00A01C00000031535053E28A5846BC4C3843BBFC139326986D CE000000000000000000000000
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Games\Stronghold 2™.lnk → L ᐁ À 䘀 6耟迟麨䡰놃낖︬刍 䙇䥓及虦⴨䚏ﶖ㾎℠
                      Stronghold 2™( ꀀ 匱卐諢䙘䲼䌸ﲻ錓頦칭
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Games\SWAT 4 - The Stetchkov Syndicate™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 000000474653490196D6922CCFF74CBC4123E66F9779EE0000 0000000000000000210053005700410054002000340020002D 00200054006800650020005300740065007400630068006B00 6F0076002000530079006E0064006900630061007400650022 2128000000090000A01C00000031535053E28A5846BC4C3843 BBFC139326986DCE000000000000000000000000
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Games\SWAT 4™.lnk → 0x4C0000000114020000000000C00000000000004685000000 00000000000000000000000000000000000000000000000000 00000000000000000000000100000000000000000000000000 0000360014001F80DF8F22EDA89E704883B196B02CFE0D5220 00000047465349AE3F635601EA9946BB17B9FB07638BB60000 00000000000000000700530057004100540020003400222128 000000090000A01C00000031535053E28A5846BC4C3843BBFC 139326986DCE000000000000000000000000
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Dropbox\Uninstall Dropbox.lnk → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb oxUninstaller.exe (Dropbox, Inc.)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Notepad.lnk → C:\Windows\System32\notepad.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Run.lnk → C:\Windows\System32\shell32.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\System Tools\computer.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\System Tools\Control Panel.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk → C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk → C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Accessibility\Magnify.ln k → C:\Windows\System32\Magnify.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Accessibility\Narrator.l nk → C:\Windows\System32\Narrator.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk → C:\Windows\System32\osk.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \SendTo\Bluetooth-Dateiübertragung.LNK → C:\Windows\System32\fsquirt.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \SendTo\Dropbox.lnk → C:\Users\Philipp\Dropbox ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Network Shortcuts\Tauschen (192.168.178.3)\target.lnk → \192.168.178.3\Tauschen
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Network Shortcuts\Medien\target.lnk → \192.168.178.3\Medien
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Office\ Zuletzt verwendet\DiDi.LNK → H:\DiDi_DVD\DiDi.mde ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Google Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Launch Internet Explorer Browser.lnk → C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Shows Desktop.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Window Switcher.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\TaskBar\Battle.net.lnk → C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe (Blizzard Entertainment)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome (2).lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Word 2010.lnk → C:\Windows\Installer{90140000-003D-0000-0000-0000000FF1CE}\wordicon.exe ()
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\TaskBar\Razer Cortex.lnk → C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe (Razer Inc.)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\TaskBar\Spotify.lnk → C:\Users\Philipp\AppData\Roaming\Spotify\Spotify.e xe (Spotify Ltd)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\TaskBar\Steam.lnk → C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinne d.lnk → 0x4C0000000114020000000000C000000000000046C1000000 00000000000000000000000000000000000000000000000000 0000000000000095FFFFFF0100000000000000000000000000 0000160014001F80F1A15925D721D411BDAF00C04F60B9F000 000C00480065006C007000500061006E0065002E0065007800 65008D000000090000A01C00000031535053E28A5846BC4C38 43BBFC139326986DCE00000000650000003153505355284C9F 799F394BA8D0E1D42DE1D5F34900000005000000001F000000 1B0000004D006900630072006F0073006F00660074002E0057 0069006E0064006F00770073002E00480065006C0070007000 61006E00650000000000000000000000000000000000
                      Shortcut: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinne d.lnk → C:\Windows\System32\control.exe (Microsoft Corporation)
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{C076B0C0-DACD-4842-BB85-C50DE47A071E}\PlayTasks\0\Spielen.lnk → H:\Program Files (x86)\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe ()
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{9FAED6B5-87ED-475C-ABF3-9545F85B5940}\PlayTasks\0\Spielen.lnk → H:\Program Files (x86)\Bethesda Softworks\Oblivion\Oblivion.exe (Bethesda Softworks)
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{6C8CA64D-9551-4E66-8ADF-B22E4576EAF7}\PlayTasks\0\Spielen.lnk → H:\Program Files (x86)\Origin Games\Battlefield 1942\BF1942.exe ()
                      Shortcut: C:\Users\Philipp\AppData\Local\Microsoft\Windows\G ameExplorer{08A0E7BB-20AD-4932-974D-5A8FACA1D755}\PlayTasks\0\Spielen.lnk → H:\Program Files (x86)\Firefly Studios\Stronghold 2\Stronghold2.exe (Firefly Studios)
                      Shortcut: C:\Users\Public\Desktop\CCleaner.lnk → C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
                      Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
                      Shortcut: C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk → C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (TeamSpeak Systems GmbH)
                      Shortcut: C:\Users\Public\Desktop\Zemana AntiMalware.lnk → C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)

                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DefaultPrograms
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk → C:\Windows\System32\wuapp.exe (Microsoft Corporation) → startmenu
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk → C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) → /showgadgets
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk → C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) → /prefetch:1
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\Configure Decoder.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → xvid.ax,Configure
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\Configure Encoder.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → xvidvfw.dll,Configure
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\Advanced\xvid_encraw.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation) → /k ““F:\Program Files (x86)\xvid_encraw.exe”” -h
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk → F:\Program Files (x86)\VLC\vlc.exe (VideoLAN) → --reset-config --reset-plugins-cache vlc://quit
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk → F:\Program Files (x86)\VLC\vlc.exe (VideoLAN) → -Iskins
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.BackupAndRestore
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi\Uninstall.lnk → C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) → /i {91B5DF26-717A-4A5F-AB10-CD450FAD428C} REMOVE=ALL
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk → C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) → --new_document
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk → C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) → --new_spreadsheet
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk → C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) → --new_presentation
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\ControlCenter3.lnk → C:\Program Files (x86)\Brother\ControlCenter3\BrCtrCen.exe (Brother Industries, Ltd.) → /Model=MFC-9320CW LAN#2
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Deinstallieren.lnk → C:\Program Files (x86)\InstallShield Installation Information{A1BBEE16-49B1-42F2-95B8-54C8C6A1C0C3}\setup.exe (Macrovision Corporation) → -runfromtemp -l0x0007 UNINSTALL Reg=BCL,Brother MFC-9320CW,LAN#2
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Installationsprüfung.lnk → C:\Program Files (x86)\Brother\Brmfl08j\Brinstck.exe (Brother Industries, Ltd.) → MFC-9320CW LAN#2
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Online-Registrierung.lnk → C:\Program Files (x86)\Brother\Brmfl08j\Brolink\Brolink0.exe (Brother Industories, Ltd.) → OLR_URL /mMFC-9320CW
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Remote Setup.lnk → C:\Program Files (x86)\Brother\Brmfl08j\brmfrmss.exe (Brother Industries Ltd.) → NET “MFC-9320CW LAN#2”
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Scanner-Einstellungen\Scanner und Kameras.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ScannersAndCameras
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\PC-FAX-Empfang\Empfangen.lnk → C:\Program Files (x86)\Brother\Brmfl08j\FAXRX.exe (Brother Industries Ltd.) → -Net “MFC-9320CW LAN#2”
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\PC-Fax senden\PC-FAX-Adressbuch.lnk → C:\Program Files (x86)\Brother\Brmfl08j\AddrBook.exe (Brother Industries, Ltd.) → PCFAX TOP
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\PC-Fax senden\PC-FAX-Einstellungen.lnk → C:\Program Files (x86)\Brother\Brmfl08j\PCfxSet.exe (Brother Industries, Ltd.) → PCFAX
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\ControlCenter3.lnk → C:\Program Files (x86)\Brother\ControlCenter3\BrCtrCen.exe (Brother Industries, Ltd.) → /Model=MFC-9320CW LAN
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Deinstallieren.lnk → C:\Program Files (x86)\InstallShield Installation Information{A1BBEE16-49B1-42F2-95B8-54C8C6A1C0C3}\setup.exe (Macrovision Corporation) → -runfromtemp -l0x0007 UNINSTALL Reg=BCL,Brother MFC-9320CW,LAN
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Installationsprüfung.lnk → C:\Program Files (x86)\Brother\Brmfl08j\Brinstck.exe (Brother Industries, Ltd.) → MFC-9320CW LAN
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Online-Registrierung.lnk → C:\Program Files (x86)\Brother\Brmfl08j\Brolink\Brolink0.exe (Brother Industories, Ltd.) → OLR_URL /mMFC-9320CW
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Remote Setup.lnk → C:\Program Files (x86)\Brother\Brmfl08j\brmfrmss.exe (Brother Industries Ltd.) → NET “MFC-9320CW LAN”
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Scanner-Einstellungen\Scanner und Kameras.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ScannersAndCameras
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\PC-FAX-Empfang\Empfangen.lnk → C:\Program Files (x86)\Brother\Brmfl08j\FAXRX.exe (Brother Industries Ltd.) → -Net “MFC-9320CW LAN”
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\PC-Fax senden\PC-FAX-Adressbuch.lnk → C:\Program Files (x86)\Brother\Brmfl08j\AddrBook.exe (Brother Industries, Ltd.) → PCFAX TOP
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\PC-Fax senden\PC-FAX-Einstellungen.lnk → C:\Program Files (x86)\Brother\Brmfl08j\PCfxSet.exe (Brother Industries, Ltd.) → PCFAX
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks\Oblivion\Oblivion deinstallieren.lnk → C:\Program Files (x86)\InstallShield Installation Information{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe (Macrovision Corporation) → /M{35CB6715-41F8-4F99-8881-6FC75BF054B0}
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk → C:\Windows\System32\compmgmt.msc () → /s
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk → C:\Windows\System32\eventvwr.msc () → /s
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk → C:\Windows\System32\perfmon.msc () → /s
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk → C:\Windows\System32\taskschd.msc () → /s
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation) → -NoExit -ImportSystemModules
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk → C:\Windows\System32\mblctr.exe (Microsoft Corporation) → /open
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCent er LaunchedBy_StartMenuShortcut
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk → C:\Windows\System32\perfmon.exe (Microsoft Corporation) → /res
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk → C:\Windows\System32\taskschd.msc () → /s
                      ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk → C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) → -SpeechUX
                      ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.EaseOfAccessCenter
                      ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows \SendTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
                      ShortcutWithArgument: C:\Users\Philipp\Desktop\Ph\standart programms\Google Docs.lnk → C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) → --new_document
                      ShortcutWithArgument: C:\Users\Philipp\Desktop\Ph\standart programms\Google Sheets.lnk → C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) → --new_spreadsheet
                      ShortcutWithArgument: C:\Users\Philipp\Desktop\Ph\standart programms\Google Slides.lnk → C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) → --new_presentation
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Word\ke nks305747274181591639\kenks.docx.lnk → C:\Users\Philipp\Desktop\kenks.docx () → 0
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\My Lockbox\My Lockbox Control Panel.lnk → H:\Program Files\My Lockbox\mylbx.exe (FSPro Labs) → /cp
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\My Lockbox\My Lockbox.lnk → H:\Program Files\My Lockbox\mylbx.exe (FSPro Labs) → /f
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Dropbox\Dropbox.lnk → C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropb ox.exe (Dropbox, Inc.) → /home
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.EaseOfAccessCenter
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \SendTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \SendTo\Skype.lnk → C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) → /sendto:
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Microsoft Outlook.lnk → C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE (Microsoft Corporation) → /recycle
                      ShortcutWithArgument: C:\Users\Philipp\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\User Pinned\TaskBar\My Lockbox.lnk → H:\Program Files\My Lockbox\mylbx.exe (FSPro Labs) → /f

                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XviD\Xvid Homepage.url → URL: hxxp://www.xvid.org
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap\WinPcap Web Site.url → URL: hxxp://www.winpcap.org/
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam Support Center.url → URL: hxxp://support.steampowered.com/
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2\Guild Wars 2 Support Webseite.url → URL: hxxp://support.guildwars2.com/
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2\Guild Wars 2 Webseite.url → URL: hxxp://www.guildwars2.com/
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url → URL: hxxp://www.piriform.com/ccleaner
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN#2\Online-Hilfe und FAQs.url → URL: hxxp://solutions.brother.com/cgi-bin/solutions.cgi?MDL=mfc233&LNG=de&SRC=FAQ
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-9320CW LAN\Online-Hilfe und FAQs.url → URL: hxxp://solutions.brother.com/cgi-bin/solutions.cgi?MDL=mfc233&LNG=de&SRC=FAQ
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks\Oblivion\ElderScrolls.com.url → URL: hxxp://www.elderscrolls.com
                      InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks\Oblivion\Oblivion registrieren.url → URL: hxxp://www.elderscrolls.com/register/
                      InternetURL: C:\Users\Philipp\Favorites\Windows Live\Windows Live Gallery.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=70742
                      InternetURL: C:\Users\Philipp\Favorites\Windows Live\Windows Live Ideas.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72700
                      InternetURL: C:\Users\Philipp\Favorites\Windows Live\Windows Live Mail.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72681
                      InternetURL: C:\Users\Philipp\Favorites\Windows Live\Windows Live Spaces.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72682
                      InternetURL: C:\Users\Philipp\Favorites\MSN-Websites\MSN Auto.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72680
                      InternetURL: C:\Users\Philipp\Favorites\MSN-Websites\MSN Fernsehen.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72659
                      InternetURL: C:\Users\Philipp\Favorites\MSN-Websites\MSN Money.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72640
                      InternetURL: C:\Users\Philipp\Favorites\MSN-Websites\MSN Nachrichten.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72636
                      InternetURL: C:\Users\Philipp\Favorites\MSN-Websites\MSN Sport.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72635
                      InternetURL: C:\Users\Philipp\Favorites\MSN-Websites\MSN.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72630
                      InternetURL: C:\Users\Philipp\Favorites\Microsoft-Websites\IE-Site auf Microsoft.com.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72186
                      InternetURL: C:\Users\Philipp\Favorites\Microsoft-Websites\Microsoft Deutschland GmbH.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72520
                      InternetURL: C:\Users\Philipp\Favorites\Microsoft-Websites\Microsoft Store.url → URL: hxxp://go.microsoft.com/fwlink/?linkid=140813
                      InternetURL: C:\Users\Philipp\Favorites\Microsoft-Websites\Microsoft Windows - Start.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72629
                      InternetURL: C:\Users\Philipp\Favorites\Microsoft-Websites\Microsoft zu Hause.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72406
                      InternetURL: C:\Users\Philipp\Favorites\Microsoft-Websites\Microsoft.com durchsuchen.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=72893
                      InternetURL: C:\Users\Philipp\Favorites\Microsoft-Websites\Site für IE Add-Ons.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=50893
                      InternetURL: C:\Users\Philipp\Favorites\Links\Vorgeschlagene Sites (2).url → URL: hxxps://ieonline.microsoft.com/#ieslice
                      InternetURL: C:\Users\Philipp\Favorites\Links\Vorgeschlagene Sites.url →
                      InternetURL: C:\Users\Philipp\Favorites\Links\Web Slice-Katalog.url → URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315
                      InternetURL: C:\Users\Philipp\Desktop\Europa Universalis IV.url → URL: steam://rungameid/236850
                      InternetURL: C:\Users\Philipp\Desktop\Golf With Your Friends.url → URL: steam://rungameid/431240
                      InternetURL: C:\Users\Philipp\Desktop\Tabletop Simulator.url → URL: steam://rungameid/286160
                      InternetURL: C:\Users\Philipp\Desktop\The Binding of Isaac Rebirth.url → URL: steam://rungameid/250900
                      InternetURL: C:\Users\Philipp\Desktop\Arda\The Binding of Isaac Rebirth.url → URL: steam://rungameid/250900
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Steam\Europa Universalis IV.url → URL: steam://rungameid/236850
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Steam\Golf With Your Friends.url → URL: steam://rungameid/431240
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Steam\Tabletop Simulator.url → URL: steam://rungameid/286160
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Steam\The Binding of Isaac Rebirth.url → URL: steam://rungameid/250900
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Igor Kulman\AutoSensitivity online support.url → BASEURL: hxxp://autosensitivity.codeplex.com/documentation URL: hxxp://autosensitivity.codeplex.com/documentation
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\GameSpy Arcade\GameSpy Arcade Help.url → BASEURL: hxxp://www.gamespyarcade.com/support/ URL: hxxp://www.gamespyarcade.com/support/
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\GameSpy Arcade\GameSpy Arcade Website.url → BASEURL: hxxp://www.gamespyarcade.com/ URL: hxxp://www.gamespyarcade.com/
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\GameSpy Arcade\GameSpy.com Gaming’s Homepage.url → BASEURL: hxxp://www.gamespy.com/ URL: hxxp://www.gamespy.com/
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\GameSpy Arcade\Register GameSpy Arcade.url → BASEURL: hxxp://www.gamespyarcade.com/register/ URL: hxxp://www.gamespyarcade.com/register/
                      InternetURL: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Dropbox\Dropbox Website.URL → URL: hxxp://www.dropbox.com
                      InternetURL: C:\Users\Philipp\AppData\Roaming.minecraft\Read Me!.url → URL: hxxp://welcome.teamextrememc.com

                      ==================== End of Shortcut.txt =============================

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #86
                        There is no malware on your machine, what issues remain?



                        Lets clean up all the old drivers related to your USB devices.

                        [ul]
                        [li]Remove All usb connected items from the computer, only leave the mouse and keyboard installed. [/li][li]Download drivecleanup.zip to your desktop.[/li][li]CLICK HERE to determine whether you’re running 32-bit or 64-bit for Windows.[/li][li]Once the determination has been made, open either the 32-bit or 64-bit folder.[/li][li]Right Click the .exe on the inside of the folder, and Run as Administrator. [/li][li]A command prompt window will open, telling you what has been removed upon completion.[/li][li]Reboot your machine.[/li][/ul]

                        Download your new fixlist click here.

                        We will do one last sweep to clean up any remaining trash on your system…

                        Zoek Scan

                        Disable your antivirus prior to this scan.

                        Download Zoek
                        Save the file to your desktop.
                        Right click Zoek.exe and run as administrator. (Xp Users double click)
                        Copy the items in red below, and paste them into Zoek.

                        createsrpoint;
                        emptyfolderscheck;delete
                        emptyclsid;
                        emptyalltemp;
                        ipconfig /flushdns;b
                        ResetHosts;
                        autoclean;


                        Now hit the run script button.
                        The log will appear after a reboot, also you can find it on the C: drive.
                        Post the log in your next reply.

                        Comment

                        • siq
                          PCHF Member
                          • Jan 2017
                          • 49

                          #87

                          Zoek.exe v5.0.0.1 Updated 27-09-2015
                          [/quote]


                          Tool run by Philipp on 17.02.2017 at 7:31:39,08.
                          Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
                          Running in: Normal Mode No Internet Access Detected
                          Launched: C:\Users\Philipp\Downloads\zoek.exe [Scan all users] [Script inserted]

                          ==== System Restore Info ======================

                          17.02.2017 07:37:35 Zoek.exe System Restore Point Created Successfully.

                          ==== Reset Hosts File ======================
                          [HEADING=1]Copyright (c) 1993-2006 Microsoft Corp.[/HEADING]
                          [HEADING=1]This is a sample HOSTS file used by Microsoft TCP/IP for Windows.[/HEADING]
                          [HEADING=1]This file contains the mappings of IP addresses to host names. Each[/HEADING]
                          [HEADING=1]entry should be kept on an individual line. The IP address should[/HEADING]
                          [HEADING=1]be placed in the first column followed by the corresponding host name.[/HEADING]
                          [HEADING=1]The IP address and the host name should be separated by at least one[/HEADING]
                          [HEADING=1]space.[/HEADING]
                          [HEADING=1]Additionally, comments (such as these) may be inserted on individual[/HEADING]
                          [HEADING=1]lines or following the machine name denoted by a ‘#’ symbol.[/HEADING]
                          [HEADING=1]For example:[/HEADING]
                          [HEADING=1]102.54.94.97 rhino.acme.com # source server[/HEADING]
                          [HEADING=1]38.25.63.10 x.acme.com # x client host[/HEADING]
                          [HEADING=1]localhost name resolution is handled within DNS itself.[/HEADING]
                          127.0.0.1 localhost
                          ::1 localhost

                          ==== Empty Folders Check ======================

                          C:\PROGRA~2\AGEIA Technologies deleted successfully
                          C:\PROGRA~3\Freemake deleted successfully
                          C:\PROGRA~3\Malwarebytes’ Anti-Malware (portable) deleted successfully
                          C:\Users\Philipp\AppData\Roaming\IrfanView deleted successfully
                          C:\Users\Philipp\AppData\Local\CrashDumps deleted successfully
                          C:\Users\Philipp\AppData\Local\LibreCAD deleted successfully
                          C:\Users\Philipp\AppData\Local\Skype deleted successfully

                          ==== Deleting CLSID Registry Keys ======================

                          ==== Deleting CLSID Registry Values ======================

                          HKEY_USERS.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} deleted successfully

                          ==== Deleting Services ======================

                          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\TrustedInstaller deleted successfully
                          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\T rustedInstaller deleted successfully

                          ==== FireFox Fix ======================

                          ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\57p5pubn.default

                          prefs.js not found
                          user.js not found
                          ---- FireFox user.js and prefs.js backups ----

                          ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\q87ndktt.default

                          prefs.js not found
                          user.js not found
                          ---- FireFox user.js and prefs.js backups ----

                          ==== Batch Command(s) Run By Tool======================

                          ==== Deleting Files \ Folders ======================

                          C:\PROGRA~2\AGEIA Technologies not found
                          C:\PROGRA~3\Malwarebytes’ Anti-Malware (portable) not found
                          C:\Users\Philipp\AppData\Roaming\ProtectDisc deleted
                          C:\PROGRA~2\ProtectDisc Driver Installer deleted
                          C:\search.sqlite deleted
                          C:\Users\Philipp\AppData\Roaming\ProductData deleted
                          C:\Windows\sysWoW64\config\systemprofile\AppData\R oaming\Hotspot Shield deleted
                          C:\PROGRA~3\Package Cache deleted
                          C:\Users\Philipp\AppData\LocalLow\IObit Apps deleted
                          C:\Users\Philipp\AppData\LocalLow\Unity deleted
                          C:\Users\Philipp\AppData\LocalLow\ADSRemoval deleted
                          C:\Windows\sysWoW64\config\systemprofile\AppData\L ocalLow\IObit Apps deleted
                          C:\Windows\wininit.ini deleted
                          C:\Windows\Syswow64\Hotspot Shield deleted
                          C:\Windows\SysWow64\AI_RecycleBin deleted
                          C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\q87ndktt.default\jetpack deleted
                          “C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\ Profiles\57p5pubn.default\extensions\iobitapps@mybrowserbar.com” deleted

                          ==== Firefox Extensions Registry ======================

                          [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Fi refox\Extensions]
                          wrc@avast.com”=“C:\Program Files\AVAST Software\Avast\WebRep\FF” [07.08.2015 13:03]

                          ==== Firefox Extensions ======================

                          ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\57p5pubn.default
                          ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\q87ndktt.default
                          ==== Firefox Plugins ======================

                          Profilepath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\P rofiles\q87ndktt.default
                          9E602A9634AC3EFA8CD5BC4CD943416B - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_ 194.dll - Shockwave Flash

                          ==== Chromium Look ======================

                          HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensio ns
                          eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[07.04.2015 16:25]
                          gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[07.04.2015 16:25]

                          Theme Creator - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Anwendungsdaten\ Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Anwendungsdaten\ Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Anwendungsdaten\ Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Anwendungsdaten\ Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Anwendungsdaten\ Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Anwendungsdaten\ Google\Chrome\User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Theme Creator - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Google\Chrome\Us er Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Google\Chrome\Us er Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Google\Chrome\Us er Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Google\Chrome\Us er Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Google\Chrome\Us er Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Google\Chrome\Us er Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Chrome Media Router - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Anwendungsdaten\Google\Chrome\Us er Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
                          Theme Creator - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Chrome Media Router - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
                          Theme Creator - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Google\Chrome\User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Chrome Media Router - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Anwendungsdate n\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
                          Theme Creator - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Google\Chrome\ User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Google\Chrome\ User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Google\Chrome\ User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Google\Chrome\ User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Google\Chrome\ User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Google\Chrome\ User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Chrome Media Router - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Anwendungsdaten\Google\Chrome\ User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
                          Theme Creator - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Chrome Media Router - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
                          Theme Creator - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Google\Chrome\User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Chrome Media Router - Philipp\AppData\Local\Anwendungsdaten\Anwendungsda ten\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
                          Theme Creator - Philipp\AppData\Local\Anwendungsdaten\Google\Chrom e\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Anwendungsdaten\Google\Chrom e\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Anwendungsdaten\Google\Chrom e\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Anwendungsdaten\Google\Chrom e\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Anwendungsdaten\Google\Chrom e\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Anwendungsdaten\Google\Chrom e\User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Chrome Media Router - Philipp\AppData\Local\Anwendungsdaten\Google\Chrom e\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
                          Theme Creator - Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllg ombffc
                          Web of Trust - Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpb ikblnp
                          uBlock₀ - Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjb keiagm
                          Avast SafePrice - Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck
                          Avast Online Security - Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
                          Tab Cookies - Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\iahecghojagkcoehfhfknajofk okndjm
                          Chrome Media Router - Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm

                          ==== Set IE to Default ======================

                          Old Values:
                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          “Start Page”=" MSN "
                          “Search Bar”=" Google "
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          “Search Bar”=" Google "
                          [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\ Internet Explorer\Main]
                          “Search Bar”=" Google "

                          New Values:
                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          “Search Bar”=" Search - Microsoft Bing "
                          “Start Page”=" MSN "
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          “Search Bar”=" Search - Microsoft Bing "
                          [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\ Internet Explorer\Main]
                          “Search Bar”=" Search - Microsoft Bing "

                          ==== All HKCU SearchScopes ======================

                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
                          “DefaultScope”=“{0633EE93-D776-472f-A0FF-E1416B8B2E3A}”
                          {012E1000-F331-11DB-8314-0800200C9A66} Google Url=" Google {searchTerms}"
                          {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url=" Search - Microsoft Bing {searchTerms}&src=IE-SearchBox&FORM=IE11SR"
                          {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} Google Url=" Google {searchTerms}&sourceid=ie7&rls=com.microsoft:{lang uage}:{referrer:source}&ie={inputEncoding?}&oe={ou tputEncoding?}"

                          ==== Deleting Registry Keys ======================

                          HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZPNConnect deleted successfully

                          ==== Empty IE Cache ======================

                          C:\Windows\system32\config\systemprofile\AppData\L ocal\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Anwendungsdaten\Anwendung sdaten\Anwendungsdaten\Temporary Internet Files\Content.IE5 emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Anwendungsdaten\Anwendung sdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Anwendungsdaten\Anwendung sdaten\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Anwendungsdaten\Microsoft \Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Anwendungsdaten\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Microsoft\Windows\Tempora ry Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Microso ft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Tempora ry Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Microsoft\Windows\Tempo rary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Micro soft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Tempo rary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Microsoft\Windows\Tem porary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Mic rosoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Tem porary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Microsoft\Windows\T emporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Users\Philipp\AppData\Local\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Windows\sysWoW64\config\systemprofile\AppData\L ocal\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
                          C:\Windows\sysWOW64\config\systemprofile\AppData\L ocal\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

                          ==== Empty FireFox Cache ======================

                          No FireFox Cache found

                          ==== Empty Chrome Cache ======================

                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Anwendungsdaten\Anwendung sdaten\Anwendungsdaten\Google\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Anwendungsdaten\Anwendung sdaten\Google\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Anwendungsdaten\Google\Ch rome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Anwendungsdaten\Google\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendu ngsdaten\Google\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Anwendungsdaten\Google\ Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Anwendungsdaten\Google\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Anwen dungsdaten\Google\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Anwendungsdaten\Googl e\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Anwendungsdaten\Google\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Anw endungsdaten\Google\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Anwendungsdaten\Goo gle\Chrome\User Data\Default\Cache emptied successfully
                          C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

                          ==== Empty All Flash Cache ======================

                          Flash Cache Emptied Successfully

                          ==== Empty All Java Cache ======================

                          Java Cache cleared successfully

                          ==== C:\zoek_backup content ======================

                          C:\zoek_backup (files=57 folders=78 74412808 bytes)

                          ==== Empty Temp Folders ======================

                          C:\Users\Default\AppData\Local\Temp emptied successfully
                          C:\Users\Default User\AppData\Local\Temp emptied successfully
                          C:\Users\Philipp\AppData\Local\Temp will be emptied at reboot
                          C:\Windows\SysNative\config\systemprofile\AppData\ Local\TEMP emptied successfully
                          C:\Windows\serviceprofiles\networkservice\AppData\ Local\Temp emptied successfully
                          C:\Windows\serviceprofiles\Localservice\AppData\Lo cal\Temp emptied successfully
                          C:\Windows\Temp will be emptied at reboot

                          ==== After Reboot ======================

                          ==== Empty Temp Folders ======================

                          C:\Windows\Temp successfully emptied
                          C:\Users\Philipp\AppData\Local\Temp successfully emptied

                          ==== Empty Recycle Bin ======================

                          C:$RECYCLE.BIN successfully emptied

                          ==== Deleting Files / Folders ======================

                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Anwend ungsdaten\Anwendungsdaten\Anwendungsdaten\Anwendun gsdaten\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Anwend ungsdaten\Anwendungsdaten\Anwendungsdaten\Microsof t\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Anwend ungsdaten\Anwendungsdaten\Anwendungsdaten\Temporar y Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Anwend ungsdaten\Anwendungsdaten\Microsoft\Windows\Tempor ary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Anwend ungsdaten\Anwendungsdaten\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Anwend ungsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Anwend ungsdaten\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Micros oft\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Anwendungsdaten\Tempor ary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Microsoft\Windows\Temp orary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Anwendungsdaten\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Anwe ndungsdaten\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Micr osoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Anwendungsdaten\Temp orary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Microsoft\Windows\Te mporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Anwendungsdaten\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\An wendungsdaten\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\Mi crosoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Anwendungsdaten\Te mporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Microsoft\Windows\ Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Users\Philipp\AppData\Local\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Windows\sysWoW64\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted
                          “C:\Windows\sysWOW64\config\systemprofile\AppData\ Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not deleted

                          ==== EOF on 17.02.2017 at 14:01:24,69 ======================

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #88
                            There is no malware on your machine, what issues remain?
                            Would you now call this issue resolved?

                            Comment

                            • Malnutrition
                              PCHF Moderator
                              • Jul 2016
                              • 7041

                              #89
                              @siq What issues remain?

                              Comment

                              • Malnutrition
                                PCHF Moderator
                                • Jul 2016
                                • 7041

                                #90
                                @siq How about an update for us please.

                                Comment

                                Working...