Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 22.01.2016, 00:22   #1
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Hey,

ich habe schon des längeren das Problem, dass sich z.Bsp Google Chrome oder auch andere Anwendungen schließen mit der Meldung: " Programm xyz reagiert nicht mehr".

Des Weiteren ist mein Computer schlagartig sehr langsam geworden. Daraufhin habe ich heute morgen einmal einen Scan mit Malwarebyte vollzogen. Dieser meldete mir über 80 Funde, welche mein Virenprogramm (BitDefender) nie gefunden hatte. Ich habe Malwarebyte die Funde dann in Quarantäne verschieben lassen, was die Situation nur verschlimmert hat.

Seit dem Verschieben der Dateien, habe ich beim laden des Desktops (nach einem Neustart), immer fast eine Minute einen kompletten Blackscreen. Danach läd er nach und nach den Hintergrund, Applikationen etc...

Außerdem ist der Computer seit dem Verschieben der Dateien nochmals langsamer geworden. Ich muss im Moment gute 10-20s warten bis er ein Programm oder Ordner öffnet.


FRST
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-01-2016
durchgeführt von Basti (Administrator) auf BASTI-DESKTOP (21-01-2016 23:52:00)
Gestartet von C:\Users\Basti\Downloads
Geladene Profile: Basti (Verfügbare Profile: Basti & Zocken & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Dassault Systemes) C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Program Files (x86)\Droid4X\Droid4XService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(GGS) C:\Users\Basti\AppData\Local\THORN\Thorn.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(GGS) C:\Users\Basti\AppData\Local\THORN\ThornHelper.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Mixesoft Project) C:\Users\Basti\AppData\Local\Mixesoft\AppNHost\appnhost.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe
(Spotify Ltd) C:\Users\Basti\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\antispam32\bdwtxapps.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxcr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Echobit LLC) C:\Program Files\Echobit\Evolve\EvolveClient.exe
(Echobit LLC) C:\Program Files\Echobit\Evolve\EvoSvc.exe
(Echobit, LLC) C:\Program Files\Echobit\Evolve\Drivers\EvolveTracker_32.exe
(Echobit, LLC) C:\Program Files\Echobit\Evolve\Drivers\EvolveTracker_64.exe
(Echobit, LLC) C:\Program Files\Echobit\Evolve\EvolveUI.exe
(Echobit, LLC) C:\Program Files\Echobit\Evolve\EvolveUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\odscanui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-16] (NVIDIA Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe [1720488 2016-01-12] (Bitdefender)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-04-29] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-04-29] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-09-23] (Cisco Systems, Inc.)
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [appnhost] => C:\Users\Basti\AppData\Local\Mixesoft\AppNHost\appnhost.exe [453176 2014-08-08] (Mixesoft Project)
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [Bitdefender-Geldb�rse-Agent] => C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe [1423288 2016-01-12] (Bitdefender)
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [Spotify Web Helper] => C:\Users\Basti\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2346096 2015-12-21] (Spotify Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BdBkpFolder [2016-01-12] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk [2016-01-21]
ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

ProxyServer: [S-1-5-21-1745305398-2489788369-3521438674-1002] => localhost:8080
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{8A41A65B-D9F1-429C-8BC5-46D12DA767EE}: [DhcpNameServer] 192.168.178.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> DefaultScope {DF39FAF5-E2FF-4630-90A1-159FB1F73C0A} URL = hxxps://de.search.yahoo.com/search?fr=mcafee&type=C010DE91021D20141021&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://www.google.com/search?q={searchTerms}&rlz=1I7ADRA_deDE485
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {C6CE0053-87D1-4C2C-9DBF-738685826369} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=PF&o=15180&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=RX&apn_dtid=YYYYYYYYDE&apn_uid=8648a3b9-301b-40f6-b522-f94384361361&apn_sauid=6FAA0A15-3C93-40FB-B6E8-4D8CD5970E54
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {DF39FAF5-E2FF-4630-90A1-159FB1F73C0A} URL = hxxps://de.search.yahoo.com/search?fr=mcafee&type=C010DE91021D20141021&p={searchTerms}
BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2016\pmbxie.dll [2016-01-12] (Bitdefender)
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-01] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-01] (Oracle Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\pmbxie.dll [2016-01-12] (Bitdefender)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Winamp Toolbar Loader -> {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} -> C:\Program Files (x86)\Winamp Toolbar\winamptb.dll [2012-03-19] (AOL Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-11-01] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-10-29] (Perfect World Entertainment Inc)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-18] (Google Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-01] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2016\pmbxie.dll [2016-01-12] (Bitdefender)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.)
Toolbar: HKLM-x32 - Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll [2012-03-19] (AOL Inc.)
Toolbar: HKLM-x32 - Kein Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  Keine Datei
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\pmbxie.dll [2016-01-12] (Bitdefender)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-18] (Google Inc.)
Toolbar: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.)
Toolbar: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> Kein Name - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} -  Keine Datei
DPF: HKLM {BAD4FE2C-503B-45CC-88CD-4B0574057D11} hxxp://clients.futuremark.com/calico/systeminfodeploy/FMSI_v490.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157
FF SearchEngineOrder.1: Sichere Suche
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Sichere Suche
FF Homepage: www.google.de
FF Session Restore: -> ist aktiviert.
FF Keyword.URL: hxxps://de.search.yahoo.com/search?fr=mcafee&type=C110DE91021D20141021&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-20] ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll [2014-09-01] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-01] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-20] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] ()
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll [2014-09-01] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei]
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-10-29] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: @my.com/Games -> C:\Users\Basti\AppData\Local\MyComGames\NPMyComDetector.dll [2015-09-30] (My.com, Inc)
FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Basti\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-01] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdnu.dll [2009-07-07] (AOL LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdnupdater2.dll [2009-07-07] (AOL LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-12-09] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\searchplugins\anonymouseorg-anonym-surfen.xml [2015-11-16]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\searchplugins\McSiteAdvisor.xml [2015-11-17]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\duckduckgo-ssl-javascript-free.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\google-de-ssl.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\google-encrypted-no-personalization.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick---deutsch.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick-ssl-pictures---deutsch.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick-ssl-pictures---english.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-eng-ger.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-esp-ale.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-fra-all.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\metager2.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ssl-wikipedia-deutsch.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ssl-wikipedia-english.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\startpage-https---deutsch.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\startpage-https.xml [2013-06-25]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2015-10-29]
FF Extension: Amazon-Icon - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\amazon-icon@giga.de [2013-12-28] [ist nicht signiert]
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-06-08] [ist nicht signiert]
FF Extension: DownThemAll! - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-05-28]
FF Extension: Updated Ad Blocker for Firefox 11+ - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi [2015-05-29]
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-06-23] [ist nicht signiert]
FF Extension: HTTPS-Everywhere - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\https-everywhere-eff@eff.org [2015-08-28]
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff [2016-01-13]
FF Extension: Bing Search Engine - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\bingsearch.full@microsoft.com [2015-03-12] [ist nicht signiert]
FF Extension: Magic Actions for YouTube™ - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\jid0-UVAeBCfd34Kk5usS8A1CBiobvM8@jetpack.xpi [2015-07-30]
FF Extension: SSL Version Control - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\jid1-ZM3BerwS6FsQAg@jetpack.xpi [2015-05-27]
FF Extension: Adblock Plus - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-17]
FF Extension: Amazon-Icon - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\amazon-icon@giga.de [2013-12-28] [ist nicht signiert]
FF Extension: HTTPS-Everywhere - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\https-everywhere@eff.org [2013-07-12] [ist nicht signiert]
FF Extension: Spartipps von SparPilot.com - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\sparpilot@sparpilot.com [2013-12-28] [ist nicht signiert]
FF Extension: UnPlug - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\unplug@compunach.xpi [2013-05-15] [ist nicht signiert]
FF Extension: JonDoFox - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{437be45a-4114-11dd-b9ab-71d256d89593}.xpi [2013-06-28] [ist nicht signiert]
FF Extension: Cookie Monster - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{45d8ff86-d909-11db-9705-005056c00008} [2013-07-12] [ist nicht signiert]
FF Extension: NoScript - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-07-20] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-15] [ist nicht signiert]
FF Extension: ProfileSwitcher - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{fa8476cf-a98c-4e08-99b4-65a69cb4b7d4}.xpi [2013-06-25] [ist nicht signiert]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
FF HKLM\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext
FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext [2015-11-25] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-10] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF HKLM-x32\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext
FF HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome: 
=======
CHR Session Restore: Default -> ist aktiviert.
CHR Profile: C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-27]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2015-12-10]
CHR Extension: (Google Docs) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-29]
CHR Extension: (Google Drive) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (Google-Suche) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Bitdefender Wallet) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhhejlifdlcgcmogbggeomfodgklfaem [2015-12-13]
CHR Extension: (Google Tabellen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-27]
CHR Extension: (Google Docs Offline) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Click&Clean) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2015-11-02]
CHR Extension: (AdBlock) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-20]
CHR Extension: (Google Maps) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-11-27]
CHR Extension: (Amazon-Icon) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [2015-09-27]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-27]
CHR Extension: (YouTube Unblocker) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2015-12-07] [UpdateUrl: hxxp://www.unblocker.yt/addon/chrome/updates.xml] <==== ACHTUNG
CHR Extension: (Click&Clean App) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-11-02]
CHR Extension: (Google Mail) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-29]
CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Basti\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx [2013-12-28]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-10-29] (Perfect World Entertainment Inc)
R2 BBDemon; C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe [46592 2011-01-08] (Dassault Systemes) [Datei ist nicht signiert]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1145216 2015-05-26] ()
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 Droid4XService; C:\Program Files (x86)\Droid4X\Droid4XService.exe [261864 2015-06-03] () [Datei ist nicht signiert]
R3 EvoSvc; C:\Program Files\Echobit\Evolve\EvoSvc.exe [1583488 2016-01-10] (Echobit LLC)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-12-22] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7184440 2015-12-22] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-16] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-04-10] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-14] (Microsoft Corporation)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert]
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3806032 2015-10-13] (INCA Internet Co., Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-16] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-16] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-07] (Electronic Arts)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-30] ()
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [857288 2015-11-09] (Bitdefender)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5250280 2015-12-29] (SoftEther VPN Project at University of Tsukuba, Japan.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert]
R2 Thorn; C:\Users\Basti\AppData\Local\THORN\Thorn.exe [56824 2015-10-01] (GGS)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe [124488 2015-09-29] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe [1604080 2016-01-12] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1600512 2015-10-28] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [282000 2015-09-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [775424 2015-09-17] (BitDefender)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2011-11-03] (Broadcom Corporation.)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107080 2012-10-29] (BitDefender LLC)
R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [87912 2015-12-14] (BitDefender)
S3 cpuz135; kein ImagePath
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-06-08] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [21656 2016-01-10] (Echobit, LLC)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160032 2015-04-29] (BitDefender LLC)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-11-29] (Intel Corporation)
R0 ignis; C:\Windows\System32\DRIVERS\ignis.sys [271808 2015-10-22] (Bitdefender)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R1 LUMDriver; C:\Windows\system32\drivers\LUMDriver.sys [24848 2008-01-02] (IBM)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0024.sys [38432 2015-12-29] (SoftEther Corporation)
S3 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-12-16] (NVIDIA Corporation)
R2 trufos; C:\Windows\System32\DRIVERS\trufos.sys [477272 2015-06-02] (BitDefender S.R.L.)
R3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments)
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-01-21 23:52 - 2016-01-21 23:54 - 00044556 _____ C:\Users\Basti\Downloads\FRST.txt
2016-01-21 23:46 - 2016-01-21 23:52 - 00000000 ____D C:\FRST
2016-01-21 23:45 - 2016-01-21 23:46 - 02370560 _____ (Farbar) C:\Users\Basti\Downloads\FRST64.exe
2016-01-21 15:28 - 2016-01-21 15:28 - 02967888 _____ C:\Users\Basti\Desktop\Sebastian Schmitt.tif
2016-01-21 14:34 - 2016-01-21 14:34 - 00002243 _____ C:\Users\Public\Desktop\Blade & Soul.lnk
2016-01-21 14:20 - 2016-01-21 14:20 - 01611384 _____ (NCSOFT Corporation) C:\Users\Basti\Downloads\NC-LauncherSetup.exe
2016-01-21 12:15 - 2016-01-21 23:55 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-01-21 12:15 - 2016-01-21 13:14 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2016-01-21 12:15 - 2016-01-21 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2016-01-21 12:15 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-01-21 12:14 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-01-21 12:14 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-01-21 12:06 - 2016-01-21 12:15 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2016-01-21 12:06 - 2016-01-21 12:06 - 22908888 _____ (Malwarebytes ) C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024.exe
2016-01-21 12:06 - 2016-01-21 12:06 - 22908888 _____ (Malwarebytes ) C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024 (1).exe
2016-01-21 12:06 - 2016-01-21 12:06 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-01-20 11:02 - 2016-01-20 11:02 - 00006949 _____ C:\Users\Basti\Desktop\BnS.xml
2016-01-18 15:09 - 2016-01-18 15:10 - 00000000 ____D C:\Users\Basti\AppData\Local\CrashDumps
2016-01-18 10:42 - 2016-01-18 10:42 - 00038983 _____ C:\ComboFix.txt
2016-01-18 10:29 - 2016-01-21 14:11 - 00007668 _____ C:\bdlog.txt
2016-01-18 10:14 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2016-01-18 10:14 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2016-01-18 10:14 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2016-01-18 10:13 - 2016-01-18 10:42 - 00000000 ____D C:\Qoobox
2016-01-18 10:12 - 2016-01-18 10:40 - 00000000 ____D C:\Windows\erdnt
2016-01-18 10:12 - 2016-01-18 10:12 - 05649812 ____R (Swearware) C:\Users\Basti\Downloads\ComboFix.exe
2016-01-18 10:08 - 2016-01-18 10:08 - 00532480 _____ (Trend Micro Incorporated) C:\Users\Basti\Downloads\cwshredder.exe
2016-01-18 10:07 - 2016-01-18 10:07 - 00052461 _____ C:\Users\Basti\Downloads\delcwssk (2).zip
2016-01-18 10:06 - 2016-01-18 10:06 - 00052461 _____ C:\Users\Basti\Downloads\delcwssk (1).zip
2016-01-18 10:03 - 2016-01-18 10:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\HijackThis.exe
2016-01-18 09:58 - 2016-01-18 09:58 - 00052461 _____ C:\Users\Basti\Downloads\delcwssk.zip
2016-01-18 09:48 - 2016-01-18 09:48 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\HijackThis_2.0.5.exe
2016-01-18 09:48 - 2016-01-18 09:48 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\HijackThis_2.0.5 (2).exe
2016-01-18 09:39 - 2016-01-18 09:39 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\HijackThis_2.0.5 (1).exe
2016-01-18 09:39 - 2016-01-18 09:39 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\_HijackThis_2.0.5.exe
2016-01-18 09:38 - 2016-01-18 09:38 - 00544173 _____ C:\Users\Basti\Downloads\HijackThis_Logfileauswertung_-_2014-02-05_16.22.13.zip
2016-01-17 23:28 - 2015-12-16 18:34 - 00111520 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2016-01-17 23:23 - 2015-12-16 15:39 - 00103032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-01-17 23:22 - 2015-12-16 15:53 - 00523384 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2016-01-17 23:22 - 2015-12-16 15:53 - 00075056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 42977072 _____ C:\Windows\system32\nvcompiler.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 37609080 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 31061624 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 24895792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 21122456 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 20663816 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 17561432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 17156968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 16981976 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 12334200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2016-01-17 23:16 - 2015-12-16 18:34 - 03168376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 02755704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 01915696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436143.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436143.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00938104 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00872056 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00734512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00681592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00502080 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00469144 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00423264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00416376 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00388560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00370808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00205456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2016-01-17 23:16 - 2015-12-16 18:34 - 00175368 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00069416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00050472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-01-17 23:16 - 2015-12-16 18:34 - 00039240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2016-01-17 23:12 - 2016-01-17 23:13 - 336974040 _____ (NVIDIA Corporation) C:\Users\Basti\Downloads\361.43-desktop-win8-win7-winvista-64bit-international-whql.exe
2016-01-17 23:07 - 2016-01-17 23:07 - 00003146 _____ C:\Windows\System32\Tasks\{2D1288DA-1D43-479F-8B4B-36F07394063D}
2016-01-17 23:03 - 2016-01-17 23:04 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\jxpiinstall(2).exe
2016-01-17 02:00 - 2016-01-17 02:00 - 01250844 _____ C:\Users\Basti\Downloads\ProcessExplorer161.zip
2016-01-14 23:46 - 2016-01-14 23:53 - 38572508 _____ C:\Users\Basti\Desktop\intro.avi
2016-01-14 23:29 - 2016-01-14 23:34 - 00576953 _____ C:\Users\Basti\Downloads\56981f3794d73.mp4
2016-01-14 21:23 - 2016-01-21 13:12 - 00000882 _____ C:\Users\Basti\Desktop\iFree Skype Recorder.lnk
2016-01-14 21:23 - 2016-01-14 21:41 - 00000000 ____D C:\Users\Basti\Documents\iFree Skype Recorder
2016-01-14 21:23 - 2016-01-14 21:24 - 00000000 ____D C:\Users\Basti\AppData\Roaming\iFree
2016-01-14 21:23 - 2016-01-14 21:23 - 01058568 _____ C:\Users\Basti\Downloads\iFreeRecorder.exe
2016-01-14 21:23 - 2016-01-14 21:23 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iFree Skype Recorder
2016-01-14 21:23 - 2016-01-14 21:23 - 00000000 ____D C:\Program Files (x86)\iFree Skype Recorder
2016-01-13 17:26 - 2016-01-13 17:26 - 01504376 _____ (Skype Technologies S.A.) C:\Users\Basti\Downloads\SkypeSetup.exe
2016-01-13 16:55 - 2016-01-13 16:55 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\chromeinstall-8u66 (1).exe
2016-01-13 16:49 - 2015-11-01 15:59 - 00110176 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-64.dll
2016-01-13 16:49 - 2015-11-01 15:52 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-01-13 16:47 - 2016-01-13 16:47 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\chromeinstall-8u66.exe
2016-01-13 10:19 - 2015-12-12 19:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-01-13 10:19 - 2015-12-12 19:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-01-13 10:19 - 2015-12-12 19:02 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-01-13 10:19 - 2015-12-12 18:37 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-01-13 10:19 - 2015-12-12 18:36 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-01-13 10:19 - 2015-12-12 18:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-01-13 10:19 - 2015-12-12 18:10 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-01-13 10:19 - 2015-12-11 19:57 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-01-13 10:19 - 2015-12-08 22:54 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2016-01-13 10:19 - 2015-12-08 22:54 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 01325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2016-01-13 10:19 - 2015-12-08 22:54 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2016-01-13 10:19 - 2015-12-08 22:53 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2016-01-13 10:19 - 2015-12-08 22:53 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2016-01-13 10:19 - 2015-12-08 22:53 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll
2016-01-13 10:19 - 2015-12-08 22:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2016-01-13 10:19 - 2015-12-08 20:07 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll
2016-01-13 10:19 - 2015-12-08 20:06 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2016-01-13 10:19 - 2015-12-08 20:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-01-13 10:19 - 2015-12-08 20:04 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2016-01-13 10:19 - 2015-12-08 19:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2016-01-13 10:19 - 2015-12-08 19:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2016-01-13 10:19 - 2015-12-08 19:11 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
2016-01-13 10:19 - 2015-12-08 18:58 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-01-13 10:19 - 2015-11-17 02:11 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-01-13 10:19 - 2015-11-17 02:08 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-01-13 10:19 - 2015-11-17 02:08 - 00792064 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-01-13 10:19 - 2015-11-17 02:08 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-01-13 10:19 - 2015-11-17 02:08 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-01-13 10:19 - 2015-11-17 02:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-01-13 10:19 - 2015-11-16 21:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-01-13 10:19 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2016-01-13 10:19 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2016-01-13 10:19 - 2015-11-14 00:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
2016-01-13 10:19 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
2016-01-13 10:19 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
2016-01-13 10:19 - 2015-11-13 23:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe
2016-01-13 10:18 - 2015-12-30 20:08 - 05572544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-01-13 10:18 - 2015-12-30 20:08 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-01-13 10:18 - 2015-12-30 20:08 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-01-13 10:18 - 2015-12-30 20:05 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-01-13 10:18 - 2015-12-30 20:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-01-13 10:18 - 2015-12-30 19:59 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-01-13 10:18 - 2015-12-30 19:59 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-01-13 10:18 - 2015-12-30 19:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-01-13 10:18 - 2015-12-30 19:58 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-01-13 10:18 - 2015-12-30 19:58 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-01-13 10:18 - 2015-12-30 19:57 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-01-13 10:18 - 2015-12-30 19:57 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-01-13 10:18 - 2015-12-30 19:57 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-01-13 10:18 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-01-13 10:18 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-01-13 10:18 - 2015-12-30 19:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:47 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-01-13 10:18 - 2015-12-30 19:47 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-01-13 10:18 - 2015-12-30 19:44 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-01-13 10:18 - 2015-12-30 19:40 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-01-13 10:18 - 2015-12-30 19:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-01-13 10:18 - 2015-12-30 19:39 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-01-13 10:18 - 2015-12-30 19:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-01-13 10:18 - 2015-12-30 19:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-01-13 10:18 - 2015-12-30 19:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-01-13 10:18 - 2015-12-30 19:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-01-13 10:18 - 2015-12-30 19:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 18:57 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-01-13 10:18 - 2015-12-30 18:50 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-01-13 10:18 - 2015-12-30 18:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-01-13 10:18 - 2015-12-30 18:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-01-13 10:18 - 2015-12-30 18:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-01-13 10:18 - 2015-12-30 18:42 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-01-13 10:18 - 2015-12-30 18:42 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-01-13 10:18 - 2015-12-30 18:41 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-01-13 10:18 - 2015-12-30 18:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-01-13 10:18 - 2015-12-30 18:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-01-13 10:18 - 2015-12-30 18:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-01-13 10:18 - 2015-12-30 18:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-01-13 10:18 - 2015-12-30 18:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-01-13 10:18 - 2015-12-30 18:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-01-13 10:18 - 2015-12-30 18:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 18:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-01-13 10:18 - 2015-12-24 00:13 - 00387784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-01-13 10:18 - 2015-12-23 23:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-01-13 10:18 - 2015-12-12 19:54 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-01-13 10:18 - 2015-12-12 19:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-01-13 10:18 - 2015-12-12 19:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-01-13 10:18 - 2015-12-12 19:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-01-13 10:18 - 2015-12-12 19:15 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-01-13 10:18 - 2015-12-12 19:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-01-13 10:18 - 2015-12-12 19:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-01-13 10:18 - 2015-12-12 19:07 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-01-13 10:18 - 2015-12-12 19:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-01-13 10:18 - 2015-12-12 19:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-01-13 10:18 - 2015-12-12 19:03 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-01-13 10:18 - 2015-12-12 19:02 - 20367360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-01-13 10:18 - 2015-12-12 19:02 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-01-13 10:18 - 2015-12-12 19:02 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-01-13 10:18 - 2015-12-12 19:02 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-01-13 10:18 - 2015-12-12 18:55 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-01-13 10:18 - 2015-12-12 18:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-01-13 10:18 - 2015-12-12 18:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-01-13 10:18 - 2015-12-12 18:44 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-01-13 10:18 - 2015-12-12 18:40 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-01-13 10:18 - 2015-12-12 18:39 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-01-13 10:18 - 2015-12-12 18:37 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-01-13 10:18 - 2015-12-12 18:37 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-01-13 10:18 - 2015-12-12 18:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-01-13 10:18 - 2015-12-12 18:36 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-01-13 10:18 - 2015-12-12 18:35 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-01-13 10:18 - 2015-12-12 18:33 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-01-13 10:18 - 2015-12-12 18:31 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-01-13 10:18 - 2015-12-12 18:28 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-01-13 10:18 - 2015-12-12 18:27 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-01-13 10:18 - 2015-12-12 18:27 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-01-13 10:18 - 2015-12-12 18:27 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-01-13 10:18 - 2015-12-12 18:25 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-01-13 10:18 - 2015-12-12 18:23 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-01-13 10:18 - 2015-12-12 18:22 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-01-13 10:18 - 2015-12-12 18:21 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-01-13 10:18 - 2015-12-12 18:20 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-01-13 10:18 - 2015-12-12 18:19 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-01-13 10:18 - 2015-12-12 18:18 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-01-13 10:18 - 2015-12-12 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-01-13 10:18 - 2015-12-12 18:12 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-01-13 10:18 - 2015-12-12 18:10 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-01-13 10:18 - 2015-12-12 18:09 - 04610560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-01-13 10:18 - 2015-12-12 18:08 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-01-13 10:18 - 2015-12-12 18:06 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-01-13 10:18 - 2015-12-12 18:02 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-01-13 10:18 - 2015-12-12 18:00 - 12856320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-01-13 10:18 - 2015-12-12 18:00 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-01-13 10:18 - 2015-12-12 18:00 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-01-13 10:18 - 2015-12-12 18:00 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-01-13 10:18 - 2015-12-12 17:54 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-01-13 10:18 - 2015-12-12 17:42 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-01-13 10:18 - 2015-12-12 17:41 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-01-13 10:18 - 2015-12-12 17:38 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-01-13 10:18 - 2015-12-12 17:36 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-01-13 10:18 - 2015-12-08 22:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-01-13 10:18 - 2015-12-08 22:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-01-13 10:18 - 2015-12-08 20:07 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-01-13 10:18 - 2015-12-08 20:07 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-01-12 22:35 - 2016-01-12 22:35 - 00000000 ____D C:\Users\Basti\AppData\Local\bdch
2016-01-12 22:35 - 2016-01-12 22:35 - 00000000 ____D C:\ProgramData\bdch
2016-01-12 22:23 - 2016-01-12 22:28 - 00000000 ____D C:\Users\Basti\Wichtig
2016-01-12 21:43 - 2016-01-12 21:43 - 00000684 ____H C:\bdr-cf01
2016-01-12 21:42 - 2016-01-12 21:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2016
2016-01-12 21:41 - 2016-01-12 21:43 - 00253404 ____H C:\bdr-ld01
2016-01-12 21:41 - 2016-01-12 21:43 - 00009216 ____H C:\bdr-ld01.mbr
2016-01-12 21:41 - 2015-10-22 14:02 - 00271808 _____ (Bitdefender) C:\Windows\system32\Drivers\ignis.sys
2016-01-12 21:41 - 2015-07-15 16:13 - 49737193 ____H C:\bdr-im01.gz
2016-01-12 21:41 - 2013-08-13 12:38 - 03271472 ____H C:\bdr-bz01
2016-01-12 21:40 - 2015-06-02 14:21 - 00477272 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2016-01-12 21:40 - 2015-04-29 13:32 - 00160032 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2016-01-12 21:37 - 2016-01-12 21:37 - 09736920 _____ C:\Users\Basti\Downloads\bitdefender_windows_2268285f-b17f-4c1f-972a-438e9cf16488.exe
2016-01-12 21:27 - 2016-01-12 21:27 - 09736920 _____ C:\Users\Basti\Downloads\bitdefender_windows_752fc001-db4f-4d5a-b26f-50072841116e.exe
2016-01-12 21:24 - 2016-01-12 21:24 - 00003414 _____ C:\Windows\System32\Tasks\Bitdefender Restart ProductCfg_F5C977342AD24B62922B89BDC5ABCCD2
2016-01-10 21:28 - 2016-01-21 13:14 - 00002020 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evolve.lnk
2016-01-10 21:28 - 2016-01-21 13:14 - 00002014 _____ C:\Users\Public\Desktop\Evolve.lnk
2016-01-10 21:28 - 2016-01-10 21:28 - 00021656 _____ (Echobit, LLC) C:\Windows\system32\Drivers\evolve.sys
2016-01-10 21:28 - 2016-01-10 21:28 - 00000000 ____D C:\Program Files\Echobit
2016-01-10 21:27 - 2016-01-10 21:27 - 03258328 _____ (Echobit LLC) C:\Users\Basti\Downloads\EvolveSetup.exe
2016-01-10 21:27 - 2016-01-10 21:27 - 00003140 _____ C:\Windows\System32\Tasks\{4FE8E9A0-83ED-441A-8CB2-539F94CDF074}
2016-01-10 21:27 - 2016-01-10 21:27 - 00000000 ____D C:\Users\Basti\AppData\Local\Echobit
2016-01-10 21:27 - 2016-01-10 21:27 - 00000000 ____D C:\ProgramData\Echobit
2016-01-10 13:57 - 2016-01-10 13:57 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2016-01-10 13:57 - 2015-10-13 14:32 - 03806032 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
2016-01-10 13:57 - 2005-01-03 07:43 - 00004682 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys
2016-01-10 13:57 - 2003-07-18 22:17 - 00005174 _____ C:\Windows\SysWOW64\nppt9x.vxd
2016-01-10 12:28 - 2016-01-21 14:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCSOFT
2016-01-10 12:28 - 2016-01-21 14:34 - 00000000 ____D C:\Program Files (x86)\NCSOFT
2016-01-10 12:27 - 2016-01-21 14:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCWest
2016-01-10 12:27 - 2016-01-21 14:33 - 00000000 ____D C:\Program Files (x86)\NCWest
2016-01-10 12:26 - 2016-01-10 12:26 - 00003534 _____ C:\Users\Basti\Documents\cc_20160110_122618.reg
2016-01-10 12:26 - 2016-01-10 12:26 - 00000372 _____ C:\Users\Basti\Documents\cc_20160110_122633.reg
2016-01-10 12:25 - 2016-01-10 12:25 - 00254422 _____ C:\Users\Basti\Documents\cc_20160110_122546.reg
2016-01-10 12:03 - 2016-01-10 12:03 - 224976152 _____ (NC Interactive, LLC ) C:\Users\Basti\Downloads\BnS_Lite_Installer.exe
2016-01-09 11:57 - 2016-01-09 11:57 - 02026520 _____ (BitTorrent Inc.) C:\Users\Basti\Downloads\uTorrent (1).exe
2016-01-09 03:35 - 2016-01-10 14:02 - 00000000 ____D C:\Users\Basti\Documents\BnS
2016-01-08 20:16 - 2016-01-08 20:16 - 00000000 ____D C:\Users\Basti\AppData\Local\BNSUpdater
2016-01-08 18:54 - 2016-01-08 18:54 - 00000000 ____D C:\Users\Basti\Downloads\BnS
2016-01-08 18:47 - 2016-01-08 18:47 - 02026520 _____ (BitTorrent Inc.) C:\Users\Basti\Downloads\uTorrent.exe
2016-01-08 18:47 - 2016-01-08 18:47 - 00024161 _____ C:\Users\Basti\Downloads\playbns_client_2.torrent
2016-01-04 23:40 - 2016-01-04 23:40 - 00028578 _____ C:\Users\Basti\Downloads\malloc.exe
2016-01-04 23:40 - 2016-01-04 23:40 - 00001740 _____ C:\Users\Basti\Downloads\malloc.o
2016-01-04 23:39 - 2016-01-04 23:39 - 00002827 _____ C:\Users\Basti\Downloads\malloc.c
2016-01-04 22:15 - 2016-01-04 22:15 - 00000747 _____ C:\Users\Basti\Desktop\aufgabe5.c
2016-01-04 11:09 - 2016-01-04 11:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-01-04 00:00 - 2016-01-21 13:13 - 00000968 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\MinGW Installation Manager.lnk
2016-01-04 00:00 - 2016-01-04 00:16 - 00000000 ____D C:\MinGW
2016-01-03 23:59 - 2016-01-03 23:59 - 00086528 _____ (MinGW.org Project) C:\Users\Basti\Downloads\mingw-get-setup.exe
2016-01-03 23:52 - 2016-01-03 23:52 - 122655932 _____ C:\Users\Basti\Downloads\gcc-5.2.0.tar.gz
2016-01-03 12:00 - 2016-01-13 17:50 - 00000000 ____D C:\Users\Basti\AppData\Roaming\CodeBlocks
2016-01-03 11:59 - 2016-01-21 13:12 - 00001104 _____ C:\Users\Basti\Desktop\CodeBlocks.lnk
2016-01-03 11:59 - 2016-01-03 12:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks
2016-01-03 11:59 - 2016-01-03 12:00 - 00000000 ____D C:\Program Files (x86)\CodeBlocks
2016-01-03 11:59 - 2016-01-03 11:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks
2016-01-03 11:58 - 2016-01-03 11:59 - 102611063 _____ (The Code::Blocks Team) C:\Users\Basti\Downloads\codeblocks-13.12mingw-setup.exe
2015-12-29 00:23 - 2015-12-29 00:23 - 00038432 _____ (SoftEther Corporation) C:\Windows\system32\Drivers\Neo_0024.sys
2015-12-29 00:21 - 2016-01-21 13:14 - 00001980 _____ C:\Users\Public\Desktop\SoftEther VPN Client Manager.lnk
2015-12-29 00:21 - 2016-01-21 13:13 - 00001992 _____ C:\ProgramData\Microsoft\Windows\Start Menu\SoftEther VPN Client Manager.lnk
2015-12-29 00:21 - 2015-12-29 00:21 - 00144104 _____ (SoftEther VPN Project at University of Tsukuba, Japan.) C:\Windows\system32\vpncmd.exe
2015-12-29 00:21 - 2015-12-29 00:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftEther VPN Client
2015-12-29 00:20 - 2016-01-21 14:14 - 00000000 ____D C:\Program Files\SoftEther VPN Client
2015-12-29 00:19 - 2015-12-29 00:19 - 00000000 ____D C:\Users\Basti\Downloads\vpngate-client-2015.12.29-build-9599.134383
2015-12-29 00:17 - 2015-12-29 00:19 - 54298926 _____ C:\Users\Basti\Downloads\vpngate-client-2015.12.29-build-9599.134383.zip
2015-12-28 23:35 - 2015-12-29 00:57 - 00000000 ____D C:\Users\Basti\Documents\Black Desert
2015-12-28 23:30 - 2015-12-28 23:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Black Desert RU Patcher
2015-12-28 23:16 - 2015-12-28 23:16 - 00000000 __SHD C:\ProgramData\Info
2015-12-28 21:32 - 2016-01-21 14:13 - 00000000 ____D C:\Users\Basti\AppData\Local\THORN
2015-12-28 21:31 - 2016-01-08 15:56 - 00004296 _____ C:\Windows\System32\Tasks\GameNet
2015-12-28 21:31 - 2015-12-28 21:31 - 00000000 ____D C:\Users\Basti\AppData\Local\Vebanaul
2015-12-28 21:29 - 2015-12-28 21:29 - 00478768 _____ (Global Gamers Solutions Ltd. (c)) C:\Users\Basti\Downloads\PlayBlackDesert.exe
2015-12-28 21:24 - 2015-12-28 21:24 - 04363099 _____ C:\Users\Basti\Downloads\setup.exe

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-01-21 23:56 - 2012-05-27 12:25 - 00000000 ____D C:\Users\Basti\Documents\Outlook-Dateien
2016-01-21 23:50 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2016-01-21 23:41 - 2015-12-13 01:57 - 00000000 ____D C:\Program Files\Bitdefender Agent
2016-01-21 23:40 - 2012-06-06 20:18 - 00000000 ____D C:\Users\Basti\AppData\Local\LogMeIn Hamachi
2016-01-21 23:40 - 2012-05-26 17:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Skype
2016-01-21 23:27 - 2009-07-14 05:45 - 00032080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-21 23:27 - 2009-07-14 05:45 - 00032080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-21 23:15 - 2012-05-26 17:22 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-21 23:05 - 2012-05-27 00:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-21 22:15 - 2012-05-26 17:22 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-21 15:28 - 2013-11-03 23:54 - 02324992 ___SH C:\Users\Basti\Desktop\Thumbs.db
2016-01-21 14:34 - 2012-05-25 15:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-01-21 14:23 - 2015-04-17 22:24 - 00000546 ____H C:\Windows\Tasks\MATLAB R2015a Startup Accelerator.job
2016-01-21 14:13 - 2015-07-15 14:58 - 00000000 _____ C:\hsrv.txt
2016-01-21 14:13 - 2012-05-25 15:06 - 00000000 ____D C:\ProgramData\NVIDIA
2016-01-21 14:13 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-21 13:29 - 2015-11-27 18:06 - 00002353 _____ C:\Users\Basti\Desktop\Chrome App Launcher.lnk
2016-01-21 13:14 - 2015-12-13 02:12 - 00002129 _____ C:\Users\Public\Desktop\Bitdefender 2016.lnk
2016-01-21 13:14 - 2015-11-21 11:45 - 00001106 _____ C:\Users\Public\Desktop\LECTURNITY Player.lnk
2016-01-21 13:14 - 2015-11-02 11:42 - 00001160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-01-21 13:14 - 2015-11-02 11:42 - 00001154 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-01-21 13:14 - 2015-09-27 14:20 - 00002178 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-21 13:14 - 2015-08-12 00:30 - 00002373 _____ C:\Users\Public\Desktop\TI-Nspire CX CAS Student Software.lnk
2016-01-21 13:14 - 2015-08-11 23:58 - 00002333 _____ C:\Users\Public\Desktop\TI-Nspire CAS Student Software.lnk
2016-01-21 13:14 - 2015-07-15 14:58 - 00000998 _____ C:\Users\Public\Desktop\Droid4X.lnk
2016-01-21 13:14 - 2015-07-14 23:38 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-01-21 13:14 - 2015-07-14 23:38 - 00002050 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-01-21 13:14 - 2015-06-20 11:50 - 00001094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Content Viewer.lnk
2016-01-21 13:14 - 2015-06-06 15:54 - 00001202 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk
2016-01-21 13:14 - 2015-05-28 15:57 - 00001062 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk
2016-01-21 13:14 - 2015-04-17 22:27 - 00001296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2015a.lnk
2016-01-21 13:14 - 2015-04-17 22:27 - 00001290 _____ C:\Users\Public\Desktop\MATLAB R2015a.lnk
2016-01-21 13:14 - 2015-02-21 13:07 - 00001166 _____ C:\Users\Public\Desktop\Dell Display Manager.lnk
2016-01-21 13:14 - 2015-01-23 17:18 - 00002029 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2016-01-21 13:14 - 2014-10-13 18:21 - 00000937 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2016-01-21 13:14 - 2014-10-09 14:36 - 00001243 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2016-01-21 13:14 - 2014-10-09 14:36 - 00001228 _____ C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2016-01-21 13:14 - 2014-07-02 22:48 - 00001998 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk
2016-01-21 13:14 - 2014-07-02 22:43 - 00000960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR-Registrierung.lnk
2016-01-21 13:14 - 2014-07-02 22:42 - 00002113 _____ C:\Users\Public\Desktop\HP Officejet 6700.lnk
2016-01-21 13:14 - 2013-11-20 21:36 - 00000918 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-01-21 13:14 - 2012-12-01 16:29 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
2016-01-21 13:14 - 2012-12-01 16:29 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
2016-01-21 13:14 - 2012-12-01 16:27 - 00001094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2016-01-21 13:14 - 2012-12-01 16:24 - 00000994 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2016-01-21 13:14 - 2012-11-24 13:29 - 00000869 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-01-21 13:14 - 2012-11-20 16:01 - 00001878 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
2016-01-21 13:14 - 2012-08-18 15:28 - 00002002 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
2016-01-21 13:14 - 2012-08-18 15:28 - 00001946 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
2016-01-21 13:14 - 2012-08-18 15:28 - 00001925 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
2016-01-21 13:14 - 2012-07-30 11:51 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-01-21 13:14 - 2012-07-29 17:18 - 00001297 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk
2016-01-21 13:14 - 2012-06-26 19:04 - 00001914 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOL Recorder.lnk
2016-01-21 13:14 - 2012-06-07 19:29 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk
2016-01-21 13:14 - 2011-06-29 12:22 - 00001455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2016-01-21 13:14 - 2011-06-29 12:22 - 00001371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
2016-01-21 13:14 - 2011-06-29 12:22 - 00001302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
2016-01-21 13:14 - 2011-06-29 12:21 - 00002483 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2016-01-21 13:14 - 2011-04-27 12:03 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-01-21 13:14 - 2011-04-27 12:03 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-01-21 13:14 - 2009-07-14 05:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-01-21 13:14 - 2009-07-14 05:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2016-01-21 13:14 - 2009-07-14 05:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-01-21 13:14 - 2009-07-14 05:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-01-21 13:14 - 2009-07-14 05:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-01-21 13:13 - 2013-12-14 11:41 - 00001804 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2016-01-21 13:13 - 2012-05-27 11:24 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\HP Solution Center.lnk
2016-01-21 13:13 - 2012-05-26 16:56 - 00001434 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-01-21 13:13 - 2009-07-14 06:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-01-21 13:13 - 2009-07-14 05:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-01-21 13:12 - 2015-11-01 15:43 - 00002137 _____ C:\Users\Basti\Desktop\Minecraft.lnk
2016-01-21 13:12 - 2015-09-30 16:40 - 00002029 _____ C:\Users\Basti\Desktop\My.com Game Center.lnk
2016-01-21 13:12 - 2015-08-25 21:01 - 00000833 _____ C:\Users\Basti\Desktop\lol.launcher.admin - Verknüpfung.lnk
2016-01-21 13:12 - 2015-06-17 14:20 - 00001085 _____ C:\Users\Basti\Desktop\Oracle VM VirtualBox.lnk
2016-01-21 13:12 - 2015-06-04 13:52 - 00001964 _____ C:\Users\Basti\Desktop\The Witcher® 3 - Wild Hunt.lnk
2016-01-21 13:12 - 2015-06-01 12:56 - 00001020 _____ C:\Users\Basti\Desktop\Fidelify.lnk
2016-01-21 13:12 - 2015-03-19 11:59 - 00001818 _____ C:\Users\Basti\Desktop\Spotify.lnk
2016-01-21 13:12 - 2014-06-08 17:13 - 00001900 _____ C:\Users\Basti\Desktop\Watch Dogs.lnk
2016-01-21 13:12 - 2014-05-24 11:30 - 00001886 _____ C:\Users\Basti\Desktop\CivilizationV_DX11.exe.lnk
2016-01-21 13:12 - 2014-05-24 00:12 - 00001011 _____ C:\Users\Basti\Desktop\Dark Souls II Black Armour Edition.lnk
2016-01-21 13:12 - 2014-05-23 20:12 - 00000628 _____ C:\Users\Basti\Desktop\Tropico 5.lnk
2016-01-21 13:12 - 2014-05-17 11:27 - 00002118 _____ C:\Users\Basti\Desktop\JDownloader 2.lnk
2016-01-21 13:12 - 2012-06-21 20:47 - 00001087 _____ C:\Users\Basti\Desktop\Basti.lnk
2016-01-21 13:12 - 2012-05-27 11:05 - 00000355 _____ C:\Users\Basti\Desktop\Computer.lnk
2016-01-21 13:09 - 2010-11-21 08:00 - 00000000 ____D C:\Windows\ShellNew
2016-01-21 13:07 - 2012-06-06 19:59 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-01-21 13:07 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-01-21 09:34 - 2012-05-26 17:23 - 00000000 ____D C:\Users\Basti\AppData\Local\Adobe
2016-01-20 10:05 - 2012-05-27 00:38 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-20 10:05 - 2012-05-27 00:38 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-20 10:05 - 2012-05-27 00:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-01-18 10:31 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2016-01-18 09:51 - 2015-08-02 16:20 - 00000000 ____D C:\Users\Basti\Desktop\Trainer
2016-01-18 00:53 - 2012-08-18 14:08 - 00007599 _____ C:\Users\Basti\AppData\Local\Resmon.ResmonCfg
2016-01-17 23:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-01-17 23:26 - 2012-09-11 20:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-01-17 23:23 - 2012-05-25 15:05 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-01-17 23:19 - 2012-05-25 15:05 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-01-17 23:08 - 2015-11-01 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-01-17 23:08 - 2015-01-31 18:37 - 00000000 ____D C:\Program Files (x86)\Java
2016-01-17 23:08 - 2013-10-07 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-01-17 23:07 - 2013-10-07 22:47 - 00000000 ____D C:\ProgramData\Oracle
2016-01-17 01:03 - 2013-12-14 11:41 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Spotify
2016-01-16 11:33 - 2013-12-14 11:41 - 00000000 ____D C:\Users\Basti\AppData\Local\Spotify
2016-01-14 23:53 - 2013-11-20 21:36 - 00000000 ____D C:\Users\Basti\AppData\Roaming\vlc
2016-01-14 12:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2016-01-14 10:57 - 2010-11-21 07:50 - 00737796 _____ C:\Windows\system32\perfh007.dat
2016-01-14 10:57 - 2010-11-21 07:50 - 00159894 _____ C:\Windows\system32\perfc007.dat
2016-01-14 10:57 - 2009-07-14 06:13 - 01710742 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-14 10:50 - 2009-07-14 05:45 - 05101656 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-14 10:46 - 2014-12-11 12:06 - 00000000 ____D C:\Windows\system32\appraiser
2016-01-14 10:46 - 2014-05-01 02:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-01-14 10:42 - 2013-03-13 23:18 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-14 10:42 - 2013-03-13 23:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-01-14 02:32 - 2013-03-13 23:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-14 02:32 - 2012-05-27 11:15 - 00000000 ____D C:\ProgramData\Microsoft Help
2016-01-14 02:29 - 2013-07-21 22:37 - 00000000 ____D C:\Windows\system32\MRT
2016-01-14 02:05 - 2011-04-27 12:44 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-01-14 01:58 - 2009-07-14 03:34 - 00000513 _____ C:\Windows\win.ini
2016-01-13 17:34 - 2012-06-09 15:23 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-01-13 17:34 - 2012-06-09 15:23 - 00000000 ____D C:\ProgramData\Skype
2016-01-13 16:50 - 2015-11-01 15:52 - 00000000 ____D C:\Users\Basti\.oracle_jre_usage
2016-01-12 22:23 - 2012-05-26 16:53 - 00000000 ____D C:\Users\Basti
2016-01-12 22:20 - 2015-12-13 02:08 - 00000000 ____D C:\ProgramData\Bitdefender
2016-01-12 22:10 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Offline Web Pages
2016-01-12 22:05 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2016-01-12 21:49 - 2015-09-30 16:38 - 00000000 ____D C:\Users\Basti\AppData\Local\MyComGames
2016-01-12 21:42 - 2015-12-13 02:11 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Bitdefender
2016-01-12 21:40 - 2015-12-13 02:07 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2016-01-12 15:22 - 2015-04-17 23:21 - 00000000 ____D C:\Users\Basti\Documents\MATLAB
2016-01-10 12:21 - 2012-11-24 14:09 - 00000000 ____D C:\Program Files (x86)\Steam
2016-01-10 12:21 - 2012-06-07 15:43 - 00000000 ____D C:\Users\Basti\AppData\Roaming\TS3Client
2016-01-10 12:20 - 2012-09-10 17:02 - 00000000 ____D C:\Windows\Minidump
2016-01-08 19:16 - 2013-02-02 19:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-01-04 11:09 - 2014-03-29 12:34 - 00000000 ____D C:\Users\Basti\AppData\Local\Skype
2016-01-04 02:53 - 2014-02-10 17:04 - 00000000 ____D C:\Users\Basti\AppData\Local\Battle.net
2016-01-04 00:56 - 2015-06-06 15:50 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm
2016-01-04 00:23 - 2013-10-17 14:45 - 00000000 ____D C:\Users\Basti\Uni
2016-01-03 14:04 - 2015-12-15 14:33 - 00000000 ____D C:\Users\Basti\Desktop\test
2015-12-30 11:58 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-12-28 22:49 - 2015-07-16 00:46 - 00000095 _____ C:\Users\Basti\Desktop\codes.txt
2015-12-24 13:21 - 2014-02-10 17:04 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-12-23 15:32 - 2015-05-28 21:19 - 00000000 ____D C:\Users\Basti\Documents\The Witcher 3
2015-12-22 12:01 - 2015-05-28 15:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2015-12-22 11:25 - 2015-05-28 15:57 - 00000000 ____D C:\Program Files (x86)\GalaxyClient

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2012-09-29 16:29 - 2013-02-12 19:50 - 0000064 _____ () C:\Program Files\MC.bat
2012-06-06 20:13 - 2012-05-11 18:11 - 0139783 _____ () C:\Program Files\MinecraftSP.jar
2012-11-08 05:39 - 2012-11-08 05:39 - 120115048 _____ () C:\Program Files (x86)\avira_antivirus_premium_en.exe
2012-07-14 15:28 - 2015-11-02 21:05 - 376347915 _____ () C:\Users\Basti\AppData\Roaming\.minecraft.rar
2013-02-07 19:16 - 2015-08-31 22:51 - 0000132 _____ () C:\Users\Basti\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
2015-07-15 14:57 - 2015-07-15 15:00 - 0002380 _____ () C:\Users\Basti\AppData\Roaming\droid4xinstaller.log
2012-08-18 14:08 - 2016-01-18 00:53 - 0007599 _____ () C:\Users\Basti\AppData\Local\Resmon.ResmonCfg
2014-07-02 22:42 - 2014-07-02 22:42 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-07-02 20:16 - 2012-07-02 20:16 - 0000252 _____ () C:\ProgramData\FastPics.log
2012-05-27 11:11 - 2012-06-10 15:42 - 0005000 _____ () C:\ProgramData\hpzinstall.log
2012-07-02 20:16 - 2013-03-01 18:36 - 0025200 _____ () C:\ProgramData\lxdw.log
2012-07-02 20:19 - 2012-07-02 20:24 - 0000537 _____ () C:\ProgramData\lxdwDiagnostics.log

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\Basti\hamachi-2-ui.exe
C:\Users\Basti\save.reg


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-01-19 09:35

==================== Ende von FRST.txt ============================
         

Ich konnte die restlichen Log files (Addition, Malwarebyte Bericht) nicht einfügen, da die Nachricht sonst zu lang ist.


Mfg Basti

Alt 22.01.2016, 00:24   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Hi und

Logs bitte nicht anhängen, notfalls splitten und über mehrere Postings verteilt posten

Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 22.01.2016, 00:55   #3
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Wollte nur nicht gleich nochmal ein post machen, da es ja irgendwo heißt, dass man in einem neu eröffneten Thema nicht gleich nochmal posten soll.

Also Addition

FRST Additions Logfile:
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-01-2016
durchgeführt von Basti (2016-01-21 23:57:51)
Gestartet von C:\Users\Basti\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2012-05-26 15:53:52)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-1745305398-2489788369-3521438674-500 - Administrator - Disabled)
Basti (S-1-5-21-1745305398-2489788369-3521438674-1002 - Administrator - Enabled) => C:\Users\Basti
Gast (S-1-5-21-1745305398-2489788369-3521438674-501 - Limited - Enabled)
Zocken (S-1-5-21-1745305398-2489788369-3521438674-1005 - Limited - Enabled) => C:\Users\Zocken

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Bitdefender Antivirus (Enabled - Out of date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AS: Bitdefender Spyware-Schutz (Enabled - Out of date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.14 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.3 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.286 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.)
Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AppNHost 1.0.5.1 (HKLM-x32\...\{A8CB86C7-CD4C-4C4F-AF6A-33D1CAC63562}) (Version: 1.0.5.1 - Mixesoft Project)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.5510 - Perfect World Entertainment)
Assassin's Creed (R) III (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft)
Audible Download Manager (HKLM-x32\...\AudibleDownloadManager) (Version: 6.6.0.15 - Audible, Inc.)
avira_antivirus_premium_en 1.00 (HKLM-x32\...\avira_antivirus_premium_en 1.00) (Version: 1.00 - Avira)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.5.2.34169 - Electronic Arts)
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 20.0.23.1252 - Bitdefender)
Bitdefender Total Security 2016 (HKLM\...\Bitdefender) (Version: 20.0.23.1252 - Bitdefender)
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Black Desert RU Patcher (HKLM-x32\...\{94381DF9-7266-459C-AF82-4D1458E1AFE7}) (Version: 1.00.0000 - Black Desert RU Patcher)
Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC)
Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
C4600 (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.24 - Piriform)
CD- und DVD-Sharing (HKLM-x32\...\{514FBEC8-E8CE-4F6F-A17F-2789E8DE8D69}) (Version: 1.0.1.4 - Apple Inc.)
Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.11004 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.11004 - Cisco Systems, Inc.) Hidden
CodeBlocks (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0315 - DT Soft Ltd)
Dark Souls II Black Armour Edition MULTI-2 1.0 (HKLM-x32\...\Dark Souls II Black Armour Edition MULTI-2 1.0) (Version:  - )
Dassault Systemes Software B21 (HKLM\...\Dassault Systemes B21_0) (Version:  - )
Dassault Systemes Software Prerequisites x86-x64 (HKLM\...\{CF1EB598-B424-436A-B15F-B763846BA970}) (Version: 8.1.3 - Dassault Systemes)
Dassault Systemes Software VC9 Prerequisites x86-x64 (HKLM\...\{F2F2DEA7-36AB-4E13-907C-D8BDE775EF97}) (Version: 9.1.2 - Dassault Systemes)
DayZ (HKLM-x32\...\Steam App 221100) (Version:  - Bohemia Interactive)
Dell Display Manager (HKLM-x32\...\{AC50C05D-9D57-40F5-B2EF-AC402F14312B}_is1) (Version:  - EnTech Taiwan)
Delta Chrome Toolbar (HKLM-x32\...\{177586E7-E42E-4F38-83D1-D15B4AF5B714}) (Version: 1.0.0.0 - DeltaInstaller) <==== ACHTUNG
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - )
Download Updater (AOL LLC) (HKLM-x32\...\SoftwareUpdUtility) (Version:  - ) <==== ACHTUNG
Droid4X (HKLM-x32\...\Droid4X) (Version: 0.8.2 - Haiyu Dongxiang Co.,Ltd.)
Dropbox (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
DVDFab 9.0.6.0 (21/08/2013) (HKLM-x32\...\DVDFab 9_is1) (Version:  - Fengtao Software Inc.)
EE-ZDE (HKLM-x32\...\{B49C924C-A651-4378-94F6-5D9BF44A959F}) (Version:  - )
Empire Earth (HKLM-x32\...\{2447500B-22D7-47BD-9B13-1A927F43A267}) (Version:  - )
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Evolve (HKLM\...\{670B1B49-9FD3-4827-9B41-471EFF580AA8}) (Version: 1.8.18 - Echobit, LLC)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Fidelify (HKLM-x32\...\Fidelify) (Version:  - )
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free YouTube to MP3 Converter version 3.11.34.1015 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.34.1015 - DVDVideoSoft Ltd.)
Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.9.0 - Futuremark Corporation)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gameforge Live 1.0 "Legend" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 1.1.1724 - Gameforge)
GeoGebra 5 (HKLM-x32\...\GeoGebra 5) (Version: 5.0.53.0 - International GeoGebra Institute)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden
GUILD WARS (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Guild Wars) (Version:  - )
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Officejet 6700 - Grundlegende Software für das Gerät (HKLM\...\{9086D601-50B7-491D-A143-28193DADE36B}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 6700 Hilfe (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP)
HP Photosmart C4600 All-In-One Driver Software 14.0 Rel. 5 (HKLM\...\{1E1746EF-F5BF-4677-8F30-04FE399130DA}) (Version: 14.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}) (Version: 3.0.2.163 - Apple Inc.)
iFree Skype Recorder 6.0.15 (HKLM-x32\...\iFree Skype Recorder) (Version: 6.0.15 - iFree Skype Recorder)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{0DCD0704-E2AB-4e97-96A7-90F146BD8243}) (Version: 2.50.6733.38 - Sony Computer Entertainment Inc.)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.6 - Intel)
iTunes (HKLM\...\{A04DCB25-7040-4935-A30D-8E0A893ABF2D}) (Version: 11.1.2.32 - Apple Inc.)
JAP (HKLM-x32\...\JAP) (Version: 00.18.001 - JAP-Team)
Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java SE Development Kit 8 Update 65 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180650}) (Version: 8.0.650.17 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games)
LECTURNITY Player (HKLM-x32\...\{8624888C-A959-45A5-98F4-292E956325EA}) (Version: 4.5.0000 - imc AG)
Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.)
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.410 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.410 - LogMeIn, Inc.) Hidden
LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.0.1 - www.leaguereplays.com)
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
MATLAB R2015a (HKLM\...\Matlab R2015a) (Version: 8.5 - MathWorks)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{3c3aafc8-d898-43ec-998f-965ffdae065a}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft)
Minecraft1.6.2 (HKLM-x32\...\Minecraft1.6.2) (Version:  - )
Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My.com Game Center (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\MyComGames) (Version: 3.146 - My.com B.V.)
NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version:  - NCSOFT)
Need for Speed™ Most Wanted (HKLM-x32\...\{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}) (Version:  - )
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.52.3 - Black Tree Gaming)
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation)
NVIDIA 3D Vision Video Player (HKLM-x32\...\{FE3B9518-9FF3-4D89-8A8D-E540C9CCAF3B}) (Version: 1.5.2 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.8.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.8.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.3.6.4639 - Electronic Arts, Inc.)
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r4600) (Version:  - )
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PFConfig 1.0.296 (HKLM-x32\...\PFConfig) (Version: 1.0.296 - Portforward.com)
Pflanzen gegen Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PS_AIO_05_C4600_Software_Min (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden
PTC Mathcad Prime 3.0 (HKLM-x32\...\{C4AB999A-D981-4913-BA26-E4776B598E7D}) (Version: 3.0.0 - PTC)
PTC Quality Agent (HKLM-x32\...\{5B7F8A19-AF71-4517-B49C-683AFC5B639C}) (Version: 2.0.0.0 - PTC)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden
Revo Uninstaller 1.94 (HKLM-x32\...\Revo Uninstaller) (Version: 1.94 - VS Revo Group)
Samsung New PC Studio (HKLM-x32\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.)
Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden
Secure Download Manager (HKLM-x32\...\{531E35C7-B4E7-418C-A2CD-C1205D9C8AC9}) (Version: 3.1.20 - Kivuto Solutions Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)
Sid Meier's Civilization V (HKLM-x32\...\Sid Meier's Civilization V_is1) (Version: Sid Meier's Civilization V - )
skyforge_mycom (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\skyforge_mycom) (Version: 1.46 - My.com B.V.)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.103 - Skype Technologies S.A.)
Sleeping Dogs Limited Edition (HKLM-x32\...\Sleeping Dogs™ UPDATE 1.5_is1) (Version: 1.5.0.0 - QfG)
SleepTimer Ultimate 1.2 (HKLM-x32\...\{0EE56463-49B2-45E1-B74F-3E0139DBC986}_is1) (Version:  - Christian Handorf)
SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.19.9599 - SoftEther VPN Project)
SolutionCenter (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Space Engineers (HKLM-x32\...\Steam App 244850) (Version:  - Keen Software House)
Spotify (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB)
Status (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.11.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.0.10.0 - GOG.com)
TI-Nspire™ CAS Student Software (HKLM-x32\...\{F03A8756-7FCB-4DCD-9AC1-12C63A6075F1}) (Version: 3.9.0.463 - Texas Instruments Inc.)
TI-Nspire™ CX CAS Student Software (HKLM-x32\...\{E994956D-8CA7-4091-BFF5-0C749470BA2E}) (Version: 4.0.0.235 - Texas Instruments Inc.)
Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Tropico 5 (HKLM-x32\...\Tropico 5_is1) (Version:  - )
Unity Web Player (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft)
VBA (3821b) (x32 Version: 6.01.00.1234 - Microsoft Corporation) Hidden
VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN)
WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden
Winamp (HKLM-x32\...\Winamp) (Version: 5.623  - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Winamp Toolbar (HKLM-x32\...\Winamp Toolbar) (Version:  - ) <==== ACHTUNG
Winamp Toolbar (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Winamp Toolbar) (Version:  - ) <==== ACHTUNG
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR 4.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH)
Xilisoft iPod to PC Copy (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Xilisoft iPod to PC Copy) (Version: 5.4.0.20120709 - Xilisoft)
XMedia Recode Version 3.1.1.6 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.1.6 - XMedia Recode)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03DA3B3E-4D58-494B-B245-DAD0A8DBDDBB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {153DADDB-4AF6-47D4-9A9D-67EC0B18A250} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated)
Task: {1B95DAB2-8C86-456F-A170-84602E3279E6} - System32\Tasks\Bitdefender Restart ProductCfg_F5C977342AD24B62922B89BDC5ABCCD2 => C:\Program Files\Bitdefender\Bitdefender 2016\ProductCfg.exe [2016-01-12] (Bitdefender)
Task: {1BA04B1B-DE8A-4E45-ACDA-1A8BA907AFFA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-10-24] (Piriform Ltd)
Task: {1F671263-2C93-4355-8954-D8A6E869F130} - System32\Tasks\{4B70D9A6-59CA-43A1-BDBB-B887E40A84D7} => Firefox.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/go/help.faq.installer?LastError=1618
Task: {2490A96E-2646-4481-8A6A-BBB935E89609} - System32\Tasks\{9342110C-473A-40B6-BA74-470DFD73271A} => pcalua.exe -a "C:\Program Files\NVIDIA Corporation\3D Emitter\nvUSBInst.exe" -d "C:\Program Files\NVIDIA Corporation\3D Emitter"
Task: {293C18C3-B0F0-4881-947C-966DBAC8BD49} - System32\Tasks\{2D1288DA-1D43-479F-8B4B-36F07394063D} => pcalua.exe -a C:\Users\Basti\Downloads\jxpiinstall(2).exe -d C:\Users\Basti\Downloads
Task: {3ACB3CBC-294D-4FA3-A2D0-3F121830A2F8} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2015-11-09] (Bitdefender)
Task: {4BFE7F94-DA9B-405C-A8F1-276005CD48F2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-20] (Adobe Systems Incorporated)
Task: {508DEA04-F80D-4D62-8C8D-BC6AC05F4FA3} - System32\Tasks\GameNet => C:\Program Files (x86)\QGNA\qGNA.exe
Task: {531F9E18-C366-4AAA-9E20-8D05859A457C} - System32\Tasks\Installation App Launcher => C:\Program Files (x86) (x86)\Lexmark 7600 Series\ezprint.exe [2010-02-10] (Lexmark International Inc.)
Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
Task: {5ED4D938-3805-450A-888D-B8DEE4C24A92} - System32\Tasks\{C9B77DE9-6A1C-4821-9150-5E9DEA822464} => pcalua.exe -a "C:\Users\Basti\Local Settings\Application Data\Bundled software uninstaller\biclient.exe" -c /initurl hxxp://bi.bisrv.com/:affid:/:sid:/:uid:? /affid uninstall /id uninstall /name "Bundled software uninstaller"
Task: {6131115E-E342-4ED5-BA2E-274E03E3AD03} - System32\Tasks\MATLAB R2015a Startup Accelerator => C:\Program Files\MATLAB\R2015a\bin\win64\MATLABStartupAccelerator.exe [2014-12-29] ()
Task: {65774187-F822-4405-9366-4822D1B7BB56} - System32\Tasks\{4FE8E9A0-83ED-441A-8CB2-539F94CDF074} => pcalua.exe -a C:\Users\Basti\Downloads\EvolveSetup.exe -d C:\Users\Basti\Downloads
Task: {6F3A25B2-F32B-4D54-90C7-DC55CE87C89F} - System32\Tasks\AdobeAAMUpdater-1.0-Basti-PC-Basti => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-05-25] (Adobe Systems Incorporated)
Task: {8CA2239D-3265-4137-9474-7F68939B16D3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {A5B7212F-CF00-47BD-A6B8-6AFB1673C7FE} - System32\Tasks\{17AF4C96-0ABB-4915-ABBF-64D12E75ED44} => pcalua.exe -a H:\Adobe_Photoshop_CS5_Extended-AkamaiDLM.exe -d H:\
Task: {AA49A26C-34A3-4E6F-B51A-1597E039672E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
Task: {AD6C33B2-B2D5-4DB3-885B-F850B71E16F8} - \Dealply -> Keine Datei <==== ACHTUNG
Task: {C09706A8-6289-4CBB-83AA-307E834C9348} - System32\Tasks\{F2F37F3E-65F3-4810-8851-E0B4B6BAEA81} => C:\Sierra\EE-ZDE\EE-AOC.exe [2002-08-21] ()
Task: {C3011503-2B45-43D6-8191-7E900C479FA0} - System32\Tasks\{D00EF0EA-619B-4134-97D6-7A640F11A328} => pcalua.exe -a "C:\Users\Basti\Downloads\FM13 Datensatz - Deutschland.exe" -d C:\Users\Basti\Downloads
Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc
Task: {DE3BBF04-CFC3-41EC-B711-791D41C3733B} - System32\Tasks\{7AE8198C-13CA-46CB-B46B-D22ECDC213E0} => pcalua.exe -a C:\Users\Basti\Downloads\forge-1.7.10-10.13.4.1448-1.7.10-installer-win.exe -d C:\Users\Basti\Downloads
Task: {E88A55D5-4F57-41B6-BB0C-B0893DC08821} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Dealply.job.bak => C:\Users\Basti\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ACHTUNG
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\MATLAB R2015a Startup Accelerator.job => C:\Program Files\MATLAB\R2015a\bin\win64\MATLABStartupAccelerator.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

Shortcut: C:\Users\Basti\Spiele\MC-Server_start.bat - Verknüpfung.lnk -> C:\Users\Basti\Desktop\Neuer Ordner\Server_start.bat (Keine Datei)
Shortcut: C:\Users\Basti\Spiele\MC.bat - Verknüpfung.lnk -> C:\Program Files\MC.bat ()
Shortcut: C:\Users\Basti\Spiele\Start NFS MW Mod Loader.bat - Verknüpfung.lnk -> C:\Program Files (x86)\EA GAMES\Need for Speed Most Wanted\Start NFS MW Mod Loader.bat ()

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2016-01-12 21:42 - 2013-09-03 13:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\bdmetrics.dll
2016-01-21 17:30 - 2016-01-21 17:30 - 01119064 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpbr.mdl
2016-01-21 17:30 - 2016-01-21 17:30 - 00794832 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpdsp.mdl
2016-01-21 17:30 - 2016-01-21 17:30 - 03038112 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpph.mdl
2016-01-21 17:30 - 2016-01-21 17:30 - 01648408 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttprbl.mdl
2012-09-11 20:19 - 2015-12-16 15:53 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-06-03 03:56 - 2015-06-03 03:56 - 00261864 _____ () C:\Program Files (x86)\Droid4X\Droid4XService.exe
2016-01-17 23:26 - 2015-12-16 18:34 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2012-06-08 14:13 - 2012-02-17 19:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll
2012-11-22 16:19 - 2013-10-30 19:53 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-02-11 19:21 - 2014-02-11 19:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-02-11 19:22 - 2014-02-11 19:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-02-11 19:21 - 2014-02-11 19:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2014-02-11 19:22 - 2014-02-11 19:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2015-09-23 18:43 - 2015-09-23 18:43 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2012-05-30 19:06 - 2012-05-30 19:06 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-05-30 19:06 - 2012-05-30 19:06 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-12-28 21:32 - 2015-04-24 16:40 - 00043520 _____ () C:\Users\Basti\AppData\Local\THORN\QtSolutions_Service-head.dll
2015-12-28 21:32 - 2014-08-28 10:36 - 00732160 _____ () C:\Users\Basti\AppData\Local\THORN\libGLESv2.dll
2015-12-28 21:32 - 2014-08-28 10:41 - 00856576 _____ () C:\Users\Basti\AppData\Local\THORN\platforms\qwindows.dll
2015-12-28 21:32 - 2014-08-28 10:36 - 00047104 _____ () C:\Users\Basti\AppData\Local\THORN\libEGL.dll
2016-01-17 23:26 - 2015-12-16 18:34 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-04-29 23:16 - 2015-04-29 23:16 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\acrotray.deu
2012-05-25 15:07 - 2012-03-28 21:18 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2016-01-14 11:16 - 2016-01-12 17:35 - 01590088 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libglesv2.dll
2016-01-14 11:16 - 2016-01-12 17:35 - 00087880 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libegl.dll
2015-12-21 13:52 - 2015-12-21 13:52 - 00932032 ____R () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll
2013-09-14 00:51 - 2013-09-14 00:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 00:50 - 2013-09-14 00:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2016-01-12 21:41 - 2013-09-03 13:29 - 00095088 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\antispam32\bdmetrics.dll
2015-04-29 23:15 - 2015-04-29 23:15 - 02897304 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\PDFMaker\Common\AdobePDFMakerX.dll
2015-04-29 23:16 - 2015-04-29 23:16 - 01446400 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\PDFMaker\AdobePDFMakerX.DEU
2015-11-11 02:42 - 2015-11-11 02:42 - 01045672 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00189440 _____ () C:\Program Files\Echobit\Evolve\libidn.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00047616 _____ () C:\Program Files\Echobit\Evolve\boost_thread-vc100-mt-1_46_1.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00044032 _____ () C:\Program Files\Echobit\Evolve\boost_date_time-vc100-mt-1_46_1.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00046592 _____ () C:\Program Files\Echobit\Evolve\boost_signals-vc100-mt-1_46_1.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00135168 _____ () C:\Program Files\Echobit\Evolve\boost_filesystem-vc100-mt-1_46_1.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00015360 _____ () C:\Program Files\Echobit\Evolve\boost_system-vc100-mt-1_46_1.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00611328 _____ () C:\Program Files\Echobit\Evolve\boost_regex-vc100-mt-1_46_1.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00321536 _____ () C:\Program Files\Echobit\Evolve\boost_program_options-vc100-mt-1_46_1.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00086400 _____ () C:\Program Files\Echobit\Evolve\EvolveEasyHook_32.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 38599680 _____ () C:\Program Files\Echobit\Evolve\libcef.DLL
2016-01-10 21:28 - 2016-01-10 21:28 - 00710430 _____ () C:\Program Files\Echobit\Evolve\swscale-2-evo.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00481201 _____ () C:\Program Files\Echobit\Evolve\avutil-51-evo.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 01166303 _____ () C:\Program Files\Echobit\Evolve\avformat-53-evo.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 05033711 _____ () C:\Program Files\Echobit\Evolve\avcodec-53-evo.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 38599680 _____ () C:\Program Files\Echobit\Evolve\libcef.dll
2016-01-10 21:28 - 2016-01-10 21:28 - 00874496 _____ () C:\Program Files\Echobit\Evolve\ffmpegsumo.dll
2012-03-09 16:26 - 2013-04-25 02:50 - 00108128 _____ () C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\zlib1.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\Users\Basti\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Basti\Desktop\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Basti\Downloads\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Basti\Downloads\361.43-desktop-win8-win7-winvista-64bit-international-whql.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\BnS_Lite_Installer.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\chromeinstall-8u66 (1).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\chromeinstall-8u66.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\codeblocks-13.12mingw-setup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\ComboFix.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\cwshredder.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\EvolveSetup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\FRST64.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\HijackThis.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\HijackThis_2.0.5 (1).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\HijackThis_2.0.5 (2).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\HijackThis_2.0.5.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\iFreeRecorder.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\jxpiinstall(2).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024 (1).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\mingw-get-setup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\NC-LauncherSetup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\PlayBlackDesert.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\setup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\SkypeSetup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\uTorrent (1).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\uTorrent.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\_HijackThis_2.0.5.exe:BDU
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

Da befinden sich 7865 mehr Seiten.

IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123simsen.com -> www.123simsen.com

Da befinden sich 7863 mehr Seiten.


==================== Hosts Inhalt: ==========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2016-01-21 23:13 - 00004098 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1	lmlicenses.wip4.adobe.com
127.0.0.1	lm.licenses.adobe.com
127.0.0.1	na2m-pr.licenses.adobe.com
127.0.0.1	ereg.wip3.adobe.com
127.0.0.1	ereg.wip4.adobe.com
127.0.0.1	wip.adobe.com
127.0.0.1	wip1.adobe.com
127.0.0.1	wip2.adobe.com
127.0.0.1	wip3.adobe.com
127.0.0.1	wip4.adobe.com
127.0.0.1	wwis-dubc1-vip60.adobe.com
127.0.0.1	hl2rcv.adobe.com
127.0.0.1	adobeereg.com
127.0.0.1	activate.adobe.com
127.0.0.1	practivate.adobe.com
127.0.0.1	ereg.adobe.com
127.0.0.1	activate.wip3.adobe.com
127.0.0.1	ereg.wip3.adobe.com
127.0.0.1	activate-sea.adobe.com
127.0.0.1	activate-sjc0.adobe.com
127.0.0.1	3dns.adobe.com
127.0.0.1	3dns-1.adobe.com
127.0.0.1	3dns-2.adobe.com
127.0.0.1	3dns-3.adobe.com
127.0.0.1	3dns-4.adobe.com
127.0.0.1	adobe-dns.adobe.com
127.0.0.1	adobe-dns-1.adobe.com
127.0.0.1	adobe-dns-2.adobe.com
127.0.0.1	adobe-dns-3.adobe.com
127.0.0.1	adobe-dns-4.adobe.com127.0.0.1	www.007guard.com

Da befinden sich 77 zusätzliche Einträge.


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist deaktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Inhaltsmanager-Assistent für PlayStation(R).lnk => C:\Windows\pss\Inhaltsmanager-Assistent für PlayStation(R).lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Basti^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Synchronizer => 
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: ApnUpdater => 
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AutoStartNPSAgent => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
MSCONFIG\startupreg: CD- und DVD-Sharing => "C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: EzPrint => "C:\Program Files (x86) (x86)\Lexmark 7600 Series\ezprint.exe"
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: LOLReplay Recorder => "C:\Program Files (x86)\LOLReplay\LOLRecorder.exe" -minimize
MSCONFIG\startupreg: lxdwmon.exe => "C:\Program Files (x86) (x86)\Lexmark 7600 Series\lxdwmon.exe"
MSCONFIG\startupreg: Pando Media Booster => 
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{AEB0AA6D-6C50-4812-9625-67A55EFD53FF}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{B6C925FB-AAF5-426B-B3E4-AE312A3FA526}] => (Allow) LPort=2869
FirewallRules: [{B8A05455-93A9-4D81-8C81-D3F3517D953C}] => (Allow) LPort=1900
FirewallRules: [{E8294358-232A-45E3-8825-6CF312AFF0A3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{FF42412D-60DF-4783-9856-A6786836D569}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [TCP Query User{8605D22C-C232-4D70-95DE-DF0204070B05}E:\skype\phone\skype.exe] => (Allow) E:\skype\phone\skype.exe
FirewallRules: [UDP Query User{3E24806E-72F0-4CB2-85B5-52D76EA61D9D}E:\skype\phone\skype.exe] => (Allow) E:\skype\phone\skype.exe
FirewallRules: [TCP Query User{66097FAD-DE6E-45FE-B4B5-494B7951E559}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{E44AFAA1-C985-4D4D-98C4-D1F1222E8DEC}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [{50589B4A-7714-4736-A12C-F203A0404CBD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{7BEB5529-C91A-4153-8184-940217CA9A68}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{BA05C10F-C9BD-4AAF-8CA9-1FD195EDC8AD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{9CE0C97A-8FA5-4C78-8636-3CCBF4236105}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{43F4BE84-BDF6-4A56-B305-76266D5CE186}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{944328E1-A43A-4626-AFB3-1B5EB8ED02AB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{01296CE7-D3EA-4B41-80A9-2B1A6DB946AC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{A1DFC9B1-30E8-4236-BC1B-7C29FA788E56}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe
FirewallRules: [{61452E45-4CE4-4DEC-BFBF-F8C65D483E7D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{35B97D4E-9D9B-42C9-ADFB-D6DE5CFDFD87}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{ACD23962-358A-4CF3-B3BE-C1859D1B3AC4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{9A6355D6-6CE8-4A0B-A848-6868982EB28C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{E5585DFB-2F3E-452B-974F-0659487E8AC3}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{37A64963-0E37-4E44-A6E5-544FC3B270B1}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{EB61EA23-EE2E-4D8B-9A1B-2F888ECA97EA}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{4F20E937-3A3E-484E-AF41-BCBF8F6EF15A}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{0FCC7DD0-110E-48F3-98D7-63537CE9D87C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C3BB32CF-7D2A-4B49-B0E6-C59A5363AFDB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E40CC70F-53F7-43AE-82A1-464181035FD8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{26EA374E-9D61-4AB5-BFEB-457A93CDB684}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{9D747C84-4B7C-4ABD-954F-808306C2E7DE}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{0FD22C5F-CEEC-452B-BB9B-F382C7DD3E7A}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{1316D1D9-190F-43A7-840B-E3DB02CAD839}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{F2AAF089-6789-4D58-86CA-8AF3A3014E3D}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{BF4BE5A0-D5B0-4CCE-AD02-C3926AF88D7F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{840BA19A-BE66-447C-8549-E61914FD6364}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{DA31F48E-4D65-448E-B0E5-F0F032D1A0C3}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{405839C9-B746-4857-8BEF-9440A903A334}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{7AFE82AF-470C-472B-9E42-73595DDB3C58}] => (Allow) LPort=7935
FirewallRules: [{834A5996-41C5-4FED-A7C7-29812EB211A6}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{3F1637F3-3EA7-4C2D-A98A-756F2DBA7161}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{F738565D-20E7-4107-B64A-A15741CD7DE5}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{48144A4D-6B79-4058-9A48-20772876CB90}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{CFE4DF24-5F00-49FB-A863-530E7E9E1505}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{C19442D6-0261-4459-BD4F-6C8C4CC36C6E}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{BDDB4C68-8452-43E0-B3EB-33E014E862F2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe
FirewallRules: [{2B9602D7-E869-44EB-A586-73EAFF8A1523}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe
FirewallRules: [{8CA1C522-931E-45DF-A8B2-1496E2233AF9}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe
FirewallRules: [{ED332F7D-C2B1-4A8E-A563-FB8F8ABD00B1}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe
FirewallRules: [{706DA564-C0DD-4259-BE64-9504CA32903B}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe
FirewallRules: [{077438E0-8148-47F5-82EA-7A23153241E2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe
FirewallRules: [{AFB4F4A8-A984-40B8-AC0A-A581DBC8D0AA}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe
FirewallRules: [{A7BBF6CC-173E-4F92-B1A5-91533FE68EBE}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe
FirewallRules: [{2525E825-F9A6-4F85-A5A8-E97D5C3A4FDA}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{4AE9836A-57F4-4F10-9FE2-079DCE1A74C5}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{782775DE-583A-4E84-BCDF-8766C9907708}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe
FirewallRules: [{A6DE10C4-6169-4354-8A5F-1D6EF61C649A}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe
FirewallRules: [{360EE568-4F95-4925-AD87-D0D8629D8E94}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe
FirewallRules: [{E834066F-C3C5-4C49-A039-7AE32F6BA807}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe
FirewallRules: [TCP Query User{56C7AB21-BCCD-4F5C-8D52-74B395884B9E}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Block) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [UDP Query User{C47A71CD-4BB7-4FF9-BC0F-829EE83DFA87}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Block) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [{27133C47-866D-499D-B8E0-62C8175B8D81}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{FC824A4A-084E-4949-A0FE-00036DCD3AE0}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe
FirewallRules: [{2BF78D21-34D1-407F-BB1E-863E83E76E74}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe
FirewallRules: [{ED6FAA94-A8B5-45A3-9D07-B568068532D2}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\RemoteInstallMacOSX.exe
FirewallRules: [{6A55489F-AC43-4B82-8B6F-10620D1D28BB}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\RemoteInstallMacOSX.exe
FirewallRules: [{E744BA9D-77AC-4A44-B1CC-53F9C01E70F8}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E7C457CF-0B0B-42A7-A0D2-F942BD081C8C}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{14972E55-7D37-4D27-AE30-652C230045BE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{B9FBD964-5AD5-4909-B65A-DCB842B4B050}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{FE2B4338-50A1-42E3-BC70-F33D927CCA59}C:\users\basti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\basti\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{FC27B11D-372E-4D59-9F85-5B7E0630AD9C}C:\users\basti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\basti\appdata\roaming\spotify\spotify.exe
FirewallRules: [{77FEF5E3-A2C3-4AAF-B6F3-2944DB24AEB0}] => (Block) C:\users\basti\appdata\roaming\spotify\spotify.exe
FirewallRules: [{3C5A270E-15A2-4014-84D7-4C2B82BFD115}] => (Block) C:\users\basti\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0BEC205D-E089-4F21-9A05-312B20B704F9}] => (Allow) E:\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{F2C2E9A0-14A3-46AB-B79D-0489399BAFF8}] => (Allow) E:\Dragon Nest Europe\DragonNest.exe
FirewallRules: [TCP Query User{6B0C01E5-C627-4A7C-8E52-D90D5FA2D12F}C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe] => (Allow) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe
FirewallRules: [UDP Query User{49CAF30B-96F6-46AF-87DC-7C846CEE1567}C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe] => (Allow) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe
FirewallRules: [{DBB21750-4C66-4A32-BDE8-9BD9B599C09C}] => (Block) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe
FirewallRules: [{E8872357-7E0F-4009-960C-A6CA99D08262}] => (Block) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe
FirewallRules: [{D90E4B67-C6C8-4C6D-B779-95A0AF0549FB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{01D550ED-529B-4EBD-A526-FF7C61C99B38}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{3AEC5918-0F0F-446C-814F-BED80BA8D615}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{A19FAE1B-8FC4-47A2-AF99-615CB1632989}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{E7C041D1-61AF-47DC-87FF-C4102F7E96AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ.exe
FirewallRules: [{29261903-A601-474E-B969-353B616287C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ.exe
FirewallRules: [{F3F0B184-0050-4CC7-A11F-2FF10347E4E1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{B75523F0-6DFC-4C2E-88DF-3A853D1A7A1E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{3BAF1F78-0DC1-4410-88A6-ACFE28FAADD8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{63076B8D-F269-449B-BF26-999899FB5637}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{092EAFF9-F1B8-492E-8A93-FCDED7F6F01A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{2FE6D278-7786-4902-A270-0562F93891F8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{5BF2665B-F8A2-448B-A8B1-166D603E24FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{589C5ED7-3E1B-4004-A20E-66EEB891C562}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{C0F3EDDA-BD33-4854-B4D0-75DD8675C224}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{6D26D78C-E034-449D-ADBE-E29E44D2F37A}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{4442C690-D7E9-4B5F-A25E-521E36417F40}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{5D891812-49CD-43AE-B7EE-B27C96C7C7B2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [TCP Query User{91BF4BE0-EB25-44AD-ADB9-36F1E34B317B}C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe] => (Allow) C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe
FirewallRules: [UDP Query User{A4A79727-54EA-44D0-948D-F9DFAEFDAF0F}C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe] => (Allow) C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe
FirewallRules: [{68D3CDC7-D1F8-4273-842F-B17E7C4E86CF}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{A4642A64-FFB6-42F5-9EF8-A3F257E61B1C}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{C5272483-76CE-4BD8-8646-C6EC5F1CF1C6}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{8B4C1C15-86C8-4AD4-B190-9C08CFFD95D9}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{25ADDED9-C807-4172-90A1-C3AC964FE326}] => (Allow) %ProgramFiles% (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{FA35EA0D-AF61-4537-97B0-E60A84D561B2}] => (Block) %USERPROFILE%\Downloads\Test\Watch.Dogs.Deluxe.Edition.Cracked-3DM\bin\watch_dogs.exe
FirewallRules: [{5B1D4735-6FF7-4A19-A18C-5AF5E9D2714F}] => (Block) E:\Program Files (x86)\Tropico 5\Tropico5.exe
FirewallRules: [{794319B8-A91B-4DD1-93BF-25E9DA084189}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\FaxApplications.exe
FirewallRules: [{8C20186C-0132-442A-A451-0EA1015D8F23}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\DigitalWizards.exe
FirewallRules: [{66CB480A-D5FC-4F94-AC12-477B0638B0DA}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\SendAFax.exe
FirewallRules: [{CEFFC8B8-7E7F-4597-9668-0026E35B6E55}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\DeviceSetup.exe
FirewallRules: [{359830D2-A868-402B-B585-B569FB7EB3C0}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe
FirewallRules: [{5EBF68FE-225D-4A50-A647-5F055D3EFEDE}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{C82C70BC-BCA0-4975-B46C-17D9C4A9BEA5}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{CE760193-0C9F-4B96-AB09-26F0C191308E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{071BE61C-F3E5-49E7-A3A4-56EA1EB407CA}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe
FirewallRules: [{D1797CFD-02F7-4544-9D54-7A0B951C5482}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe
FirewallRules: [{7A5E1850-EC46-4F46-85DA-54540ACBDDB2}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [{996983E1-D0BE-4FCD-8BBA-E257667941C5}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [TCP Query User{B8D07668-448E-487F-969A-93BD616D78E5}C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe
FirewallRules: [UDP Query User{662D666A-2E35-412E-A419-095CFC37F1C1}C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe
FirewallRules: [{F2FC4E0B-76F9-4320-853A-51889938D513}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe
FirewallRules: [{FDFA8CE5-7B10-4F85-911C-B56695D7EAE2}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe
FirewallRules: [TCP Query User{5FC2F183-3E0D-440A-A0CD-69E7A331D073}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{E8183AD0-A3B5-4509-A899-446F3BC09495}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{041EF0F9-A7FE-4004-805D-A9BCE9B87258}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{33544488-16F1-42C3-A81A-1C1511AF6668}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe
FirewallRules: [{031849CA-EB99-4088-9CCB-4C258DD89942}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe
FirewallRules: [{8E346669-071F-4C46-A819-6CD8A7CC5FEA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe
FirewallRules: [{B1A7B880-0EB6-4823-9D86-9FFCF83A3F58}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{E58C066A-3E3D-42F8-BFA8-E9BAE65EB7E4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{B991969E-6CD9-460C-A810-EDD7ADA4E68B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{04971D38-5D33-4E01-B3BB-219E0093C7BA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{89F1D3EE-7834-42BC-9700-3D25BCBC56B3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C3FAE89B-1D4E-4D46-8A61-50158D229C9A}C:\program files\matlab\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2015a\bin\win64\matlab.exe
FirewallRules: [UDP Query User{AF96BE9C-1D63-45FA-A019-CBD69EC2ECFD}C:\program files\matlab\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2015a\bin\win64\matlab.exe
FirewallRules: [{79EDEFCB-DED5-415A-A2D4-954E3A07B2BC}] => (Block) C:\program files\matlab\r2015a\bin\win64\matlab.exe
FirewallRules: [{5D435D29-34E0-4F66-BC06-329AC4E22143}] => (Block) C:\program files\matlab\r2015a\bin\win64\matlab.exe
FirewallRules: [TCP Query User{E16785C3-4F1F-43DB-8569-7DAA1BB4939E}C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [UDP Query User{F8F7CE09-1BD6-40C2-BD53-B90E1779DF9E}C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{56E46A08-F7EC-4BCD-99E7-67C16D04072B}] => (Block) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{BAE9B81F-B180-450C-AAC2-90F85855CDCF}] => (Block) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [TCP Query User{960BAFE7-B279-4687-9762-B617276B2508}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [UDP Query User{3DD91B0E-AD44-4ACC-A86F-E3FFDF965641}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{1498F3EC-1538-4C3F-9EAA-03B8D867AF38}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{91101AFB-5036-4D1E-9DE3-115D13D0A94C}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [TCP Query User{DB4711FF-7CE3-4C3F-A9E2-C814CAE24E25}C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe
FirewallRules: [UDP Query User{2FCA9D68-E3E0-464D-B786-8D9728A834FD}C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe
FirewallRules: [{6D6BEFEA-892A-461E-8E30-BC2DD8A8A9F1}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe
FirewallRules: [{C30C8168-C7A9-411E-B51C-B21F3F9F16B2}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe
FirewallRules: [TCP Query User{83036536-6209-4CB8-B628-DA794E18A8DE}C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe
FirewallRules: [UDP Query User{A139B970-9425-43E7-BDB6-4E22B2345171}C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe
FirewallRules: [{700BBAB0-6C40-4AF2-BA97-8C696AC63CB0}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe
FirewallRules: [{F11DDB0B-43A6-49B1-B7D0-5A8066177317}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe
FirewallRules: [TCP Query User{BB97726B-726D-4884-B231-36F1A90474C5}C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe
FirewallRules: [UDP Query User{F0AFB84E-50C4-44F0-92F2-B67D99132739}C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe
FirewallRules: [{00EB906D-649C-4861-8C9D-34882AA42F23}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe
FirewallRules: [{8CA6EF79-B664-454D-B766-431FFD0DF4B7}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe
FirewallRules: [{A6D6D585-8623-4CE1-BAAD-351E922FB928}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{C2585F8A-885F-42B0-862D-ABAE50F00A1F}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe
FirewallRules: [{BBFEFEDB-1230-42AF-A40A-7968C2540868}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe
FirewallRules: [{077A8C17-D8B6-424C-8B93-106296089B81}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe
FirewallRules: [{E873F7D5-09B2-46FE-9BB0-FC73E216E95C}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe
FirewallRules: [TCP Query User{82994F2D-DF04-4504-9058-CD0ECF2CB746}C:\users\basti\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\basti\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [UDP Query User{7A4E61E8-A717-4843-BD4D-C110383BB73B}C:\users\basti\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\basti\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [TCP Query User{705B4041-A30C-4268-8F74-2563047066DB}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [UDP Query User{0C868E8E-EF56-47E5-9E9E-6416F680CADC}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [{A7EF31CF-8B85-49A0-AA01-137354F2D690}] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [{0A27EF24-7F72-4DA8-96AA-0602EE1512E5}] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [{6A3A3F01-F7A8-4478-BCE1-A786958317D4}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{AF0213A2-AC56-4328-AC32-39E8FB0880D0}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [TCP Query User{7C58B92D-4076-4983-AF12-2E3D4EE31460}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [UDP Query User{43725424-2FA4-4C68-A7C6-AE4D1E43ABD4}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{C5AE2AAD-ACB2-4E63-BC67-B6FA715C0461}] => (Block) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{50A441D2-4782-462D-AEDA-5999E5B5CED0}] => (Block) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{798DF15F-3FB2-4BF3-A2FC-DF8A03AECE4C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C34618EC-DBF5-490C-AF1D-DF67C2E6D049}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{A4A0EC4B-C983-4968-9F2D-3302F4F92661}C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe] => (Allow) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe
FirewallRules: [UDP Query User{A4AAC983-1616-4AB4-8AD2-3D6AFF5356D7}C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe] => (Allow) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe
FirewallRules: [{06F93520-1969-4A3A-8192-EA0B59554B6E}] => (Block) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe
FirewallRules: [{F423C64F-ED88-4412-9950-D47215E34DBB}] => (Block) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe
FirewallRules: [{7773F1CF-7D07-444E-9F8C-D57EEBADC678}] => (Allow) C:\Users\Basti\Downloads\PlayBlackDesert.exe
FirewallRules: [{A6016ED8-3344-4278-8690-1A83D5005216}] => (Allow) C:\Users\Basti\Downloads\PlayBlackDesert.exe
FirewallRules: [{C52C2134-609E-4B7E-B36A-3EADD6F8A190}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe
FirewallRules: [{238E1164-63F1-46B6-AD8F-0CC27C8619BA}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe
FirewallRules: [{C96E8D7E-8DE5-4FD3-85C1-CF41AE855BA6}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe
FirewallRules: [{22687CF4-7DE2-4EA1-8698-5586C8BA5CE2}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe
FirewallRules: [{E1DD1465-3FC5-4683-9970-D29CF3F37977}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
FirewallRules: [{A1F50892-915B-4F15-8E2B-23EC7CCCA0AE}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe
FirewallRules: [TCP Query User{D47A2608-0668-439F-BD5D-3F91C39914AB}C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{F79027D7-71EA-4E9B-A204-126AE06D6F0B}C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe
FirewallRules: [{25BF71AC-A7D7-455F-909D-072BE2A7890D}] => (Block) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe
FirewallRules: [{56497540-DDF4-4F39-97B8-427A74C3F8EB}] => (Block) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe
FirewallRules: [{C92E8A48-A808-4C74-8216-0AF4284CF939}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\PublicLauncher.exe
FirewallRules: [{FFB5C658-D2AA-45C6-90F8-83CC5523B319}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\PublicLauncher.exe
FirewallRules: [{9E2CB54A-70ED-4A4E-A8BD-F7E24A1E8A57}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\MQELDiagnostics.exe
FirewallRules: [{00ED0974-C580-4FFD-A091-BA3BFBEC7AC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\MQELDiagnostics.exe
FirewallRules: [TCP Query User{5197AE62-CE7D-4AA2-B80F-B5F444D5BFA7}C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [UDP Query User{A0DC3AE3-67CD-46C7-ABB1-F7B625700ACC}C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [{5C48AC52-2639-4854-A883-55938500DD89}] => (Block) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [{F39D5120-EA60-4023-8F52-E21E2020037B}] => (Block) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [{571F6C7C-2EFF-4F40-BB56-2654CCAFC1C2}] => (Allow) C:\Program Files\Echobit\Evolve\EvoSvc.exe
FirewallRules: [{450EC6E1-77C0-43E2-9A68-1750427FB700}] => (Allow) C:\Program Files\Echobit\Evolve\EvolveClient.exe
FirewallRules: [{3FFDEB63-D938-43B8-A52B-A79A42CE5867}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{7759388F-4EB9-47C8-905A-89153DD9989C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{90246421-2C2E-499B-A5B5-69F2DEB1E1F7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{DF9CE38A-4A6C-48B5-9157-3B60D3673EC7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{4EED09D9-F074-4E5F-8F6B-04CB10A69337}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{3DC9517A-F886-44F5-AF92-5EE0EF4B3B9A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe

==================== Wiederherstellungspunkte =========================

21-01-2016 14:26:57 Entfernt Blade & Soul
21-01-2016 14:33:54 Installiert Blade & Soul

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (01/21/2016 02:28:47 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (01/21/2016 02:14:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/21/2016 01:25:41 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (01/21/2016 01:11:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/21/2016 10:45:54 AM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (01/21/2016 10:31:30 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/21/2016 09:38:26 AM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (01/21/2016 09:23:47 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/20/2016 09:46:05 AM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (01/20/2016 09:33:44 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


Systemfehler:
=============
Error: (01/21/2016 11:58:36 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.

Error: (01/21/2016 11:57:52 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.

Error: (01/21/2016 11:57:52 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.

Error: (01/21/2016 11:57:52 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.

Error: (01/21/2016 11:57:31 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.

Error: (01/21/2016 03:23:30 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10.

Error: (01/21/2016 02:14:23 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (01/21/2016 01:48:09 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147467243.

Error: (01/21/2016 01:48:09 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16392) (User: NT-AUTORITÄT)
Description: Fehler beim Starten des BITS-Dienstes. Fehler: 2147500053.

Error: (01/21/2016 01:12:05 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)


CodeIntegrity:
===================================
  Date: 2016-01-18 10:27:54.004
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2016-01-18 10:27:53.954
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-30 14:58:14.199
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.CP6452" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-30 14:58:14.135
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.CP6452" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 13:19:19.901
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.sA6316" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 13:19:19.826
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.sA6316" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 13:07:59.521
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.AF5708" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 13:07:59.460
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.AF5708" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 00:11:40.229
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.yT4184" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 00:11:40.169
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.yT4184" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Prozentuale Nutzung des RAM: 74%
Installierter physikalischer RAM: 8146.98 MB
Verfügbarer physikalischer RAM: 2080.05 MB
Summe virtueller Speicher: 14287.19 MB
Verfügbarer virtueller Speicher: 6894.3 MB

==================== Laufwerke ================================

Drive c: (Win7HPx64) (Fixed) (Total:465.76 GB) (Free:38.61 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)]
Drive d: (MUNZ_2012) (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS
Drive e: (SAMSUNG) (Fixed) (Total:931.28 GB) (Free:313.13 GB) FAT32

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4E7DE8CA)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: C3178030)
Partition 1: (Active) - (Size=931.5 GB) - (Type=0C)

==================== Ende von Addition.txt ============================
         
--- --- ---


Malwarebyte

Code:
ATTFilter
<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2016/01/21 12:15:47 +0100</date>
<logfile>mbam-log-2016-01-21 (12-15-46).xml</logfile>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.2.0.1024</version>
<malware-database>v2016.01.21.01</malware-database>
<rootkit-database>v2016.01.20.01</rootkit-database>
<license>free</license>
<file-protection>disabled</file-protection>
<web-protection>disabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<hostname>BASTI-DESKTOP</hostname>
<ip>192.168.178.25, *****</ip>
<osversion>Windows 7 Service Pack 1</osversion>
<arch>x64</arch>
<username>Basti</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>threat</type>
<result>completed</result>
<objects>538955</objects>
<time>3017</time>
<processes>0</processes>
<modules>0</modules>
<keys>9</keys>
<values>2</values>
<datas>0</datas>
<folders>10</folders>
<files>61</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>enabled</filesystem>
<archives>enabled</archives>
<rootkits>disabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<heuristics>enabled</heuristics>
<pup>enabled</pup>
<pum>enabled</pum>
</options>
<items>
<key><path>HKLM\SOFTWARE\CLASSES\APPID\{608D3067-77E8-463D-9084-908966806826}</path><vendor>PUP.Optional.Incredibar</vendor><action>success</action><hash>e461a19bc2d744f21fa31577ab57bd43</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{608D3067-77E8-463D-9084-908966806826}</path><vendor>PUP.Optional.Incredibar</vendor><action>success</action><hash>e461a19bc2d744f21fa31577ab57bd43</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{608D3067-77E8-463D-9084-908966806826}</path><vendor>PUP.Optional.Incredibar</vendor><action>success</action><hash>e461a19bc2d744f21fa31577ab57bd43</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</path><vendor>Adware.1ClickDownloader</vendor><action>success</action><hash>75d0f349e2b78caa219f85079072c838</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</path><vendor>Adware.1ClickDownloader</vendor><action>success</action><hash>75d0f349e2b78caa219f85079072c838</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</path><vendor>Adware.1ClickDownloader</vendor><action>success</action><hash>75d0f349e2b78caa219f85079072c838</hash></key>
<key><path>HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Dealply</path><vendor>PUP.Optional.DealPly</vendor><action>delete-on-reboot</action><hash>e95c0c300099bc7a0c612c9134cfeb15</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\kekfoodhbhpjhjcdecjngamojfhknooc</path><vendor>PUP.Optional.Amonetize</vendor><action>success</action><hash>b68fff3d316866d030e3aa052ed5ca36</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111491187}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>ab9a2517a1f880b6961bebd1c3403cc4</hash></key>
<value><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111491187}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>PC Speed Up Extension-bg.exe</valuedata><hash>ab9a2517a1f880b6961bebd1c3403cc4</hash></value>
<value><path>HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS</path><valuename>ntfdsaftsfdfdxx@mozilla.org</valuename><vendor>PUP.Optional.Amonetize</vendor><action>success</action><valuedata>C:\Users\Basti\AppData\Roaming\iPumper\extension_firefox.xpi</valuedata><hash>370eac908d0cfc3a0115b4fbd92a847c</hash></value>
<folder><path>C:\Users\Basti\AppData\Roaming\OpenCandy</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ac99023aa6f36dc95e48534662a042be</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ac99023aa6f36dc95e48534662a042be</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\components</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\Dealply</path><vendor>PUP.Optional.DealPly</vendor><action>success</action><hash>e56096a6930638fe7a2e555bb25044bc</hash></folder>
<folder><path>C:\Users\Basti\AppData\Roaming\Dealply\UpdateProc</path><vendor>PUP.Optional.DealPly</vendor><action>success</action><hash>e56096a6930638fe7a2e555bb25044bc</hash></folder>
<file><path>C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35\LatestDLMgr.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>3f065ae2d2c786b078326dc854ad9a66</hash></file>
<file><path>C:\Windows\hidcon.exe</path><vendor>Trojan.Agent.Drop</vendor><action>success</action><hash>d273ef4d4257c2742021cc7755adbb45</hash></file>
<file><path>C:\Windows\System32\Tasks\Dealply</path><vendor>PUP.Optional.DealPly</vendor><action>success</action><hash>65e088b48118d75fb6a7c3fac53ea060</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\logs.dat</path><vendor>Backdoor.Bifrose.Trace</vendor><action>success</action><hash>01440a32445596a0b33fe0131de613ed</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35\LinkuryYAHOO_RBCB_p3v3.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ac99023aa6f36dc95e48534662a042be</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\chrome.manifest</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\install.rdf</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\components\FFDisp.dll</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\delta.css</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\delta.xul</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\dpk.htm</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\hlprs.js</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\loader.xul</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\mtstart.js</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\serp.js</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\tmplt.js</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\arwDwn.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\closeo.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\help_16.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\home.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\icon_seperator.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\logo.PNG</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\privecy_16_hot.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\sign.jpg</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\specialoffer.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\tellafriend.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\uninstall.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ae.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\bg.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ch.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\cn.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\cz.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\de.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\eg.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\en.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\es.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\fr.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\gr.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\he.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\il.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\it.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ja.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\jp.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\nl.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\no.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\pl.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\pt.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ro.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ru.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\sa.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\se.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\sv.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\tr.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ua.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\us.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\manifest.mf</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\zigbert.rsa</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\zigbert.sf</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Dealply\UpdateProc\config.dat</path><vendor>PUP.Optional.DealPly</vendor><action>success</action><hash>e56096a6930638fe7a2e555bb25044bc</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js</path><vendor>PUP.Optional.Babylon</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.newTab&quot;, true);</baddata><gooddata></gooddata><hash>90b58fad4b4e0531af323da4e420a35d</hash></file>
<file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js</path><vendor>PUP.Optional.Babylon</vendor><action>replaced</action><baddata>rences

/* Do not edit this file.
 *
 * If you make changes to this file while the application is running,
 * the changes will be overwritten wh</baddata><gooddata></gooddata><hash>3d08023ad7c289ad9a47fce5a2628a76</hash></file>
</items>
</mbam-log>
         
__________________

Alt 22.01.2016, 09:11   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Zitat:
C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe]
Lesestoff:
Illegale Software: Cracks, Keygens und Co

Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html

Es geht weiter wenn du alles Illegale entfernt hast.

Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 22.01.2016, 09:59   #5
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Sry
Des hab ich vergessen zu löschen.
Werde sofort alles beseitigen wenn ich wieder zu Hause bin.

Soll ich danach nochmal einen bestimmten Scan laufen lassen?


Alt 22.01.2016, 10:58   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Das Log von Malwarebytes richtig posten. Im TXT Format. XML kann doch keiner lesen.
__________________
--> Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam

Alt 22.01.2016, 13:28   #7
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Code von Malwarebytes in TXT-form

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 21.01.2016
Suchlaufzeit: 12:15
Protokolldatei: malwarebytes.txt
Administrator: Ja

Version: 2.2.0.1024
Malware-Datenbank: v2016.01.21.01
Rootkit-Datenbank: v2016.01.20.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Basti

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 538955
Abgelaufene Zeit: 50 Min., 17 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 9
PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\APPID\{608D3067-77E8-463D-9084-908966806826}, In Quarantäne, [e461a19bc2d744f21fa31577ab57bd43], 
PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{608D3067-77E8-463D-9084-908966806826}, In Quarantäne, [e461a19bc2d744f21fa31577ab57bd43], 
PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{608D3067-77E8-463D-9084-908966806826}, In Quarantäne, [e461a19bc2d744f21fa31577ab57bd43], 
Adware.1ClickDownloader, HKLM\SOFTWARE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, In Quarantäne, [75d0f349e2b78caa219f85079072c838], 
Adware.1ClickDownloader, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, In Quarantäne, [75d0f349e2b78caa219f85079072c838], 
Adware.1ClickDownloader, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, In Quarantäne, [75d0f349e2b78caa219f85079072c838], 
PUP.Optional.DealPly, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Dealply, Löschen bei Neustart, [e95c0c300099bc7a0c612c9134cfeb15], 
PUP.Optional.Amonetize, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\kekfoodhbhpjhjcdecjngamojfhknooc, In Quarantäne, [b68fff3d316866d030e3aa052ed5ca36], 
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111491187}, In Quarantäne, [ab9a2517a1f880b6961bebd1c3403cc4], 

Registrierungswerte: 2
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111491187}|AppName, PC Speed Up Extension-bg.exe, In Quarantäne, [ab9a2517a1f880b6961bebd1c3403cc4]
PUP.Optional.Amonetize, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|ntfdsaftsfdfdxx@mozilla.org, C:\Users\Basti\AppData\Roaming\iPumper\extension_firefox.xpi, In Quarantäne, [370eac908d0cfc3a0115b4fbd92a847c]

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 10
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy, In Quarantäne, [ac99023aa6f36dc95e48534662a042be], 
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35, In Quarantäne, [ac99023aa6f36dc95e48534662a042be], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\components, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.DealPly, C:\Users\Basti\AppData\Roaming\Dealply, In Quarantäne, [e56096a6930638fe7a2e555bb25044bc], 
PUP.Optional.DealPly, C:\Users\Basti\AppData\Roaming\Dealply\UpdateProc, In Quarantäne, [e56096a6930638fe7a2e555bb25044bc], 

Dateien: 61
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35\LatestDLMgr.exe, In Quarantäne, [3f065ae2d2c786b078326dc854ad9a66], 
Trojan.Agent.Drop, C:\Windows\hidcon.exe, In Quarantäne, [d273ef4d4257c2742021cc7755adbb45], 
PUP.Optional.DealPly, C:\Windows\System32\Tasks\Dealply, In Quarantäne, [65e088b48118d75fb6a7c3fac53ea060], 
Backdoor.Bifrose.Trace, C:\Users\Basti\AppData\Roaming\logs.dat, In Quarantäne, [01440a32445596a0b33fe0131de613ed], 
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35\LinkuryYAHOO_RBCB_p3v3.exe, In Quarantäne, [ac99023aa6f36dc95e48534662a042be], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\chrome.manifest, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\install.rdf, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\components\FFDisp.dll, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\delta.css, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\delta.xul, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\dpk.htm, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\hlprs.js, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\loader.xul, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\mtstart.js, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\serp.js, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\tmplt.js, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\arwDwn.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\closeo.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\help_16.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\home.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\icon_seperator.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\logo.PNG, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\privecy_16_hot.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\sign.jpg, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\specialoffer.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\tellafriend.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\uninstall.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ae.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\bg.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ch.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\cn.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\cz.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\de.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\eg.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\en.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\es.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\fr.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\gr.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\he.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\il.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\it.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ja.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\jp.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\nl.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\no.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\pl.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\pt.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ro.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ru.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\sa.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\se.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\sv.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\tr.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ua.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\us.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\manifest.mf, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\zigbert.rsa, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\zigbert.sf, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], 
PUP.Optional.DealPly, C:\Users\Basti\AppData\Roaming\Dealply\UpdateProc\config.dat, In Quarantäne, [e56096a6930638fe7a2e555bb25044bc], 
PUP.Optional.Babylon, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTab", true);), Ersetzt,[90b58fad4b4e0531af323da4e420a35d]
PUP.Optional.Babylon, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js, Gut: (), Schlecht: (rences

/* Do not edit this file.
 *
 * If you make changes to this file while the application is running,
 * the changes will be overwritten wh), Ersetzt,[3d08023ad7c289ad9a47fce5a2628a76]

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         

Alt 22.01.2016, 13:30   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 22.01.2016, 17:45   #9
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



AdwCleaner:


Code:
ATTFilter
# AdwCleaner v5.030 - Bericht erstellt am 22/01/2016 um 17:04:37
# Aktualisiert am 17/01/2016 von Xplode
# Datenbank : 2016-01-19.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Basti - BASTI-DESKTOP
# Gestartet von : C:\Users\Basti\Desktop\AdwCleaner_5.030.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum

***** [ Dienste ] *****


***** [ Ordner ] *****

[-] Ordner Gelöscht : C:\Program Files (x86)\Winamp Toolbar
[-] Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\AskTB
[-] Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
[-] Ordner Gelöscht : C:\Program Files (x86)\Common Files\Software Update Utility
[-] Ordner Gelöscht : C:\ProgramData\Winamp Toolbar
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Local\Winamp Toolbar
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Booster
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\dvdvideosoftiehelpers
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iPumper
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\Extensions\staged\EFGLQA@78ETGYN-0W7FN789T87.COM
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\Extensions\sparpilot@sparpilot.com
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\staged\EFGLQA@78ETGYN-0W7FN789T87.COM
[-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\sparpilot@sparpilot.com

***** [ Dateien ] *****

[-] Datei Gelöscht : C:\END
[-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
[-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt
[-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
[-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt
[-] Datei Gelöscht : C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\npnkeeiehehhefofiekoflfedgehcdhl

***** [ DLLs ] *****


***** [ Verknüpfungen ] *****


***** [ Aufgabenplanung ] *****


***** [ Registrierungsdatenbank ] *****

[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F20F11FD-203E-45A9-B7BB-AFC1B4FEA7A6}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{507591C2-2F4E-46A7-92D6-E6CFF82E5F26}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A8C2644D-BF72-4A89-A88C-D85F565F2F46}
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[-] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
[-] Schlüssel Gelöscht : HKCU\Software\BI
[-] Schlüssel Gelöscht : HKCU\Software\Escolade
[-] Schlüssel Gelöscht : HKCU\Software\Headlight
[-] Schlüssel Gelöscht : HKCU\Software\OCS
[-] Schlüssel Gelöscht : HKCU\Software\Softonic
[-] Schlüssel Gelöscht : HKCU\Software\Winamp Toolbar
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Winamp Toolbar
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{177586E7-E42E-4F38-83D1-D15B4AF5B714}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\7E685771E24E83F4381D1DB5A45F7B41
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\7E685771E24E83F4381D1DB5A45F7B41
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E685771E24E83F4381D1DB5A45F7B41
[-] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C6CE0053-87D1-4C2C-9DBF-738685826369}

***** [ Internetbrowser ] *****

[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("browser.search.defaultenginename", "Ask.com");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("browser.search.order.1", "Ask.com");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("browser.search.selectedEngine", "Ask.com");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.admin", false);
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.aflt", "babsst");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.autoRvrt", "false");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.dfltLng", "en");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.excTlbr", false);
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.id", "5005731d0000000000000008cae5fc52");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.instlDay", "15746");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.instlRef", "sst");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.newTab", false);
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.prdct", "delta");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.prtnrId", "delta");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.rvrt", "false");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.smplGrp", "none");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.tlbrId", "base");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.vrsn", "1.8.10.0");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.10.014:55:22");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.vrsni", "1.8.10.0");
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\prefs.js] [Preference] Gelöscht : user_pref("pttl.menu-search-groups-tab", false);
[-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\prefs.js] [Preference] Gelöscht : user_pref("pttl.menu-search-groups-win", false);
[-] [C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : bopakagnckmlgajfccecajhnimjiiedh
[-] [C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : mkcedibhemacmilmkpndpkoidlnmgngg
[-] [C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : npnkeeiehehhefofiekoflfedgehcdhl

*************************

:: "Tracing" Schlüssel gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [14981 Bytes] ##########
         
--- --- ---




JRT

JRT Logfile:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Windows 7 Home Premium x64 
Ran by Basti (Administrator) on 22.01.2016 at 17:14:57,44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 24 

Successfully deleted: C:\ProgramData\thunder network (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Local\{2807B5C6-21F2-437F-A447-2CDE66EC162D} (Empty Folder)
Successfully deleted: C:\Users\Basti\AppData\Local\{745065C1-17A7-4617-B5CB-FC6F610C1C53} (Empty Folder)
Successfully deleted: C:\Users\Basti\AppData\Local\{7A9BA8C6-F356-4222-A711-3E1B243FEB9E} (Empty Folder)
Successfully deleted: C:\Users\Basti\AppData\Local\{CA69364C-5368-4B53-BE56-648DBB42BBF1} (Empty Folder)
Successfully deleted: C:\Users\Basti\AppData\Roaming\4930 (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Roaming\getrighttogo (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\staged (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\bingsearch.full@microsoft.com\search.xml (File) 
Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\hxxps-everywhere-eff@eff.org\chrome\locale\ru@petr1708 (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\hxxps-everywhere-eff@eff.org\chrome\locale\zh_CN.GB2312 (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\staged (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\extensions\staged (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\startpage-hxxps.xml (File) 
Successfully deleted: C:\Users\Public\thunder network (Folder) 
Successfully deleted: C:\Windows\wininit.ini (File) 
Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\34IRQKQM (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\46070FJA (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OJWNIVD8 (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OY95ZJ7K (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PMG458TI (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SKP48RWE (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YG3Y9O3X (Folder) 
Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z43XJXW4 (Folder) 



Registry: 1 

Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.01.2016 at 17:21:56,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
--- --- ---

Alt 22.01.2016, 17:48   #10
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



FRST Logfile:
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-01-2016
durchgeführt von Basti (Administrator) auf BASTI-DESKTOP (22-01-2016 17:31:38)
Gestartet von C:\Users\Basti\Desktop
Geladene Profile: Basti (Verfügbare Profile: Basti & Zocken & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Dassault Systemes) C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Program Files (x86)\Droid4X\Droid4XService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(GGS) C:\Users\Basti\AppData\Local\THORN\Thorn.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(GGS) C:\Users\Basti\AppData\Local\THORN\ThornHelper.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\antispam32\bdwtxapps.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxcr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-16] (NVIDIA Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe [1720488 2016-01-12] (Bitdefender)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-04-29] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-04-29] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-09-23] (Cisco Systems, Inc.)
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [appnhost] => C:\Users\Basti\AppData\Local\Mixesoft\AppNHost\appnhost.exe [453176 2014-08-08] (Mixesoft Project)
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [Bitdefender-Geldb�rse-Agent] => C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe [1423288 2016-01-12] (Bitdefender)
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [Spotify Web Helper] => C:\Users\Basti\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2346096 2015-12-21] (Spotify Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BdBkpFolder [2016-01-12] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk [2016-01-21]
ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{8A41A65B-D9F1-429C-8BC5-46D12DA767EE}: [DhcpNameServer] 192.168.178.1

Internet Explorer:
==================
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = 
SearchScopes: HKLM-x32 -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> DefaultScope {DF39FAF5-E2FF-4630-90A1-159FB1F73C0A} URL = hxxps://de.search.yahoo.com/search?fr=mcafee&type=C010DE91021D20141021&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://www.google.com/search?q={searchTerms}&rlz=1I7ADRA_deDE485
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {DF39FAF5-E2FF-4630-90A1-159FB1F73C0A} URL = hxxps://de.search.yahoo.com/search?fr=mcafee&type=C010DE91021D20141021&p={searchTerms}
BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2016\pmbxie.dll [2016-01-12] (Bitdefender)
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-01] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-01] (Oracle Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\pmbxie.dll [2016-01-12] (Bitdefender)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-11-01] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-10-29] (Perfect World Entertainment Inc)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-18] (Google Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-01] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2016\pmbxie.dll [2016-01-12] (Bitdefender)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\pmbxie.dll [2016-01-12] (Bitdefender)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-18] (Google Inc.)
Toolbar: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.)
DPF: HKLM {BAD4FE2C-503B-45CC-88CD-4B0574057D11} hxxp://clients.futuremark.com/calico/systeminfodeploy/FMSI_v490.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157
FF SearchEngineOrder.1: Sichere Suche
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Sichere Suche
FF Homepage: www.google.de
FF Session Restore: -> ist aktiviert.
FF Keyword.URL: hxxps://de.search.yahoo.com/search?fr=mcafee&type=C110DE91021D20141021&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-20] ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll [2014-09-01] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-01] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-20] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] ()
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll [2014-09-01] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei]
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-10-29] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: @my.com/Games -> C:\Users\Basti\AppData\Local\MyComGames\NPMyComDetector.dll [2015-09-30] (My.com, Inc)
FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Basti\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-01] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-12-09] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\searchplugins\anonymouseorg-anonym-surfen.xml [2015-11-16]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\searchplugins\McSiteAdvisor.xml [2015-11-17]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\duckduckgo-ssl-javascript-free.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\google-de-ssl.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\google-encrypted-no-personalization.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick---deutsch.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick-ssl-pictures---deutsch.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick-ssl-pictures---english.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-eng-ger.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-esp-ale.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-fra-all.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\metager2.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ssl-wikipedia-deutsch.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ssl-wikipedia-english.xml [2013-06-25]
FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\startpage-https---deutsch.xml [2013-06-25]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2015-10-29]
FF Extension: Amazon-Icon - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\amazon-icon@giga.de [2013-12-28] [ist nicht signiert]
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-06-08] [ist nicht signiert]
FF Extension: DownThemAll! - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-05-28]
FF Extension: Updated Ad Blocker for Firefox 11+ - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi [2015-05-29]
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-06-23] [ist nicht signiert]
FF Extension: HTTPS-Everywhere - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\https-everywhere-eff@eff.org [2015-08-28]
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff [2016-01-13]
FF Extension: Bing Search Engine - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\bingsearch.full@microsoft.com [2016-01-22] [ist nicht signiert]
FF Extension: Magic Actions for YouTube™ - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\jid0-UVAeBCfd34Kk5usS8A1CBiobvM8@jetpack.xpi [2015-07-30]
FF Extension: SSL Version Control - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\jid1-ZM3BerwS6FsQAg@jetpack.xpi [2015-05-27]
FF Extension: Adblock Plus - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-17]
FF Extension: Amazon-Icon - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\amazon-icon@giga.de [2013-12-28] [ist nicht signiert]
FF Extension: HTTPS-Everywhere - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\https-everywhere@eff.org [2013-07-12] [ist nicht signiert]
FF Extension: UnPlug - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\unplug@compunach.xpi [2013-05-15] [ist nicht signiert]
FF Extension: JonDoFox - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{437be45a-4114-11dd-b9ab-71d256d89593}.xpi [2013-06-28] [ist nicht signiert]
FF Extension: Cookie Monster - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{45d8ff86-d909-11db-9705-005056c00008} [2013-07-12] [ist nicht signiert]
FF Extension: NoScript - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-07-20] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-15] [ist nicht signiert]
FF Extension: ProfileSwitcher - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{fa8476cf-a98c-4e08-99b4-65a69cb4b7d4}.xpi [2013-06-25] [ist nicht signiert]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
FF HKLM\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext
FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext [2015-11-25] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-10] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF HKLM-x32\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext
FF HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome: 
=======
CHR Session Restore: Default -> ist aktiviert.
CHR Profile: C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-27]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2015-12-10]
CHR Extension: (Google Docs) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-29]
CHR Extension: (Google Drive) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (Google-Suche) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Bitdefender Wallet) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhhejlifdlcgcmogbggeomfodgklfaem [2015-12-13]
CHR Extension: (Google Tabellen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-27]
CHR Extension: (Google Docs Offline) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Click&Clean) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2015-11-02]
CHR Extension: (AdBlock) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-20]
CHR Extension: (Google Maps) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-11-27]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-27]
CHR Extension: (Click&Clean App) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-11-02]
CHR Extension: (Google Mail) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-29]
CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-10-29] (Perfect World Entertainment Inc)
R2 BBDemon; C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe [46592 2011-01-08] (Dassault Systemes) [Datei ist nicht signiert]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1145216 2015-05-26] ()
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 Droid4XService; C:\Program Files (x86)\Droid4X\Droid4XService.exe [261864 2015-06-03] () [Datei ist nicht signiert]
S3 EvoSvc; C:\Program Files\Echobit\Evolve\EvoSvc.exe [1583488 2016-01-10] (Echobit LLC)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-12-22] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7184440 2015-12-22] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-16] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-04-10] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-14] (Microsoft Corporation)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert]
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3806032 2015-10-13] (INCA Internet Co., Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-16] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-16] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-07] (Electronic Arts)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-30] ()
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [857288 2015-11-09] (Bitdefender)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5250280 2015-12-29] (SoftEther VPN Project at University of Tsukuba, Japan.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert]
R2 Thorn; C:\Users\Basti\AppData\Local\THORN\Thorn.exe [56824 2015-10-01] (GGS)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe [124488 2015-09-29] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe [1604080 2016-01-12] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1600512 2015-10-28] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [282000 2015-09-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [775424 2015-09-17] (BitDefender)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2011-11-03] (Broadcom Corporation.)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107080 2012-10-29] (BitDefender LLC)
R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [87912 2015-12-14] (BitDefender)
S3 cpuz135; kein ImagePath
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-06-08] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [21656 2016-01-10] (Echobit, LLC)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160032 2015-04-29] (BitDefender LLC)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-11-29] (Intel Corporation)
R0 ignis; C:\Windows\System32\DRIVERS\ignis.sys [271808 2015-10-22] (Bitdefender)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R1 LUMDriver; C:\Windows\system32\drivers\LUMDriver.sys [24848 2008-01-02] (IBM)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0024.sys [38432 2015-12-29] (SoftEther Corporation)
S3 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-12-16] (NVIDIA Corporation)
R2 trufos; C:\Windows\System32\DRIVERS\trufos.sys [477272 2015-06-02] (BitDefender S.R.L.)
R3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments)
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-01-22 17:31 - 2016-01-22 17:31 - 02370560 _____ (Farbar) C:\Users\Basti\Desktop\FRST64.exe
2016-01-22 17:31 - 2016-01-22 17:31 - 00040729 _____ C:\Users\Basti\Desktop\FRST.txt
2016-01-22 17:21 - 2016-01-22 17:21 - 00003521 _____ C:\Users\Basti\Desktop\JRT.txt
2016-01-22 17:13 - 2016-01-22 17:13 - 01600184 _____ (Malwarebytes) C:\Users\Basti\Desktop\JRT.exe
2016-01-22 13:41 - 2016-01-22 17:04 - 00000000 ____D C:\AdwCleaner
2016-01-22 13:35 - 2016-01-22 13:35 - 01505280 _____ C:\Users\Basti\Desktop\AdwCleaner_5.030.exe
2016-01-22 13:26 - 2016-01-22 13:26 - 00018340 _____ C:\Users\Basti\Desktop\malwarebytes.txt
2016-01-21 23:46 - 2016-01-22 17:31 - 00000000 ____D C:\FRST
2016-01-21 15:28 - 2016-01-21 15:28 - 02967888 _____ C:\Users\Basti\Desktop\Sebastian Schmitt.tif
2016-01-21 14:34 - 2016-01-21 14:34 - 00002243 _____ C:\Users\Public\Desktop\Blade & Soul.lnk
2016-01-21 14:20 - 2016-01-21 14:20 - 01611384 _____ (NCSOFT Corporation) C:\Users\Basti\Downloads\NC-LauncherSetup.exe
2016-01-21 12:15 - 2016-01-22 13:25 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-01-21 12:15 - 2016-01-21 13:14 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2016-01-21 12:15 - 2016-01-21 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2016-01-21 12:15 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-01-21 12:14 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-01-21 12:14 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-01-21 12:06 - 2016-01-21 12:15 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2016-01-21 12:06 - 2016-01-21 12:06 - 22908888 _____ (Malwarebytes ) C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024 (1).exe
2016-01-21 12:06 - 2016-01-21 12:06 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-01-20 11:02 - 2016-01-20 11:02 - 00006949 _____ C:\Users\Basti\Desktop\BnS.xml
2016-01-18 15:09 - 2016-01-18 15:10 - 00000000 ____D C:\Users\Basti\AppData\Local\CrashDumps
2016-01-18 10:42 - 2016-01-18 10:42 - 00038983 _____ C:\ComboFix.txt
2016-01-18 10:29 - 2016-01-22 17:05 - 00008451 _____ C:\bdlog.txt
2016-01-18 10:14 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2016-01-18 10:14 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2016-01-18 10:14 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2016-01-18 10:14 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2016-01-18 10:13 - 2016-01-18 10:42 - 00000000 ____D C:\Qoobox
2016-01-18 10:12 - 2016-01-18 10:40 - 00000000 ____D C:\Windows\erdnt
2016-01-17 23:28 - 2015-12-16 18:34 - 00111520 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2016-01-17 23:23 - 2015-12-16 15:39 - 00103032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-01-17 23:22 - 2015-12-16 15:53 - 00523384 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2016-01-17 23:22 - 2015-12-16 15:53 - 00075056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 42977072 _____ C:\Windows\system32\nvcompiler.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 37609080 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 31061624 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 24895792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 21122456 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 20663816 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 17561432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 17156968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 16981976 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 12334200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2016-01-17 23:16 - 2015-12-16 18:34 - 03168376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 02755704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 01915696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436143.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436143.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00938104 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00872056 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00734512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00681592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00502080 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00469144 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00423264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00416376 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00388560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00370808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00205456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2016-01-17 23:16 - 2015-12-16 18:34 - 00175368 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00069416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-01-17 23:16 - 2015-12-16 18:34 - 00050472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-01-17 23:16 - 2015-12-16 18:34 - 00039240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2016-01-17 23:12 - 2016-01-17 23:13 - 336974040 _____ (NVIDIA Corporation) C:\Users\Basti\Downloads\361.43-desktop-win8-win7-winvista-64bit-international-whql.exe
2016-01-17 23:07 - 2016-01-17 23:07 - 00003146 _____ C:\Windows\System32\Tasks\{2D1288DA-1D43-479F-8B4B-36F07394063D}
2016-01-17 23:03 - 2016-01-17 23:04 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\jxpiinstall(2).exe
2016-01-14 23:46 - 2016-01-14 23:53 - 38572508 _____ C:\Users\Basti\Desktop\intro.avi
2016-01-14 23:29 - 2016-01-14 23:34 - 00576953 _____ C:\Users\Basti\Downloads\56981f3794d73.mp4
2016-01-14 21:23 - 2016-01-21 13:12 - 00000882 _____ C:\Users\Basti\Desktop\iFree Skype Recorder.lnk
2016-01-14 21:23 - 2016-01-14 21:41 - 00000000 ____D C:\Users\Basti\Documents\iFree Skype Recorder
2016-01-14 21:23 - 2016-01-14 21:24 - 00000000 ____D C:\Users\Basti\AppData\Roaming\iFree
2016-01-14 21:23 - 2016-01-14 21:23 - 01058568 _____ C:\Users\Basti\Downloads\iFreeRecorder.exe
2016-01-14 21:23 - 2016-01-14 21:23 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iFree Skype Recorder
2016-01-14 21:23 - 2016-01-14 21:23 - 00000000 ____D C:\Program Files (x86)\iFree Skype Recorder
2016-01-13 17:26 - 2016-01-13 17:26 - 01504376 _____ (Skype Technologies S.A.) C:\Users\Basti\Downloads\SkypeSetup.exe
2016-01-13 16:55 - 2016-01-13 16:55 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\chromeinstall-8u66 (1).exe
2016-01-13 16:49 - 2015-11-01 15:59 - 00110176 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-64.dll
2016-01-13 16:49 - 2015-11-01 15:52 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-01-13 16:47 - 2016-01-13 16:47 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\chromeinstall-8u66.exe
2016-01-13 10:19 - 2015-12-12 19:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-01-13 10:19 - 2015-12-12 19:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-01-13 10:19 - 2015-12-12 19:02 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-01-13 10:19 - 2015-12-12 18:37 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-01-13 10:19 - 2015-12-12 18:36 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-01-13 10:19 - 2015-12-12 18:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-01-13 10:19 - 2015-12-12 18:10 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-01-13 10:19 - 2015-12-11 19:57 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-01-13 10:19 - 2015-12-08 22:54 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2016-01-13 10:19 - 2015-12-08 22:54 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 01325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2016-01-13 10:19 - 2015-12-08 22:54 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
2016-01-13 10:19 - 2015-12-08 22:54 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2016-01-13 10:19 - 2015-12-08 22:53 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
2016-01-13 10:19 - 2015-12-08 22:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll
2016-01-13 10:19 - 2015-12-08 22:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2016-01-13 10:19 - 2015-12-08 22:53 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2016-01-13 10:19 - 2015-12-08 22:53 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll
2016-01-13 10:19 - 2015-12-08 22:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2016-01-13 10:19 - 2015-12-08 20:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
2016-01-13 10:19 - 2015-12-08 20:07 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2016-01-13 10:19 - 2015-12-08 20:07 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll
2016-01-13 10:19 - 2015-12-08 20:06 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2016-01-13 10:19 - 2015-12-08 20:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-01-13 10:19 - 2015-12-08 20:04 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2016-01-13 10:19 - 2015-12-08 19:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2016-01-13 10:19 - 2015-12-08 19:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2016-01-13 10:19 - 2015-12-08 19:11 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
2016-01-13 10:19 - 2015-12-08 18:58 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-01-13 10:19 - 2015-11-17 02:11 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-01-13 10:19 - 2015-11-17 02:08 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-01-13 10:19 - 2015-11-17 02:08 - 00792064 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-01-13 10:19 - 2015-11-17 02:08 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-01-13 10:19 - 2015-11-17 02:08 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-01-13 10:19 - 2015-11-17 02:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-01-13 10:19 - 2015-11-16 21:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-01-13 10:19 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2016-01-13 10:19 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2016-01-13 10:19 - 2015-11-14 00:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
2016-01-13 10:19 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
2016-01-13 10:19 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
2016-01-13 10:19 - 2015-11-13 23:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe
2016-01-13 10:18 - 2015-12-30 20:08 - 05572544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-01-13 10:18 - 2015-12-30 20:08 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-01-13 10:18 - 2015-12-30 20:08 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-01-13 10:18 - 2015-12-30 20:05 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-01-13 10:18 - 2015-12-30 20:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-01-13 10:18 - 2015-12-30 20:01 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-01-13 10:18 - 2015-12-30 20:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-01-13 10:18 - 2015-12-30 19:59 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-01-13 10:18 - 2015-12-30 19:59 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-01-13 10:18 - 2015-12-30 19:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-01-13 10:18 - 2015-12-30 19:58 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-01-13 10:18 - 2015-12-30 19:58 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-01-13 10:18 - 2015-12-30 19:57 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-01-13 10:18 - 2015-12-30 19:57 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-01-13 10:18 - 2015-12-30 19:57 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-01-13 10:18 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-01-13 10:18 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-01-13 10:18 - 2015-12-30 19:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:47 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-01-13 10:18 - 2015-12-30 19:47 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-01-13 10:18 - 2015-12-30 19:44 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-01-13 10:18 - 2015-12-30 19:41 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-01-13 10:18 - 2015-12-30 19:40 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-01-13 10:18 - 2015-12-30 19:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-01-13 10:18 - 2015-12-30 19:39 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-01-13 10:18 - 2015-12-30 19:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-01-13 10:18 - 2015-12-30 19:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-01-13 10:18 - 2015-12-30 19:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-01-13 10:18 - 2015-12-30 19:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-01-13 10:18 - 2015-12-30 19:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 18:57 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-01-13 10:18 - 2015-12-30 18:50 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-01-13 10:18 - 2015-12-30 18:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-01-13 10:18 - 2015-12-30 18:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-01-13 10:18 - 2015-12-30 18:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-01-13 10:18 - 2015-12-30 18:42 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-01-13 10:18 - 2015-12-30 18:42 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-01-13 10:18 - 2015-12-30 18:41 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-01-13 10:18 - 2015-12-30 18:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-01-13 10:18 - 2015-12-30 18:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-01-13 10:18 - 2015-12-30 18:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-01-13 10:18 - 2015-12-30 18:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-01-13 10:18 - 2015-12-30 18:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-01-13 10:18 - 2015-12-30 18:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-01-13 10:18 - 2015-12-30 18:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 18:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-01-13 10:18 - 2015-12-30 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-01-13 10:18 - 2015-12-24 00:13 - 00387784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-01-13 10:18 - 2015-12-23 23:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-01-13 10:18 - 2015-12-12 19:54 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-01-13 10:18 - 2015-12-12 19:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-01-13 10:18 - 2015-12-12 19:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-01-13 10:18 - 2015-12-12 19:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-01-13 10:18 - 2015-12-12 19:15 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-01-13 10:18 - 2015-12-12 19:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-01-13 10:18 - 2015-12-12 19:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-01-13 10:18 - 2015-12-12 19:07 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-01-13 10:18 - 2015-12-12 19:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-01-13 10:18 - 2015-12-12 19:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-01-13 10:18 - 2015-12-12 19:03 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-01-13 10:18 - 2015-12-12 19:02 - 20367360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-01-13 10:18 - 2015-12-12 19:02 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-01-13 10:18 - 2015-12-12 19:02 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-01-13 10:18 - 2015-12-12 19:02 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-01-13 10:18 - 2015-12-12 18:55 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-01-13 10:18 - 2015-12-12 18:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-01-13 10:18 - 2015-12-12 18:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-01-13 10:18 - 2015-12-12 18:44 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-01-13 10:18 - 2015-12-12 18:40 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-01-13 10:18 - 2015-12-12 18:39 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-01-13 10:18 - 2015-12-12 18:37 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-01-13 10:18 - 2015-12-12 18:37 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-01-13 10:18 - 2015-12-12 18:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-01-13 10:18 - 2015-12-12 18:36 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-01-13 10:18 - 2015-12-12 18:35 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-01-13 10:18 - 2015-12-12 18:33 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-01-13 10:18 - 2015-12-12 18:31 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-01-13 10:18 - 2015-12-12 18:28 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-01-13 10:18 - 2015-12-12 18:27 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-01-13 10:18 - 2015-12-12 18:27 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-01-13 10:18 - 2015-12-12 18:27 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-01-13 10:18 - 2015-12-12 18:25 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-01-13 10:18 - 2015-12-12 18:23 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-01-13 10:18 - 2015-12-12 18:22 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-01-13 10:18 - 2015-12-12 18:21 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-01-13 10:18 - 2015-12-12 18:20 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-01-13 10:18 - 2015-12-12 18:19 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-01-13 10:18 - 2015-12-12 18:18 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-01-13 10:18 - 2015-12-12 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-01-13 10:18 - 2015-12-12 18:12 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-01-13 10:18 - 2015-12-12 18:10 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-01-13 10:18 - 2015-12-12 18:09 - 04610560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-01-13 10:18 - 2015-12-12 18:08 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-01-13 10:18 - 2015-12-12 18:06 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-01-13 10:18 - 2015-12-12 18:02 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-01-13 10:18 - 2015-12-12 18:00 - 12856320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-01-13 10:18 - 2015-12-12 18:00 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-01-13 10:18 - 2015-12-12 18:00 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-01-13 10:18 - 2015-12-12 18:00 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-01-13 10:18 - 2015-12-12 17:54 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-01-13 10:18 - 2015-12-12 17:42 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-01-13 10:18 - 2015-12-12 17:41 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-01-13 10:18 - 2015-12-12 17:38 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-01-13 10:18 - 2015-12-12 17:36 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-01-13 10:18 - 2015-12-08 22:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-01-13 10:18 - 2015-12-08 22:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-01-13 10:18 - 2015-12-08 20:07 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-01-13 10:18 - 2015-12-08 20:07 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-01-12 22:35 - 2016-01-12 22:35 - 00000000 ____D C:\Users\Basti\AppData\Local\bdch
2016-01-12 22:35 - 2016-01-12 22:35 - 00000000 ____D C:\ProgramData\bdch
2016-01-12 22:23 - 2016-01-12 22:28 - 00000000 ____D C:\Users\Basti\Wichtig
2016-01-12 21:43 - 2016-01-12 21:43 - 00000684 ____H C:\bdr-cf01
2016-01-12 21:42 - 2016-01-12 21:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2016
2016-01-12 21:41 - 2016-01-12 21:43 - 00253404 ____H C:\bdr-ld01
2016-01-12 21:41 - 2016-01-12 21:43 - 00009216 ____H C:\bdr-ld01.mbr
2016-01-12 21:41 - 2015-10-22 14:02 - 00271808 _____ (Bitdefender) C:\Windows\system32\Drivers\ignis.sys
2016-01-12 21:41 - 2015-07-15 16:13 - 49737193 ____H C:\bdr-im01.gz
2016-01-12 21:41 - 2013-08-13 12:38 - 03271472 ____H C:\bdr-bz01
2016-01-12 21:40 - 2015-06-02 14:21 - 00477272 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2016-01-12 21:40 - 2015-04-29 13:32 - 00160032 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2016-01-12 21:37 - 2016-01-12 21:37 - 09736920 _____ C:\Users\Basti\Downloads\bitdefender_windows_2268285f-b17f-4c1f-972a-438e9cf16488.exe
2016-01-12 21:27 - 2016-01-12 21:27 - 09736920 _____ C:\Users\Basti\Downloads\bitdefender_windows_752fc001-db4f-4d5a-b26f-50072841116e.exe
2016-01-12 21:24 - 2016-01-12 21:24 - 00003414 _____ C:\Windows\System32\Tasks\Bitdefender Restart ProductCfg_F5C977342AD24B62922B89BDC5ABCCD2
2016-01-10 21:28 - 2016-01-21 13:14 - 00002020 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evolve.lnk
2016-01-10 21:28 - 2016-01-21 13:14 - 00002014 _____ C:\Users\Public\Desktop\Evolve.lnk
2016-01-10 21:28 - 2016-01-10 21:28 - 00021656 _____ (Echobit, LLC) C:\Windows\system32\Drivers\evolve.sys
2016-01-10 21:28 - 2016-01-10 21:28 - 00000000 ____D C:\Program Files\Echobit
2016-01-10 21:27 - 2016-01-10 21:27 - 03258328 _____ (Echobit LLC) C:\Users\Basti\Downloads\EvolveSetup.exe
2016-01-10 21:27 - 2016-01-10 21:27 - 00003140 _____ C:\Windows\System32\Tasks\{4FE8E9A0-83ED-441A-8CB2-539F94CDF074}
2016-01-10 21:27 - 2016-01-10 21:27 - 00000000 ____D C:\Users\Basti\AppData\Local\Echobit
2016-01-10 21:27 - 2016-01-10 21:27 - 00000000 ____D C:\ProgramData\Echobit
2016-01-10 13:57 - 2016-01-10 13:57 - 00000000 ____D C:\Program Files\Common Files\INCA Shared
2016-01-10 13:57 - 2015-10-13 14:32 - 03806032 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
2016-01-10 13:57 - 2005-01-03 07:43 - 00004682 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys
2016-01-10 13:57 - 2003-07-18 22:17 - 00005174 _____ C:\Windows\SysWOW64\nppt9x.vxd
2016-01-10 12:28 - 2016-01-21 14:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCSOFT
2016-01-10 12:28 - 2016-01-21 14:34 - 00000000 ____D C:\Program Files (x86)\NCSOFT
2016-01-10 12:27 - 2016-01-21 14:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCWest
2016-01-10 12:27 - 2016-01-21 14:33 - 00000000 ____D C:\Program Files (x86)\NCWest
2016-01-10 12:26 - 2016-01-10 12:26 - 00003534 _____ C:\Users\Basti\Documents\cc_20160110_122618.reg
2016-01-10 12:26 - 2016-01-10 12:26 - 00000372 _____ C:\Users\Basti\Documents\cc_20160110_122633.reg
2016-01-10 12:25 - 2016-01-10 12:25 - 00254422 _____ C:\Users\Basti\Documents\cc_20160110_122546.reg
2016-01-10 12:03 - 2016-01-10 12:03 - 224976152 _____ (NC Interactive, LLC ) C:\Users\Basti\Downloads\BnS_Lite_Installer.exe
2016-01-09 03:35 - 2016-01-10 14:02 - 00000000 ____D C:\Users\Basti\Documents\BnS
2016-01-08 20:16 - 2016-01-08 20:16 - 00000000 ____D C:\Users\Basti\AppData\Local\BNSUpdater
2016-01-08 18:54 - 2016-01-08 18:54 - 00000000 ____D C:\Users\Basti\Downloads\BnS
2016-01-08 18:47 - 2016-01-08 18:47 - 00024161 _____ C:\Users\Basti\Downloads\playbns_client_2.torrent
2016-01-04 23:40 - 2016-01-04 23:40 - 00028578 _____ C:\Users\Basti\Downloads\malloc.exe
2016-01-04 23:40 - 2016-01-04 23:40 - 00001740 _____ C:\Users\Basti\Downloads\malloc.o
2016-01-04 23:39 - 2016-01-04 23:39 - 00002827 _____ C:\Users\Basti\Downloads\malloc.c
2016-01-04 22:15 - 2016-01-04 22:15 - 00000747 _____ C:\Users\Basti\Desktop\aufgabe5.c
2016-01-04 11:09 - 2016-01-04 11:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-01-04 00:00 - 2016-01-21 13:13 - 00000968 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\MinGW Installation Manager.lnk
2016-01-04 00:00 - 2016-01-04 00:16 - 00000000 ____D C:\MinGW
2016-01-03 23:59 - 2016-01-03 23:59 - 00086528 _____ (MinGW.org Project) C:\Users\Basti\Downloads\mingw-get-setup.exe
2016-01-03 23:52 - 2016-01-03 23:52 - 122655932 _____ C:\Users\Basti\Downloads\gcc-5.2.0.tar.gz
2016-01-03 12:00 - 2016-01-13 17:50 - 00000000 ____D C:\Users\Basti\AppData\Roaming\CodeBlocks
2016-01-03 11:59 - 2016-01-21 13:12 - 00001104 _____ C:\Users\Basti\Desktop\CodeBlocks.lnk
2016-01-03 11:59 - 2016-01-03 12:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks
2016-01-03 11:59 - 2016-01-03 12:00 - 00000000 ____D C:\Program Files (x86)\CodeBlocks
2016-01-03 11:59 - 2016-01-03 11:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks
2016-01-03 11:58 - 2016-01-03 11:59 - 102611063 _____ (The Code::Blocks Team) C:\Users\Basti\Downloads\codeblocks-13.12mingw-setup.exe
2015-12-29 00:23 - 2015-12-29 00:23 - 00038432 _____ (SoftEther Corporation) C:\Windows\system32\Drivers\Neo_0024.sys
2015-12-29 00:21 - 2016-01-21 13:14 - 00001980 _____ C:\Users\Public\Desktop\SoftEther VPN Client Manager.lnk
2015-12-29 00:21 - 2016-01-21 13:13 - 00001992 _____ C:\ProgramData\Microsoft\Windows\Start Menu\SoftEther VPN Client Manager.lnk
2015-12-29 00:21 - 2015-12-29 00:21 - 00144104 _____ (SoftEther VPN Project at University of Tsukuba, Japan.) C:\Windows\system32\vpncmd.exe
2015-12-29 00:21 - 2015-12-29 00:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftEther VPN Client
2015-12-29 00:20 - 2016-01-22 17:09 - 00000000 ____D C:\Program Files\SoftEther VPN Client
2015-12-29 00:19 - 2015-12-29 00:19 - 00000000 ____D C:\Users\Basti\Downloads\vpngate-client-2015.12.29-build-9599.134383
2015-12-29 00:17 - 2015-12-29 00:19 - 54298926 _____ C:\Users\Basti\Downloads\vpngate-client-2015.12.29-build-9599.134383.zip
2015-12-28 23:35 - 2015-12-29 00:57 - 00000000 ____D C:\Users\Basti\Documents\Black Desert
2015-12-28 23:30 - 2015-12-28 23:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Black Desert RU Patcher
2015-12-28 23:16 - 2015-12-28 23:16 - 00000000 __SHD C:\ProgramData\Info
2015-12-28 21:32 - 2016-01-22 17:09 - 00000000 ____D C:\Users\Basti\AppData\Local\THORN
2015-12-28 21:31 - 2016-01-08 15:56 - 00004296 _____ C:\Windows\System32\Tasks\GameNet
2015-12-28 21:31 - 2015-12-28 21:31 - 00000000 ____D C:\Users\Basti\AppData\Local\Vebanaul
2015-12-28 21:24 - 2015-12-28 21:24 - 04363099 _____ C:\Users\Basti\Downloads\setup.exe

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-01-22 17:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2016-01-22 17:19 - 2009-07-14 05:45 - 00032080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-22 17:19 - 2009-07-14 05:45 - 00032080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-22 17:16 - 2012-05-26 17:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Skype
2016-01-22 17:15 - 2015-04-17 22:24 - 00000546 ____H C:\Windows\Tasks\MATLAB R2015a Startup Accelerator.job
2016-01-22 17:15 - 2012-05-26 17:22 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-22 17:09 - 2015-12-13 01:57 - 00000000 ____D C:\Program Files\Bitdefender Agent
2016-01-22 17:09 - 2012-06-06 20:18 - 00000000 ____D C:\Users\Basti\AppData\Local\LogMeIn Hamachi
2016-01-22 17:08 - 2015-07-15 14:58 - 00000000 _____ C:\hsrv.txt
2016-01-22 17:08 - 2012-05-26 17:22 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-22 17:08 - 2012-05-25 15:06 - 00000000 ____D C:\ProgramData\NVIDIA
2016-01-22 17:08 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-22 17:05 - 2012-05-27 00:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-22 13:38 - 2012-12-09 22:22 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2016-01-22 13:36 - 2012-05-25 15:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-01-22 13:36 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-01-22 13:07 - 2012-05-26 17:23 - 00000000 ____D C:\Users\Basti\AppData\Local\Adobe
2016-01-22 01:09 - 2012-05-27 12:25 - 00000000 ____D C:\Users\Basti\Documents\Outlook-Dateien
2016-01-21 15:28 - 2013-11-03 23:54 - 02324992 ___SH C:\Users\Basti\Desktop\Thumbs.db
2016-01-21 13:29 - 2015-11-27 18:06 - 00002353 _____ C:\Users\Basti\Desktop\Chrome App Launcher.lnk
2016-01-21 13:14 - 2015-12-13 02:12 - 00002129 _____ C:\Users\Public\Desktop\Bitdefender 2016.lnk
2016-01-21 13:14 - 2015-11-21 11:45 - 00001106 _____ C:\Users\Public\Desktop\LECTURNITY Player.lnk
2016-01-21 13:14 - 2015-11-02 11:42 - 00001160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-01-21 13:14 - 2015-11-02 11:42 - 00001154 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-01-21 13:14 - 2015-09-27 14:20 - 00002178 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-21 13:14 - 2015-08-12 00:30 - 00002373 _____ C:\Users\Public\Desktop\TI-Nspire CX CAS Student Software.lnk
2016-01-21 13:14 - 2015-08-11 23:58 - 00002333 _____ C:\Users\Public\Desktop\TI-Nspire CAS Student Software.lnk
2016-01-21 13:14 - 2015-07-15 14:58 - 00000998 _____ C:\Users\Public\Desktop\Droid4X.lnk
2016-01-21 13:14 - 2015-07-14 23:38 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-01-21 13:14 - 2015-07-14 23:38 - 00002050 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-01-21 13:14 - 2015-06-20 11:50 - 00001094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Content Viewer.lnk
2016-01-21 13:14 - 2015-06-06 15:54 - 00001202 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk
2016-01-21 13:14 - 2015-05-28 15:57 - 00001062 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk
2016-01-21 13:14 - 2015-04-17 22:27 - 00001296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2015a.lnk
2016-01-21 13:14 - 2015-04-17 22:27 - 00001290 _____ C:\Users\Public\Desktop\MATLAB R2015a.lnk
2016-01-21 13:14 - 2015-02-21 13:07 - 00001166 _____ C:\Users\Public\Desktop\Dell Display Manager.lnk
2016-01-21 13:14 - 2015-01-23 17:18 - 00002029 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2016-01-21 13:14 - 2014-10-13 18:21 - 00000937 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2016-01-21 13:14 - 2014-10-09 14:36 - 00001243 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2016-01-21 13:14 - 2014-10-09 14:36 - 00001228 _____ C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2016-01-21 13:14 - 2014-07-02 22:48 - 00001998 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk
2016-01-21 13:14 - 2014-07-02 22:43 - 00000960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR-Registrierung.lnk
2016-01-21 13:14 - 2014-07-02 22:42 - 00002113 _____ C:\Users\Public\Desktop\HP Officejet 6700.lnk
2016-01-21 13:14 - 2013-11-20 21:36 - 00000918 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-01-21 13:14 - 2012-12-01 16:29 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
2016-01-21 13:14 - 2012-12-01 16:29 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
2016-01-21 13:14 - 2012-12-01 16:27 - 00001094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2016-01-21 13:14 - 2012-12-01 16:24 - 00000994 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2016-01-21 13:14 - 2012-11-24 13:29 - 00000869 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-01-21 13:14 - 2012-11-20 16:01 - 00001878 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
2016-01-21 13:14 - 2012-08-18 15:28 - 00002002 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
2016-01-21 13:14 - 2012-08-18 15:28 - 00001946 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
2016-01-21 13:14 - 2012-08-18 15:28 - 00001925 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
2016-01-21 13:14 - 2012-07-30 11:51 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-01-21 13:14 - 2012-07-29 17:18 - 00001297 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk
2016-01-21 13:14 - 2012-06-26 19:04 - 00001914 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOL Recorder.lnk
2016-01-21 13:14 - 2012-06-07 19:29 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk
2016-01-21 13:14 - 2011-06-29 12:22 - 00001455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2016-01-21 13:14 - 2011-06-29 12:22 - 00001371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
2016-01-21 13:14 - 2011-06-29 12:22 - 00001302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
2016-01-21 13:14 - 2011-06-29 12:21 - 00002483 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2016-01-21 13:14 - 2011-04-27 12:03 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-01-21 13:14 - 2011-04-27 12:03 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-01-21 13:14 - 2009-07-14 05:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-01-21 13:14 - 2009-07-14 05:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2016-01-21 13:14 - 2009-07-14 05:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-01-21 13:14 - 2009-07-14 05:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-01-21 13:14 - 2009-07-14 05:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-01-21 13:13 - 2013-12-14 11:41 - 00001804 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2016-01-21 13:13 - 2012-05-27 11:24 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\HP Solution Center.lnk
2016-01-21 13:13 - 2012-05-26 16:56 - 00001434 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-01-21 13:13 - 2009-07-14 06:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-01-21 13:13 - 2009-07-14 05:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-01-21 13:12 - 2015-11-01 15:43 - 00002137 _____ C:\Users\Basti\Desktop\Minecraft.lnk
2016-01-21 13:12 - 2015-09-30 16:40 - 00002029 _____ C:\Users\Basti\Desktop\My.com Game Center.lnk
2016-01-21 13:12 - 2015-08-25 21:01 - 00000833 _____ C:\Users\Basti\Desktop\lol.launcher.admin - Verknüpfung.lnk
2016-01-21 13:12 - 2015-06-17 14:20 - 00001085 _____ C:\Users\Basti\Desktop\Oracle VM VirtualBox.lnk
2016-01-21 13:12 - 2015-06-04 13:52 - 00001964 _____ C:\Users\Basti\Desktop\The Witcher® 3 - Wild Hunt.lnk
2016-01-21 13:12 - 2015-06-01 12:56 - 00001020 _____ C:\Users\Basti\Desktop\Fidelify.lnk
2016-01-21 13:12 - 2015-03-19 11:59 - 00001818 _____ C:\Users\Basti\Desktop\Spotify.lnk
2016-01-21 13:12 - 2014-05-24 11:30 - 00001886 _____ C:\Users\Basti\Desktop\CivilizationV_DX11.exe.lnk
2016-01-21 13:12 - 2014-05-17 11:27 - 00002118 _____ C:\Users\Basti\Desktop\JDownloader 2.lnk
2016-01-21 13:12 - 2012-06-21 20:47 - 00001087 _____ C:\Users\Basti\Desktop\Basti.lnk
2016-01-21 13:12 - 2012-05-27 11:05 - 00000355 _____ C:\Users\Basti\Desktop\Computer.lnk
2016-01-21 13:09 - 2010-11-21 08:00 - 00000000 ____D C:\Windows\ShellNew
2016-01-21 13:07 - 2012-06-06 19:59 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-01-20 10:05 - 2012-05-27 00:38 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-20 10:05 - 2012-05-27 00:38 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-20 10:05 - 2012-05-27 00:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-01-18 10:31 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2016-01-18 09:51 - 2015-08-02 16:20 - 00000000 ____D C:\Users\Basti\Desktop\Trainer
2016-01-18 00:53 - 2012-08-18 14:08 - 00007599 _____ C:\Users\Basti\AppData\Local\Resmon.ResmonCfg
2016-01-17 23:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-01-17 23:26 - 2012-09-11 20:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-01-17 23:23 - 2012-05-25 15:05 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-01-17 23:19 - 2012-05-25 15:05 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-01-17 23:08 - 2015-11-01 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-01-17 23:08 - 2015-01-31 18:37 - 00000000 ____D C:\Program Files (x86)\Java
2016-01-17 23:08 - 2013-10-07 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-01-17 23:07 - 2013-10-07 22:47 - 00000000 ____D C:\ProgramData\Oracle
2016-01-17 01:03 - 2013-12-14 11:41 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Spotify
2016-01-16 11:33 - 2013-12-14 11:41 - 00000000 ____D C:\Users\Basti\AppData\Local\Spotify
2016-01-14 23:53 - 2013-11-20 21:36 - 00000000 ____D C:\Users\Basti\AppData\Roaming\vlc
2016-01-14 12:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2016-01-14 10:57 - 2010-11-21 07:50 - 00737796 _____ C:\Windows\system32\perfh007.dat
2016-01-14 10:57 - 2010-11-21 07:50 - 00159894 _____ C:\Windows\system32\perfc007.dat
2016-01-14 10:57 - 2009-07-14 06:13 - 01710742 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-14 10:50 - 2009-07-14 05:45 - 05101656 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-14 10:46 - 2014-12-11 12:06 - 00000000 ____D C:\Windows\system32\appraiser
2016-01-14 10:46 - 2014-05-01 02:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-01-14 10:42 - 2013-03-13 23:18 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-14 10:42 - 2013-03-13 23:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-01-14 02:32 - 2013-03-13 23:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-14 02:32 - 2012-05-27 11:15 - 00000000 ____D C:\ProgramData\Microsoft Help
2016-01-14 02:29 - 2013-07-21 22:37 - 00000000 ____D C:\Windows\system32\MRT
2016-01-14 02:05 - 2011-04-27 12:44 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-01-14 01:58 - 2009-07-14 03:34 - 00000513 _____ C:\Windows\win.ini
2016-01-13 17:34 - 2012-06-09 15:23 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-01-13 17:34 - 2012-06-09 15:23 - 00000000 ____D C:\ProgramData\Skype
2016-01-13 16:50 - 2015-11-01 15:52 - 00000000 ____D C:\Users\Basti\.oracle_jre_usage
2016-01-12 22:23 - 2012-05-26 16:53 - 00000000 ____D C:\Users\Basti
2016-01-12 22:20 - 2015-12-13 02:08 - 00000000 ____D C:\ProgramData\Bitdefender
2016-01-12 22:10 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Offline Web Pages
2016-01-12 22:05 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2016-01-12 21:49 - 2015-09-30 16:38 - 00000000 ____D C:\Users\Basti\AppData\Local\MyComGames
2016-01-12 21:42 - 2015-12-13 02:11 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Bitdefender
2016-01-12 21:40 - 2015-12-13 02:07 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2016-01-12 15:22 - 2015-04-17 23:21 - 00000000 ____D C:\Users\Basti\Documents\MATLAB
2016-01-10 12:21 - 2012-11-24 14:09 - 00000000 ____D C:\Program Files (x86)\Steam
2016-01-10 12:21 - 2012-06-07 15:43 - 00000000 ____D C:\Users\Basti\AppData\Roaming\TS3Client
2016-01-10 12:20 - 2012-09-10 17:02 - 00000000 ____D C:\Windows\Minidump
2016-01-08 19:16 - 2013-02-02 19:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-01-04 11:09 - 2014-03-29 12:34 - 00000000 ____D C:\Users\Basti\AppData\Local\Skype
2016-01-04 02:53 - 2014-02-10 17:04 - 00000000 ____D C:\Users\Basti\AppData\Local\Battle.net
2016-01-04 00:56 - 2015-06-06 15:50 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm
2016-01-04 00:23 - 2013-10-17 14:45 - 00000000 ____D C:\Users\Basti\Uni
2016-01-03 14:04 - 2015-12-15 14:33 - 00000000 ____D C:\Users\Basti\Desktop\test
2015-12-30 11:58 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-12-28 22:49 - 2015-07-16 00:46 - 00000095 _____ C:\Users\Basti\Desktop\codes.txt
2015-12-24 13:21 - 2014-02-10 17:04 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-12-23 15:32 - 2015-05-28 21:19 - 00000000 ____D C:\Users\Basti\Documents\The Witcher 3

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2012-09-29 16:29 - 2013-02-12 19:50 - 0000064 _____ () C:\Program Files\MC.bat
2012-06-06 20:13 - 2012-05-11 18:11 - 0139783 _____ () C:\Program Files\MinecraftSP.jar
2012-11-08 05:39 - 2012-11-08 05:39 - 120115048 _____ () C:\Program Files (x86)\avira_antivirus_premium_en.exe
2012-07-14 15:28 - 2015-11-02 21:05 - 376347915 _____ () C:\Users\Basti\AppData\Roaming\.minecraft.rar
2013-02-07 19:16 - 2015-08-31 22:51 - 0000132 _____ () C:\Users\Basti\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
2015-07-15 14:57 - 2015-07-15 15:00 - 0002380 _____ () C:\Users\Basti\AppData\Roaming\droid4xinstaller.log
2012-08-18 14:08 - 2016-01-18 00:53 - 0007599 _____ () C:\Users\Basti\AppData\Local\Resmon.ResmonCfg
2014-07-02 22:42 - 2014-07-02 22:42 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-07-02 20:16 - 2012-07-02 20:16 - 0000252 _____ () C:\ProgramData\FastPics.log
2012-05-27 11:11 - 2012-06-10 15:42 - 0005000 _____ () C:\ProgramData\hpzinstall.log
2012-07-02 20:16 - 2013-03-01 18:36 - 0025200 _____ () C:\ProgramData\lxdw.log
2012-07-02 20:19 - 2012-07-02 20:24 - 0000537 _____ () C:\ProgramData\lxdwDiagnostics.log

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\Basti\hamachi-2-ui.exe
C:\Users\Basti\save.reg


Einige Dateien in TEMP:
====================
C:\Users\Basti\AppData\Local\Temp\sqlite3.dll
C:\Users\Basti\AppData\Local\Temp\Uninstall.exe


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-01-19 09:35

==================== Ende von FRST.txt ===========================
         
--- --- ---

Alt 22.01.2016, 17:49   #11
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Addition
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-01-2016
durchgeführt von Basti (2016-01-22 17:31:55)
Gestartet von C:\Users\Basti\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-05-26 15:53:52)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-1745305398-2489788369-3521438674-500 - Administrator - Disabled)
Basti (S-1-5-21-1745305398-2489788369-3521438674-1002 - Administrator - Enabled) => C:\Users\Basti
Gast (S-1-5-21-1745305398-2489788369-3521438674-501 - Limited - Enabled)
Zocken (S-1-5-21-1745305398-2489788369-3521438674-1005 - Limited - Enabled) => C:\Users\Zocken

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Bitdefender Antivirus (Enabled - Out of date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AS: Bitdefender Spyware-Schutz (Enabled - Out of date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.14 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.3 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.286 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.)
Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AppNHost 1.0.5.1 (HKLM-x32\...\{A8CB86C7-CD4C-4C4F-AF6A-33D1CAC63562}) (Version: 1.0.5.1 - Mixesoft Project)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.5510 - Perfect World Entertainment)
Audible Download Manager (HKLM-x32\...\AudibleDownloadManager) (Version: 6.6.0.15 - Audible, Inc.)
avira_antivirus_premium_en 1.00 (HKLM-x32\...\avira_antivirus_premium_en 1.00) (Version: 1.00 - Avira)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.5.2.34169 - Electronic Arts)
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 20.0.23.1252 - Bitdefender)
Bitdefender Total Security 2016 (HKLM\...\Bitdefender) (Version: 20.0.23.1252 - Bitdefender)
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Black Desert RU Patcher (HKLM-x32\...\{94381DF9-7266-459C-AF82-4D1458E1AFE7}) (Version: 1.00.0000 - Black Desert RU Patcher)
Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC)
Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
C4600 (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.24 - Piriform)
CD- und DVD-Sharing (HKLM-x32\...\{514FBEC8-E8CE-4F6F-A17F-2789E8DE8D69}) (Version: 1.0.1.4 - Apple Inc.)
Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.11004 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.11004 - Cisco Systems, Inc.) Hidden
CodeBlocks (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team)
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0315 - DT Soft Ltd)
Dark Souls II Black Armour Edition MULTI-2 1.0 (HKLM-x32\...\Dark Souls II Black Armour Edition MULTI-2 1.0) (Version:  - )
Dassault Systemes Software B21 (HKLM\...\Dassault Systemes B21_0) (Version:  - )
Dassault Systemes Software Prerequisites x86-x64 (HKLM\...\{CF1EB598-B424-436A-B15F-B763846BA970}) (Version: 8.1.3 - Dassault Systemes)
Dassault Systemes Software VC9 Prerequisites x86-x64 (HKLM\...\{F2F2DEA7-36AB-4E13-907C-D8BDE775EF97}) (Version: 9.1.2 - Dassault Systemes)
DayZ (HKLM-x32\...\Steam App 221100) (Version:  - Bohemia Interactive)
Dell Display Manager (HKLM-x32\...\{AC50C05D-9D57-40F5-B2EF-AC402F14312B}_is1) (Version:  - EnTech Taiwan)
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - )
Droid4X (HKLM-x32\...\Droid4X) (Version: 0.8.2 - Haiyu Dongxiang Co.,Ltd.)
Dropbox (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
DVDFab 9.0.6.0 (21/08/2013) (HKLM-x32\...\DVDFab 9_is1) (Version:  - Fengtao Software Inc.)
EE-ZDE (HKLM-x32\...\{B49C924C-A651-4378-94F6-5D9BF44A959F}) (Version:  - )
Empire Earth (HKLM-x32\...\{2447500B-22D7-47BD-9B13-1A927F43A267}) (Version:  - )
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Evolve (HKLM\...\{670B1B49-9FD3-4827-9B41-471EFF580AA8}) (Version: 1.8.18 - Echobit, LLC)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Fidelify (HKLM-x32\...\Fidelify) (Version:  - )
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free YouTube to MP3 Converter version 3.11.34.1015 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.34.1015 - DVDVideoSoft Ltd.)
Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.9.0 - Futuremark Corporation)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gameforge Live 1.0 "Legend" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 1.1.1724 - Gameforge)
GeoGebra 5 (HKLM-x32\...\GeoGebra 5) (Version: 5.0.53.0 - International GeoGebra Institute)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden
GUILD WARS (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Guild Wars) (Version:  - )
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Officejet 6700 - Grundlegende Software für das Gerät (HKLM\...\{9086D601-50B7-491D-A143-28193DADE36B}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 6700 Hilfe (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP)
HP Photosmart C4600 All-In-One Driver Software 14.0 Rel. 5 (HKLM\...\{1E1746EF-F5BF-4677-8F30-04FE399130DA}) (Version: 14.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}) (Version: 3.0.2.163 - Apple Inc.)
iFree Skype Recorder 6.0.15 (HKLM-x32\...\iFree Skype Recorder) (Version: 6.0.15 - iFree Skype Recorder)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{0DCD0704-E2AB-4e97-96A7-90F146BD8243}) (Version: 2.50.6733.38 - Sony Computer Entertainment Inc.)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.6 - Intel)
iTunes (HKLM\...\{A04DCB25-7040-4935-A30D-8E0A893ABF2D}) (Version: 11.1.2.32 - Apple Inc.)
JAP (HKLM-x32\...\JAP) (Version: 00.18.001 - JAP-Team)
Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java SE Development Kit 8 Update 65 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180650}) (Version: 8.0.650.17 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games)
LECTURNITY Player (HKLM-x32\...\{8624888C-A959-45A5-98F4-292E956325EA}) (Version: 4.5.0000 - imc AG)
Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.)
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.410 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.410 - LogMeIn, Inc.) Hidden
LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.0.1 - www.leaguereplays.com)
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
MATLAB R2015a (HKLM\...\Matlab R2015a) (Version: 8.5 - MathWorks)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{3c3aafc8-d898-43ec-998f-965ffdae065a}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft)
Minecraft1.6.2 (HKLM-x32\...\Minecraft1.6.2) (Version:  - )
Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My.com Game Center (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\MyComGames) (Version: 3.146 - My.com B.V.)
NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version:  - NCSOFT)
Need for Speed™ Most Wanted (HKLM-x32\...\{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}) (Version:  - )
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.52.3 - Black Tree Gaming)
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation)
NVIDIA 3D Vision Video Player (HKLM-x32\...\{FE3B9518-9FF3-4D89-8A8D-E540C9CCAF3B}) (Version: 1.5.2 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.8.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.8.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.3.6.4639 - Electronic Arts, Inc.)
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r4600) (Version:  - )
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PFConfig 1.0.296 (HKLM-x32\...\PFConfig) (Version: 1.0.296 - Portforward.com)
Pflanzen gegen Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PS_AIO_05_C4600_Software_Min (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden
PTC Mathcad Prime 3.0 (HKLM-x32\...\{C4AB999A-D981-4913-BA26-E4776B598E7D}) (Version: 3.0.0 - PTC)
PTC Quality Agent (HKLM-x32\...\{5B7F8A19-AF71-4517-B49C-683AFC5B639C}) (Version: 2.0.0.0 - PTC)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden
Revo Uninstaller 1.94 (HKLM-x32\...\Revo Uninstaller) (Version: 1.94 - VS Revo Group)
Samsung New PC Studio (HKLM-x32\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.)
Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden
Secure Download Manager (HKLM-x32\...\{531E35C7-B4E7-418C-A2CD-C1205D9C8AC9}) (Version: 3.1.20 - Kivuto Solutions Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)
Sid Meier's Civilization V (HKLM-x32\...\Sid Meier's Civilization V_is1) (Version: Sid Meier's Civilization V - )
skyforge_mycom (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\skyforge_mycom) (Version: 1.46 - My.com B.V.)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.103 - Skype Technologies S.A.)
Sleeping Dogs Limited Edition (HKLM-x32\...\Sleeping Dogs™ UPDATE 1.5_is1) (Version: 1.5.0.0 - QfG)
SleepTimer Ultimate 1.2 (HKLM-x32\...\{0EE56463-49B2-45E1-B74F-3E0139DBC986}_is1) (Version:  - Christian Handorf)
SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.19.9599 - SoftEther VPN Project)
SolutionCenter (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Space Engineers (HKLM-x32\...\Steam App 244850) (Version:  - Keen Software House)
Spotify (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB)
Status (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.11.0 - GOG.com)
The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.0.10.0 - GOG.com)
TI-Nspire™ CAS Student Software (HKLM-x32\...\{F03A8756-7FCB-4DCD-9AC1-12C63A6075F1}) (Version: 3.9.0.463 - Texas Instruments Inc.)
TI-Nspire™ CX CAS Student Software (HKLM-x32\...\{E994956D-8CA7-4091-BFF5-0C749470BA2E}) (Version: 4.0.0.235 - Texas Instruments Inc.)
Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Tropico 5 (HKLM-x32\...\Tropico 5_is1) (Version:  - )
Unity Web Player (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft)
VBA (3821b) (x32 Version: 6.01.00.1234 - Microsoft Corporation) Hidden
VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN)
WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden
Winamp (HKLM-x32\...\Winamp) (Version: 5.623  - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR 4.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH)
Xilisoft iPod to PC Copy (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Xilisoft iPod to PC Copy) (Version: 5.4.0.20120709 - Xilisoft)
XMedia Recode Version 3.1.1.6 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.1.6 - XMedia Recode)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {03DA3B3E-4D58-494B-B245-DAD0A8DBDDBB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {153DADDB-4AF6-47D4-9A9D-67EC0B18A250} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated)
Task: {1B95DAB2-8C86-456F-A170-84602E3279E6} - System32\Tasks\Bitdefender Restart ProductCfg_F5C977342AD24B62922B89BDC5ABCCD2 => C:\Program Files\Bitdefender\Bitdefender 2016\ProductCfg.exe [2016-01-12] (Bitdefender)
Task: {1BA04B1B-DE8A-4E45-ACDA-1A8BA907AFFA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-10-24] (Piriform Ltd)
Task: {1F671263-2C93-4355-8954-D8A6E869F130} - System32\Tasks\{4B70D9A6-59CA-43A1-BDBB-B887E40A84D7} => Firefox.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/go/help.faq.installer?LastError=1618
Task: {2490A96E-2646-4481-8A6A-BBB935E89609} - System32\Tasks\{9342110C-473A-40B6-BA74-470DFD73271A} => pcalua.exe -a "C:\Program Files\NVIDIA Corporation\3D Emitter\nvUSBInst.exe" -d "C:\Program Files\NVIDIA Corporation\3D Emitter"
Task: {293C18C3-B0F0-4881-947C-966DBAC8BD49} - System32\Tasks\{2D1288DA-1D43-479F-8B4B-36F07394063D} => pcalua.exe -a C:\Users\Basti\Downloads\jxpiinstall(2).exe -d C:\Users\Basti\Downloads
Task: {3ACB3CBC-294D-4FA3-A2D0-3F121830A2F8} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2015-11-09] (Bitdefender)
Task: {4BFE7F94-DA9B-405C-A8F1-276005CD48F2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-20] (Adobe Systems Incorporated)
Task: {508DEA04-F80D-4D62-8C8D-BC6AC05F4FA3} - System32\Tasks\GameNet => C:\Program Files (x86)\QGNA\qGNA.exe
Task: {531F9E18-C366-4AAA-9E20-8D05859A457C} - System32\Tasks\Installation App Launcher => C:\Program Files (x86) (x86)\Lexmark 7600 Series\ezprint.exe [2010-02-10] (Lexmark International Inc.)
Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
Task: {5ED4D938-3805-450A-888D-B8DEE4C24A92} - System32\Tasks\{C9B77DE9-6A1C-4821-9150-5E9DEA822464} => pcalua.exe -a "C:\Users\Basti\Local Settings\Application Data\Bundled software uninstaller\biclient.exe" -c /initurl hxxp://bi.bisrv.com/:affid:/:sid:/:uid:? /affid uninstall /id uninstall /name "Bundled software uninstaller"
Task: {6131115E-E342-4ED5-BA2E-274E03E3AD03} - System32\Tasks\MATLAB R2015a Startup Accelerator => C:\Program Files\MATLAB\R2015a\bin\win64\MATLABStartupAccelerator.exe [2014-12-29] ()
Task: {65774187-F822-4405-9366-4822D1B7BB56} - System32\Tasks\{4FE8E9A0-83ED-441A-8CB2-539F94CDF074} => pcalua.exe -a C:\Users\Basti\Downloads\EvolveSetup.exe -d C:\Users\Basti\Downloads
Task: {6F3A25B2-F32B-4D54-90C7-DC55CE87C89F} - System32\Tasks\AdobeAAMUpdater-1.0-Basti-PC-Basti => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-05-25] (Adobe Systems Incorporated)
Task: {822254E8-1508-4FDA-A2D3-1D5A491C3664} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
Task: {8CA2239D-3265-4137-9474-7F68939B16D3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {8ECEC114-1088-4798-8437-7B8444048439} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
Task: {A5B7212F-CF00-47BD-A6B8-6AFB1673C7FE} - System32\Tasks\{17AF4C96-0ABB-4915-ABBF-64D12E75ED44} => pcalua.exe -a H:\Adobe_Photoshop_CS5_Extended-AkamaiDLM.exe -d H:\
Task: {AD6C33B2-B2D5-4DB3-885B-F850B71E16F8} - \Dealply -> Keine Datei <==== ACHTUNG
Task: {C09706A8-6289-4CBB-83AA-307E834C9348} - System32\Tasks\{F2F37F3E-65F3-4810-8851-E0B4B6BAEA81} => C:\Sierra\EE-ZDE\EE-AOC.exe [2002-08-21] ()
Task: {C3011503-2B45-43D6-8191-7E900C479FA0} - System32\Tasks\{D00EF0EA-619B-4134-97D6-7A640F11A328} => pcalua.exe -a "C:\Users\Basti\Downloads\FM13 Datensatz - Deutschland.exe" -d C:\Users\Basti\Downloads
Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc
Task: {DE3BBF04-CFC3-41EC-B711-791D41C3733B} - System32\Tasks\{7AE8198C-13CA-46CB-B46B-D22ECDC213E0} => pcalua.exe -a C:\Users\Basti\Downloads\forge-1.7.10-10.13.4.1448-1.7.10-installer-win.exe -d C:\Users\Basti\Downloads

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Dealply.job.bak => C:\Users\Basti\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ACHTUNG
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\MATLAB R2015a Startup Accelerator.job => C:\Program Files\MATLAB\R2015a\bin\win64\MATLABStartupAccelerator.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

Shortcut: C:\Users\Basti\Spiele\MC-Server_start.bat - Verknüpfung.lnk -> C:\Users\Basti\Desktop\Neuer Ordner\Server_start.bat (Keine Datei)
Shortcut: C:\Users\Basti\Spiele\MC.bat - Verknüpfung.lnk -> C:\Program Files\MC.bat ()
Shortcut: C:\Users\Basti\Spiele\Start NFS MW Mod Loader.bat - Verknüpfung.lnk -> C:\Program Files (x86)\EA GAMES\Need for Speed Most Wanted\Start NFS MW Mod Loader.bat ()

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2016-01-12 21:42 - 2013-09-03 13:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\bdmetrics.dll
2016-01-21 17:30 - 2016-01-21 17:30 - 01119064 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpbr.mdl
2016-01-21 17:30 - 2016-01-21 17:30 - 00794832 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpdsp.mdl
2016-01-21 17:30 - 2016-01-21 17:30 - 03038112 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpph.mdl
2016-01-21 17:30 - 2016-01-21 17:30 - 01648408 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttprbl.mdl
2015-06-03 03:56 - 2015-06-03 03:56 - 00261864 _____ () C:\Program Files (x86)\Droid4X\Droid4XService.exe
2012-06-08 14:13 - 2012-02-17 19:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll
2016-01-17 23:26 - 2015-12-16 18:34 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2012-11-22 16:19 - 2013-10-30 19:53 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-09-23 18:43 - 2015-09-23 18:43 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2012-05-30 19:06 - 2012-05-30 19:06 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-05-30 19:06 - 2012-05-30 19:06 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-12-28 21:32 - 2015-04-24 16:40 - 00043520 _____ () C:\Users\Basti\AppData\Local\THORN\QtSolutions_Service-head.dll
2015-12-28 21:32 - 2014-08-28 10:36 - 00732160 _____ () C:\Users\Basti\AppData\Local\THORN\libGLESv2.dll
2015-12-28 21:32 - 2014-08-28 10:41 - 00856576 _____ () C:\Users\Basti\AppData\Local\THORN\platforms\qwindows.dll
2015-12-28 21:32 - 2014-08-28 10:36 - 00047104 _____ () C:\Users\Basti\AppData\Local\THORN\libEGL.dll
2012-05-25 15:07 - 2012-03-28 21:18 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-12-21 13:52 - 2015-12-21 13:52 - 00932032 ____R () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll
2016-01-17 23:26 - 2015-12-16 18:34 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-01-14 11:16 - 2016-01-12 17:35 - 01590088 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libglesv2.dll
2016-01-14 11:16 - 2016-01-12 17:35 - 00087880 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\Users\Basti\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Basti\Desktop\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Basti\Desktop\AdwCleaner_5.030.exe:BDU
AlternateDataStreams: C:\Users\Basti\Desktop\FRST64.exe:BDU
AlternateDataStreams: C:\Users\Basti\Desktop\JRT.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Basti\Downloads\361.43-desktop-win8-win7-winvista-64bit-international-whql.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\BnS_Lite_Installer.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\chromeinstall-8u66 (1).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\chromeinstall-8u66.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\codeblocks-13.12mingw-setup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\EvolveSetup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\iFreeRecorder.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\jxpiinstall(2).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024 (1).exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\mingw-get-setup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\NC-LauncherSetup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\setup.exe:BDU
AlternateDataStreams: C:\Users\Basti\Downloads\SkypeSetup.exe:BDU
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

Da befinden sich 7865 mehr Seiten.

IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123simsen.com -> www.123simsen.com

Da befinden sich 7863 mehr Seiten.


==================== Hosts Inhalt: ==========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2016-01-22 17:08 - 00004098 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1	lmlicenses.wip4.adobe.com
127.0.0.1	lm.licenses.adobe.com
127.0.0.1	na2m-pr.licenses.adobe.com
127.0.0.1	ereg.wip3.adobe.com
127.0.0.1	ereg.wip4.adobe.com
127.0.0.1	wip.adobe.com
127.0.0.1	wip1.adobe.com
127.0.0.1	wip2.adobe.com
127.0.0.1	wip3.adobe.com
127.0.0.1	wip4.adobe.com
127.0.0.1	wwis-dubc1-vip60.adobe.com
127.0.0.1	hl2rcv.adobe.com
127.0.0.1	adobeereg.com
127.0.0.1	activate.adobe.com
127.0.0.1	practivate.adobe.com
127.0.0.1	ereg.adobe.com
127.0.0.1	activate.wip3.adobe.com
127.0.0.1	ereg.wip3.adobe.com
127.0.0.1	activate-sea.adobe.com
127.0.0.1	activate-sjc0.adobe.com
127.0.0.1	3dns.adobe.com
127.0.0.1	3dns-1.adobe.com
127.0.0.1	3dns-2.adobe.com
127.0.0.1	3dns-3.adobe.com
127.0.0.1	3dns-4.adobe.com
127.0.0.1	adobe-dns.adobe.com
127.0.0.1	adobe-dns-1.adobe.com
127.0.0.1	adobe-dns-2.adobe.com
127.0.0.1	adobe-dns-3.adobe.com
127.0.0.1	adobe-dns-4.adobe.com127.0.0.1	www.007guard.com

Da befinden sich 77 zusätzliche Einträge.


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist deaktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Inhaltsmanager-Assistent für PlayStation(R).lnk => C:\Windows\pss\Inhaltsmanager-Assistent für PlayStation(R).lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Basti^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Synchronizer => 
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: ApnUpdater => 
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AutoStartNPSAgent => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
MSCONFIG\startupreg: CD- und DVD-Sharing => "C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: EzPrint => "C:\Program Files (x86) (x86)\Lexmark 7600 Series\ezprint.exe"
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: LOLReplay Recorder => "C:\Program Files (x86)\LOLReplay\LOLRecorder.exe" -minimize
MSCONFIG\startupreg: lxdwmon.exe => "C:\Program Files (x86) (x86)\Lexmark 7600 Series\lxdwmon.exe"
MSCONFIG\startupreg: Pando Media Booster => 
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{AEB0AA6D-6C50-4812-9625-67A55EFD53FF}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{B6C925FB-AAF5-426B-B3E4-AE312A3FA526}] => (Allow) LPort=2869
FirewallRules: [{B8A05455-93A9-4D81-8C81-D3F3517D953C}] => (Allow) LPort=1900
FirewallRules: [{E8294358-232A-45E3-8825-6CF312AFF0A3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{FF42412D-60DF-4783-9856-A6786836D569}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [TCP Query User{8605D22C-C232-4D70-95DE-DF0204070B05}E:\skype\phone\skype.exe] => (Allow) E:\skype\phone\skype.exe
FirewallRules: [UDP Query User{3E24806E-72F0-4CB2-85B5-52D76EA61D9D}E:\skype\phone\skype.exe] => (Allow) E:\skype\phone\skype.exe
FirewallRules: [TCP Query User{66097FAD-DE6E-45FE-B4B5-494B7951E559}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{E44AFAA1-C985-4D4D-98C4-D1F1222E8DEC}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [{50589B4A-7714-4736-A12C-F203A0404CBD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{7BEB5529-C91A-4153-8184-940217CA9A68}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{BA05C10F-C9BD-4AAF-8CA9-1FD195EDC8AD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{9CE0C97A-8FA5-4C78-8636-3CCBF4236105}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{43F4BE84-BDF6-4A56-B305-76266D5CE186}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{944328E1-A43A-4626-AFB3-1B5EB8ED02AB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{01296CE7-D3EA-4B41-80A9-2B1A6DB946AC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{A1DFC9B1-30E8-4236-BC1B-7C29FA788E56}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe
FirewallRules: [{61452E45-4CE4-4DEC-BFBF-F8C65D483E7D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{35B97D4E-9D9B-42C9-ADFB-D6DE5CFDFD87}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{ACD23962-358A-4CF3-B3BE-C1859D1B3AC4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{9A6355D6-6CE8-4A0B-A848-6868982EB28C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{E5585DFB-2F3E-452B-974F-0659487E8AC3}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{37A64963-0E37-4E44-A6E5-544FC3B270B1}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{EB61EA23-EE2E-4D8B-9A1B-2F888ECA97EA}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{4F20E937-3A3E-484E-AF41-BCBF8F6EF15A}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{0FCC7DD0-110E-48F3-98D7-63537CE9D87C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C3BB32CF-7D2A-4B49-B0E6-C59A5363AFDB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E40CC70F-53F7-43AE-82A1-464181035FD8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{26EA374E-9D61-4AB5-BFEB-457A93CDB684}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{9D747C84-4B7C-4ABD-954F-808306C2E7DE}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{0FD22C5F-CEEC-452B-BB9B-F382C7DD3E7A}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{1316D1D9-190F-43A7-840B-E3DB02CAD839}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{F2AAF089-6789-4D58-86CA-8AF3A3014E3D}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{BF4BE5A0-D5B0-4CCE-AD02-C3926AF88D7F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{840BA19A-BE66-447C-8549-E61914FD6364}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{DA31F48E-4D65-448E-B0E5-F0F032D1A0C3}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{405839C9-B746-4857-8BEF-9440A903A334}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{7AFE82AF-470C-472B-9E42-73595DDB3C58}] => (Allow) LPort=7935
FirewallRules: [{834A5996-41C5-4FED-A7C7-29812EB211A6}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{3F1637F3-3EA7-4C2D-A98A-756F2DBA7161}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe
FirewallRules: [{F738565D-20E7-4107-B64A-A15741CD7DE5}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{48144A4D-6B79-4058-9A48-20772876CB90}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe
FirewallRules: [{CFE4DF24-5F00-49FB-A863-530E7E9E1505}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{C19442D6-0261-4459-BD4F-6C8C4CC36C6E}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{BDDB4C68-8452-43E0-B3EB-33E014E862F2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe
FirewallRules: [{2B9602D7-E869-44EB-A586-73EAFF8A1523}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe
FirewallRules: [{8CA1C522-931E-45DF-A8B2-1496E2233AF9}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe
FirewallRules: [{ED332F7D-C2B1-4A8E-A563-FB8F8ABD00B1}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe
FirewallRules: [{706DA564-C0DD-4259-BE64-9504CA32903B}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe
FirewallRules: [{077438E0-8148-47F5-82EA-7A23153241E2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe
FirewallRules: [{AFB4F4A8-A984-40B8-AC0A-A581DBC8D0AA}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe
FirewallRules: [{A7BBF6CC-173E-4F92-B1A5-91533FE68EBE}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe
FirewallRules: [{2525E825-F9A6-4F85-A5A8-E97D5C3A4FDA}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{4AE9836A-57F4-4F10-9FE2-079DCE1A74C5}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{782775DE-583A-4E84-BCDF-8766C9907708}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe
FirewallRules: [{A6DE10C4-6169-4354-8A5F-1D6EF61C649A}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe
FirewallRules: [{360EE568-4F95-4925-AD87-D0D8629D8E94}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe
FirewallRules: [{E834066F-C3C5-4C49-A039-7AE32F6BA807}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe
FirewallRules: [TCP Query User{56C7AB21-BCCD-4F5C-8D52-74B395884B9E}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Block) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [UDP Query User{C47A71CD-4BB7-4FF9-BC0F-829EE83DFA87}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Block) C:\program files (x86)\sony\content manager assistant\cma.exe
FirewallRules: [{27133C47-866D-499D-B8E0-62C8175B8D81}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{FC824A4A-084E-4949-A0FE-00036DCD3AE0}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe
FirewallRules: [{2BF78D21-34D1-407F-BB1E-863E83E76E74}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe
FirewallRules: [{ED6FAA94-A8B5-45A3-9D07-B568068532D2}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\RemoteInstallMacOSX.exe
FirewallRules: [{6A55489F-AC43-4B82-8B6F-10620D1D28BB}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\RemoteInstallMacOSX.exe
FirewallRules: [{E744BA9D-77AC-4A44-B1CC-53F9C01E70F8}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{E7C457CF-0B0B-42A7-A0D2-F942BD081C8C}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{14972E55-7D37-4D27-AE30-652C230045BE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{B9FBD964-5AD5-4909-B65A-DCB842B4B050}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{FE2B4338-50A1-42E3-BC70-F33D927CCA59}C:\users\basti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\basti\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{FC27B11D-372E-4D59-9F85-5B7E0630AD9C}C:\users\basti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\basti\appdata\roaming\spotify\spotify.exe
FirewallRules: [{77FEF5E3-A2C3-4AAF-B6F3-2944DB24AEB0}] => (Block) C:\users\basti\appdata\roaming\spotify\spotify.exe
FirewallRules: [{3C5A270E-15A2-4014-84D7-4C2B82BFD115}] => (Block) C:\users\basti\appdata\roaming\spotify\spotify.exe
FirewallRules: [{0BEC205D-E089-4F21-9A05-312B20B704F9}] => (Allow) E:\Dragon Nest Europe\DragonNest.exe
FirewallRules: [{F2C2E9A0-14A3-46AB-B79D-0489399BAFF8}] => (Allow) E:\Dragon Nest Europe\DragonNest.exe
FirewallRules: [TCP Query User{6B0C01E5-C627-4A7C-8E52-D90D5FA2D12F}C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe] => (Allow) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe
FirewallRules: [UDP Query User{49CAF30B-96F6-46AF-87DC-7C846CEE1567}C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe] => (Allow) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe
FirewallRules: [{DBB21750-4C66-4A32-BDE8-9BD9B599C09C}] => (Block) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe
FirewallRules: [{E8872357-7E0F-4009-960C-A6CA99D08262}] => (Block) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe
FirewallRules: [{D90E4B67-C6C8-4C6D-B779-95A0AF0549FB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{01D550ED-529B-4EBD-A526-FF7C61C99B38}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{3AEC5918-0F0F-446C-814F-BED80BA8D615}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{A19FAE1B-8FC4-47A2-AF99-615CB1632989}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{E7C041D1-61AF-47DC-87FF-C4102F7E96AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ.exe
FirewallRules: [{29261903-A601-474E-B969-353B616287C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ.exe
FirewallRules: [{F3F0B184-0050-4CC7-A11F-2FF10347E4E1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{B75523F0-6DFC-4C2E-88DF-3A853D1A7A1E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{3BAF1F78-0DC1-4410-88A6-ACFE28FAADD8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{63076B8D-F269-449B-BF26-999899FB5637}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{092EAFF9-F1B8-492E-8A93-FCDED7F6F01A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{2FE6D278-7786-4902-A270-0562F93891F8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{5BF2665B-F8A2-448B-A8B1-166D603E24FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{589C5ED7-3E1B-4004-A20E-66EEB891C562}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{C0F3EDDA-BD33-4854-B4D0-75DD8675C224}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{6D26D78C-E034-449D-ADBE-E29E44D2F37A}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{4442C690-D7E9-4B5F-A25E-521E36417F40}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{5D891812-49CD-43AE-B7EE-B27C96C7C7B2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [TCP Query User{91BF4BE0-EB25-44AD-ADB9-36F1E34B317B}C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe] => (Allow) C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe
FirewallRules: [UDP Query User{A4A79727-54EA-44D0-948D-F9DFAEFDAF0F}C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe] => (Allow) C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe
FirewallRules: [{68D3CDC7-D1F8-4273-842F-B17E7C4E86CF}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{A4642A64-FFB6-42F5-9EF8-A3F257E61B1C}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{C5272483-76CE-4BD8-8646-C6EC5F1CF1C6}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{8B4C1C15-86C8-4AD4-B190-9C08CFFD95D9}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{25ADDED9-C807-4172-90A1-C3AC964FE326}] => (Allow) %ProgramFiles% (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe
FirewallRules: [{794319B8-A91B-4DD1-93BF-25E9DA084189}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\FaxApplications.exe
FirewallRules: [{8C20186C-0132-442A-A451-0EA1015D8F23}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\DigitalWizards.exe
FirewallRules: [{66CB480A-D5FC-4F94-AC12-477B0638B0DA}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\SendAFax.exe
FirewallRules: [{CEFFC8B8-7E7F-4597-9668-0026E35B6E55}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\DeviceSetup.exe
FirewallRules: [{359830D2-A868-402B-B585-B569FB7EB3C0}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe
FirewallRules: [{5EBF68FE-225D-4A50-A647-5F055D3EFEDE}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{C82C70BC-BCA0-4975-B46C-17D9C4A9BEA5}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{CE760193-0C9F-4B96-AB09-26F0C191308E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{071BE61C-F3E5-49E7-A3A4-56EA1EB407CA}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe
FirewallRules: [{D1797CFD-02F7-4544-9D54-7A0B951C5482}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe
FirewallRules: [{7A5E1850-EC46-4F46-85DA-54540ACBDDB2}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [{996983E1-D0BE-4FCD-8BBA-E257667941C5}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [TCP Query User{B8D07668-448E-487F-969A-93BD616D78E5}C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe
FirewallRules: [UDP Query User{662D666A-2E35-412E-A419-095CFC37F1C1}C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe
FirewallRules: [{F2FC4E0B-76F9-4320-853A-51889938D513}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe
FirewallRules: [{FDFA8CE5-7B10-4F85-911C-B56695D7EAE2}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe
FirewallRules: [TCP Query User{5FC2F183-3E0D-440A-A0CD-69E7A331D073}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{E8183AD0-A3B5-4509-A899-446F3BC09495}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{041EF0F9-A7FE-4004-805D-A9BCE9B87258}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{33544488-16F1-42C3-A81A-1C1511AF6668}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe
FirewallRules: [{031849CA-EB99-4088-9CCB-4C258DD89942}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe
FirewallRules: [{8E346669-071F-4C46-A819-6CD8A7CC5FEA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe
FirewallRules: [{B1A7B880-0EB6-4823-9D86-9FFCF83A3F58}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{E58C066A-3E3D-42F8-BFA8-E9BAE65EB7E4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{B991969E-6CD9-460C-A810-EDD7ADA4E68B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{04971D38-5D33-4E01-B3BB-219E0093C7BA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{89F1D3EE-7834-42BC-9700-3D25BCBC56B3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C3FAE89B-1D4E-4D46-8A61-50158D229C9A}C:\program files\matlab\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2015a\bin\win64\matlab.exe
FirewallRules: [UDP Query User{AF96BE9C-1D63-45FA-A019-CBD69EC2ECFD}C:\program files\matlab\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2015a\bin\win64\matlab.exe
FirewallRules: [{79EDEFCB-DED5-415A-A2D4-954E3A07B2BC}] => (Block) C:\program files\matlab\r2015a\bin\win64\matlab.exe
FirewallRules: [{5D435D29-34E0-4F66-BC06-329AC4E22143}] => (Block) C:\program files\matlab\r2015a\bin\win64\matlab.exe
FirewallRules: [TCP Query User{E16785C3-4F1F-43DB-8569-7DAA1BB4939E}C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [UDP Query User{F8F7CE09-1BD6-40C2-BD53-B90E1779DF9E}C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{56E46A08-F7EC-4BCD-99E7-67C16D04072B}] => (Block) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{BAE9B81F-B180-450C-AAC2-90F85855CDCF}] => (Block) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [TCP Query User{960BAFE7-B279-4687-9762-B617276B2508}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [UDP Query User{3DD91B0E-AD44-4ACC-A86F-E3FFDF965641}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{1498F3EC-1538-4C3F-9EAA-03B8D867AF38}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [{91101AFB-5036-4D1E-9DE3-115D13D0A94C}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe
FirewallRules: [TCP Query User{DB4711FF-7CE3-4C3F-A9E2-C814CAE24E25}C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe
FirewallRules: [UDP Query User{2FCA9D68-E3E0-464D-B786-8D9728A834FD}C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe
FirewallRules: [{6D6BEFEA-892A-461E-8E30-BC2DD8A8A9F1}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe
FirewallRules: [{C30C8168-C7A9-411E-B51C-B21F3F9F16B2}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe
FirewallRules: [TCP Query User{83036536-6209-4CB8-B628-DA794E18A8DE}C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe
FirewallRules: [UDP Query User{A139B970-9425-43E7-BDB6-4E22B2345171}C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe
FirewallRules: [{700BBAB0-6C40-4AF2-BA97-8C696AC63CB0}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe
FirewallRules: [{F11DDB0B-43A6-49B1-B7D0-5A8066177317}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe
FirewallRules: [TCP Query User{BB97726B-726D-4884-B231-36F1A90474C5}C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe
FirewallRules: [UDP Query User{F0AFB84E-50C4-44F0-92F2-B67D99132739}C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe
FirewallRules: [{00EB906D-649C-4861-8C9D-34882AA42F23}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe
FirewallRules: [{8CA6EF79-B664-454D-B766-431FFD0DF4B7}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe
FirewallRules: [{A6D6D585-8623-4CE1-BAAD-351E922FB928}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{C2585F8A-885F-42B0-862D-ABAE50F00A1F}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe
FirewallRules: [{BBFEFEDB-1230-42AF-A40A-7968C2540868}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe
FirewallRules: [{077A8C17-D8B6-424C-8B93-106296089B81}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe
FirewallRules: [{E873F7D5-09B2-46FE-9BB0-FC73E216E95C}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe
FirewallRules: [TCP Query User{82994F2D-DF04-4504-9058-CD0ECF2CB746}C:\users\basti\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\basti\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [UDP Query User{7A4E61E8-A717-4843-BD4D-C110383BB73B}C:\users\basti\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\basti\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [TCP Query User{705B4041-A30C-4268-8F74-2563047066DB}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [UDP Query User{0C868E8E-EF56-47E5-9E9E-6416F680CADC}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [{A7EF31CF-8B85-49A0-AA01-137354F2D690}] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [{0A27EF24-7F72-4DA8-96AA-0602EE1512E5}] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [{6A3A3F01-F7A8-4478-BCE1-A786958317D4}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{AF0213A2-AC56-4328-AC32-39E8FB0880D0}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [TCP Query User{7C58B92D-4076-4983-AF12-2E3D4EE31460}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [UDP Query User{43725424-2FA4-4C68-A7C6-AE4D1E43ABD4}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{C5AE2AAD-ACB2-4E63-BC67-B6FA715C0461}] => (Block) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{50A441D2-4782-462D-AEDA-5999E5B5CED0}] => (Block) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{798DF15F-3FB2-4BF3-A2FC-DF8A03AECE4C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C34618EC-DBF5-490C-AF1D-DF67C2E6D049}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{A4A0EC4B-C983-4968-9F2D-3302F4F92661}C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe] => (Allow) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe
FirewallRules: [UDP Query User{A4AAC983-1616-4AB4-8AD2-3D6AFF5356D7}C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe] => (Allow) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe
FirewallRules: [{06F93520-1969-4A3A-8192-EA0B59554B6E}] => (Block) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe
FirewallRules: [{F423C64F-ED88-4412-9950-D47215E34DBB}] => (Block) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe
FirewallRules: [{7773F1CF-7D07-444E-9F8C-D57EEBADC678}] => (Allow) C:\Users\Basti\Downloads\PlayBlackDesert.exe
FirewallRules: [{A6016ED8-3344-4278-8690-1A83D5005216}] => (Allow) C:\Users\Basti\Downloads\PlayBlackDesert.exe
FirewallRules: [{C52C2134-609E-4B7E-B36A-3EADD6F8A190}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe
FirewallRules: [{238E1164-63F1-46B6-AD8F-0CC27C8619BA}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe
FirewallRules: [{C96E8D7E-8DE5-4FD3-85C1-CF41AE855BA6}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe
FirewallRules: [{22687CF4-7DE2-4EA1-8698-5586C8BA5CE2}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe
FirewallRules: [{E1DD1465-3FC5-4683-9970-D29CF3F37977}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
FirewallRules: [{A1F50892-915B-4F15-8E2B-23EC7CCCA0AE}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe
FirewallRules: [TCP Query User{D47A2608-0668-439F-BD5D-3F91C39914AB}C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{F79027D7-71EA-4E9B-A204-126AE06D6F0B}C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe
FirewallRules: [{25BF71AC-A7D7-455F-909D-072BE2A7890D}] => (Block) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe
FirewallRules: [{56497540-DDF4-4F39-97B8-427A74C3F8EB}] => (Block) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe
FirewallRules: [{C92E8A48-A808-4C74-8216-0AF4284CF939}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\PublicLauncher.exe
FirewallRules: [{FFB5C658-D2AA-45C6-90F8-83CC5523B319}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\PublicLauncher.exe
FirewallRules: [{9E2CB54A-70ED-4A4E-A8BD-F7E24A1E8A57}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\MQELDiagnostics.exe
FirewallRules: [{00ED0974-C580-4FFD-A091-BA3BFBEC7AC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\MQELDiagnostics.exe
FirewallRules: [TCP Query User{5197AE62-CE7D-4AA2-B80F-B5F444D5BFA7}C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [UDP Query User{A0DC3AE3-67CD-46C7-ABB1-F7B625700ACC}C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [{5C48AC52-2639-4854-A883-55938500DD89}] => (Block) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [{F39D5120-EA60-4023-8F52-E21E2020037B}] => (Block) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [{571F6C7C-2EFF-4F40-BB56-2654CCAFC1C2}] => (Allow) C:\Program Files\Echobit\Evolve\EvoSvc.exe
FirewallRules: [{450EC6E1-77C0-43E2-9A68-1750427FB700}] => (Allow) C:\Program Files\Echobit\Evolve\EvolveClient.exe
FirewallRules: [{3FFDEB63-D938-43B8-A52B-A79A42CE5867}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{7759388F-4EB9-47C8-905A-89153DD9989C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{90246421-2C2E-499B-A5B5-69F2DEB1E1F7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{DF9CE38A-4A6C-48B5-9157-3B60D3673EC7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{4EED09D9-F074-4E5F-8F6B-04CB10A69337}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{3DC9517A-F886-44F5-AF92-5EE0EF4B3B9A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe

==================== Wiederherstellungspunkte =========================

21-01-2016 14:26:57 Entfernt Blade & Soul
21-01-2016 14:33:54 Installiert Blade & Soul
22-01-2016 17:15:03 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (01/22/2016 05:24:00 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (01/22/2016 05:09:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/22/2016 01:31:22 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (01/22/2016 01:09:17 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (01/22/2016 12:56:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/22/2016 01:07:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Client.exe, Version 0.0.146.5585 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1abc

Startzeit: 01d154a85317fdbe

Endzeit: 73

Anwendungspfad: C:\Program Files (x86)\NCSOFT\BnS\bin\Client.exe

Berichts-ID: 0e447086-c09c-11e5-ba16-0008cae5fc52

Error: (01/22/2016 01:00:19 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Client.exe, Version 0.0.146.5585 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1a70

Startzeit: 01d154a669c2ae21

Endzeit: 51

Anwendungspfad: C:\Program Files (x86)\NCSOFT\BnS\bin\Client.exe

Berichts-ID: 0f2c1b30-c09b-11e5-ba16-0008cae5fc52

Error: (01/21/2016 02:28:47 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (01/21/2016 02:14:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/21/2016 01:25:41 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP)
Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127


Systemfehler:
=============
Error: (01/22/2016 05:15:57 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Display Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (01/22/2016 05:09:47 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (01/22/2016 05:05:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Apple Mobile Device" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%109

Error: (01/22/2016 05:05:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Druckwarteschlange" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1069

Error: (01/22/2016 05:05:34 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "Spooler" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
%%50

Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (01/22/2016 05:05:32 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\bcmihvsrv64.dll

Error: (01/22/2016 05:05:32 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\bcmihvsrv64.dll

Error: (01/22/2016 05:05:25 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\bcmihvsrv64.dll

Error: (01/22/2016 05:05:06 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: 
%%1056

Error: (01/22/2016 05:04:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "BBUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


CodeIntegrity:
===================================
  Date: 2016-01-18 10:27:54.004
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2016-01-18 10:27:53.954
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-30 14:58:14.199
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.CP6452" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-30 14:58:14.135
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.CP6452" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 13:19:19.901
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.sA6316" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 13:19:19.826
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.sA6316" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 13:07:59.521
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.AF5708" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 13:07:59.460
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.AF5708" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 00:11:40.229
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.yT4184" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-12-29 00:11:40.169
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.yT4184" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Prozentuale Nutzung des RAM: 55%
Installierter physikalischer RAM: 8146.98 MB
Verfügbarer physikalischer RAM: 3621.87 MB
Summe virtueller Speicher: 14287.19 MB
Verfügbarer virtueller Speicher: 8793.6 MB

==================== Laufwerke ================================

Drive c: (Win7HPx64) (Fixed) (Total:465.76 GB) (Free:54.55 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)]
Drive d: (MUNZ_2012) (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS
Drive e: (SAMSUNG) (Fixed) (Total:931.28 GB) (Free:313.13 GB) FAT32

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4E7DE8CA)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: C3178030)
Partition 1: (Active) - (Size=931.5 GB) - (Type=0C)

==================== Ende von Addition.txt ============================
         

Alt 22.01.2016, 18:25   #12
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
Task: {AD6C33B2-B2D5-4DB3-885B-F850B71E16F8} - \Dealply -> Keine Datei <==== ACHTUNG
HKLM-x32\...\Run: [] => [X]
Task: C:\Windows\Tasks\Dealply.job.bak => C:\Users\Basti\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ACHTUNG
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
C:\Users\Basti\hamachi-2-ui.exe
C:\Users\Basti\save.reg
emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt 22.01.2016, 18:44   #13
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Fixlog
Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-01-2016
durchgeführt von Basti (2016-01-22 18:32:58) Run:1
Gestartet von C:\Users\Basti\Desktop
Geladene Profile: Basti (Verfügbare Profile: Basti & Zocken & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
Task: {AD6C33B2-B2D5-4DB3-885B-F850B71E16F8} - \Dealply -> Keine Datei <==== ACHTUNG
HKLM-x32\...\Run: [] => [X]
Task: C:\Windows\Tasks\Dealply.job.bak => C:\Users\Basti\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ACHTUNG
HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
C:\Users\Basti\hamachi-2-ui.exe
C:\Users\Basti\save.reg
emptytemp:
         
*****************

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AD6C33B2-B2D5-4DB3-885B-F850B71E16F8}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD6C33B2-B2D5-4DB3-885B-F850B71E16F8}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply => Schlüssel nicht gefunden. 
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt
C:\Windows\Tasks\Dealply.job.bak => erfolgreich verschoben
"HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer" => Schlüssel erfolgreich entfernt
C:\Users\Basti\hamachi-2-ui.exe => erfolgreich verschoben
C:\Users\Basti\save.reg => erfolgreich verschoben
EmptyTemp: => 20.3 GB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 18:34:55 ====
         

Alt 22.01.2016, 18:47   #14
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



Okay, dann Kontrollscans mit (1) MBAM, (2) ESET und (3) SecurityCheck bitte:


1. Schritt: MBAM

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




2. Schritt: ESET

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




3. Schritt: SecurityCheck

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 23.01.2016, 11:14   #15
Mafia255
 
Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Standard

Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam



MBAM
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 22.01.2016
Suchlaufzeit: 18:48
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.2.0.1024
Malware-Datenbank: v2016.01.22.07
Rootkit-Datenbank: v2016.01.20.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Basti

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 538103
Abgelaufene Zeit: 46 Min., 34 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
ESET...hat ganz schön lange gebraucht. Ich glaub der ist ca 9.5h gelaufen.
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=90def005ca238c4d82c0cf0aa042f148
# end=init
# utc_time=2016-01-22 07:04:38
# local_time=2016-01-22 08:04:38 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=41221
Update Finalize
Updated modules version: 0
Old modules - leave modules
Update Init
Update Download
Update Init
Update Download
Update Finalize
Updated modules version: 27771
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=90def005ca238c4d82c0cf0aa042f148
# end=updated
# utc_time=2016-01-22 07:11:42
# local_time=2016-01-22 08:11:42 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=90def005ca238c4d82c0cf0aa042f148
# engine=27771
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-01-22 07:27:11
# local_time=2016-01-22 08:27:11 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Bitdefender Antivirus'
# compatibility_mode=2067 16777213 50 88 1348 150803496 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 2687906 205120681 0 0
# scanned=4342
# found=1
# cleaned=0
# scan_time=929
sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=90def005ca238c4d82c0cf0aa042f148
# end=init
# utc_time=2016-01-22 07:32:14
# local_time=2016-01-22 08:32:14 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=53251
Update Finalize
Updated modules version: 27771
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=90def005ca238c4d82c0cf0aa042f148
# end=updated
# utc_time=2016-01-22 07:32:40
# local_time=2016-01-22 08:32:40 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=90def005ca238c4d82c0cf0aa042f148
# engine=27771
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-01-23 05:17:10
# local_time=2016-01-23 06:17:10 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Bitdefender Antivirus'
# compatibility_mode=2067 16777213 50 88 35096 150838895 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 2723305 205156080 0 0
# scanned=1227807
# found=12
# cleaned=0
# scan_time=35070
sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir"
sh=D0557816EC4DE99AF7D0CF003B8586A18BD97034 ft=1 fh=73d51bed1f67e8af vn="Win32/Spy.Zbot.YW Trojaner" ac=I fn="C:\ProgramData\NVIDIA\Updatus\Packages\00003367\dao.15411892.exe"
sh=D0557816EC4DE99AF7D0CF003B8586A18BD97034 ft=1 fh=73d51bed1f67e8af vn="Win32/Spy.Zbot.YW Trojaner" ac=I fn="C:\Users\All Users\NVIDIA\Updatus\Packages\00003367\dao.15411892.exe"
sh=6E31A6D60056AE0AA43DC0EF2501E0A83FF0C782 ft=1 fh=ec910ffbdbda110c vn="Variante von Win32/Toolbar.Conduit.AI evtl. unerwünschte Anwendung" ac=I fn="E:\Program Files (x86)\DVDVideoSoft\TB\ConduitInstaller.exe"
sh=359D977D432E4F90FE627B2717144AE873990AC4 ft=1 fh=63c7b0ee3e7f229d vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\Program Files (x86)\DVDVideoSoft\TB\DVDVideoSoftTB.exe"
sh=D94D95A9DC6EA1645BA959FE28C59B6F48B4C9CB ft=0 fh=0000000000000000 vn="HTML/Iframe.B Trojaner" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-06-21 223358\Backup files 2.zip"
sh=659937DC23FB9B389B79495FA8F4C0A3065921CF ft=0 fh=0000000000000000 vn="Win32/Vittalia.A evtl. unerwünschte Anwendung" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-06-21 223358\Backup files 5.zip"
sh=8A92C925A45E2F657502EDCC7545204B7077E7FF ft=0 fh=0000000000000000 vn="Variante von Win32/Adware.Coupons.AA Anwendung" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-06-21 223358\Backup files 15.zip"
sh=023A624441CECD326D021F426FE7103E2B55671D ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-07-28 181346\Backup files 15.zip"
sh=A69C740E036FC438EF9A54B5BEEEC1CCEBA82DA2 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-09-13 223221\Backup files 7.zip"
sh=12AFD48E07E4EBB65057C85307CD7D78C23DB150 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-09-13 223221\Backup files 353.zip"
sh=36DB8ECB21889CA25B7543CE6B749CB57254A073 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-09-13 223221\Backup files 721.zip"
         
Security Check
Code:
ATTFilter
 Results of screen317's Security Check version 1.009  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Bitdefender Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Java 8 Update 65  
 Java version 32-bit out of Date! 
 Adobe Flash Player 20.0.0.286  
 Mozilla Firefox (42.0) 
 Google Chrome (47.0.2526.106) 
 Google Chrome (47.0.2526.111) 
````````Process Check: objlist.exe by Laurent````````  
 Bitdefender Bitdefender 2016 vsserv.exe  
 Bitdefender Agent ProductAgentService.exe   
 Bitdefender Bitdefender 2016 updatesrv.exe  
 Bitdefender Bitdefender 2016 bdagent.exe  
 Bitdefender Bitdefender 2016 bdwtxag.exe  
 Bitdefender Bitdefender 2016 Antispam32 bdwtxapps.exe 
 Bitdefender Bitdefender 2016 downloader.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         

Antwort

Themen zu Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam
antivirus, avira, bonjour, combofix, computer, dnsapi.dll, flash player, google, hijack, home, homepage, installation, keine rückmeldung, langsam, launch, mozilla, officejet, problem, programm, prozesse, registry, rundll, scan, services.exe, software, system, usb, virenfunde, windows



Ähnliche Themen: Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam


  1. Windows + Office keine Rückmeldung, System super langsam
    Alles rund um Windows - 03.01.2016 (2)
  2. Notebook sehr langsam / Keine Rückmeldung
    Log-Analyse und Auswertung - 31.10.2015 (7)
  3. Rechner Win7 super langsam; IE keine Rückmeldung
    Log-Analyse und Auswertung - 08.10.2015 (4)
  4. Laptop extrem langsam und ständig "Keine Rückmeldung"
    Log-Analyse und Auswertung - 25.06.2015 (22)
  5. Windows 7: Computer extrem langsam nach Neustart
    Plagegeister aller Art und deren Bekämpfung - 17.03.2015 (22)
  6. Windows 7 Nach Start Schwarzer Desktop und keine Taskleiste aber Explorer Fenster mit "Computer" offen
    Plagegeister aller Art und deren Bekämpfung - 21.10.2014 (10)
  7. PC langsam (keine Rückmeldung) mehrmals Windows Installer nach Systemstart
    Log-Analyse und Auswertung - 24.07.2014 (16)
  8. Windows 7 nach Zurücksetzen auf Werkseinstellungen extrem langsam, Windows Explorer stürzt dauernd ab
    Log-Analyse und Auswertung - 22.06.2014 (13)
  9. Computer wird langsam und will ständig ein Java-Update durchführen. Virenfund nach scan.
    Log-Analyse und Auswertung - 25.01.2014 (7)
  10. Computer extrem langsam im Netz, Windows 7 Professional
    Plagegeister aller Art und deren Bekämpfung - 22.10.2013 (7)
  11. i havenet.com und Computer extrem langsam, Windows XP
    Plagegeister aller Art und deren Bekämpfung - 10.10.2013 (13)
  12. Mozilla extrem langsam, Malwarebyte meldet PuB.Blabbers
    Plagegeister aller Art und deren Bekämpfung - 03.11.2012 (15)
  13. Firefox langsam - keine Rückmeldung
    Log-Analyse und Auswertung - 11.09.2011 (1)
  14. Computer extrem langsam, stürzt häufig ab, Avira brachte keine Besserung
    Log-Analyse und Auswertung - 15.02.2010 (1)
  15. Windows Explorer langsam/ Rechner extrem lansam
    Log-Analyse und Auswertung - 28.07.2009 (9)
  16. Beide Computer langsam - einer nach 3 Minuten sogar extrem langsam
    Log-Analyse und Auswertung - 09.06.2006 (7)

Zum Thema Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam - Hey, ich habe schon des längeren das Problem, dass sich z.Bsp Google Chrome oder auch andere Anwendungen schließen mit der Meldung: " Programm xyz reagiert nicht mehr". Des Weiteren ist - Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam...
Archiv
Du betrachtest: Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.