Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 17.02.2017, 21:14   #1
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Hi zusammen,

Irgendwie spinnt mein Laptop, seitdem ich mir ein Spiel (Freeware) runterladen wollte. Mir ist schon aufgefallen, dass da viel Malware mitkam, ich habe dann versucht das zu beheben:

Malwarebytes fand jede Menge, alles gelöscht.
Die Probleme sind aber geblieben: ein extrem langsamer Browser, der mit 3 Tabs überfordert ist.
Manchmal möchte ich Seiten aufrufen, werde aber erstmal woanders hingeleitet.
Ich habe hier etwas über "Trotux" gelesen, das kam auf jeden Fall mal als umgeleitete URL.

Nach dem Scan mit Malwarebytes hatte ich nach dem Neustart erstmal nur einen schwarzen Bildschirm mit funktionierender Maus. Habe dann über ein paar Umwege Malwarebytes erneut geöffnet und plötzlich war der normale Desktop wieder da.

Keine Ahnung was los ist. :-D Ich bitte um Hilfe.

FRST habe ich schonmal laufen lassen, TDSSKiller ebenfalls.
Die Logs hängen an.

Ich sage auf jeden Fall schonmal danke!! Schönes Wochenende! :-)

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-02-2017 02
durchgeführt von M (Administrator) auf NOTEBOOK (17-02-2017 20:57:10)
Gestartet von C:\Users\M\Desktop
Geladene Profile: M (Verfügbare Profile: M)
Platform: Windows 8.1 (Update) (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1")
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(IEC) C:\Program Files (x86)\BikaQRssReader\BikaQ.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidMonitorSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Don HO don.h@free.fr) C:\Program Files (x86)\notepad2\notepad2.exe
(pdfforge GmbH) C:\Program Files\PDF Architect 4\creator-ws.exe
(© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\System Setting\TssSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TDUSrv64.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
() C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe
(Mozilla Corporation) C:\Program Files (x86)\Firefox\Firefox.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [] => [X]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672664 2014-06-30] (Realtek Semiconductor)
HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296008 2013-10-22] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-10-09] (TOSHIBA Corporation)
HKLM\...\Run: [ThpSrv] => C:\Windows\system32\thpsrv /logon
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [354144 2013-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [179288 2014-04-17] (TOSHIBA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [517536 2014-04-07] (TOSHIBA)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595480 2016-03-20] (Oracle Corporation)
HKLM-x32\...\Run: [AnyMP4 Free iPhone Data RecoveryAppService] => C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe [88128 2016-10-28] ()
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\MountPoints2: {6fd17b76-c396-11e5-8296-303a64aa1620} - "E:\AutoRun.exe" 
ShellExecuteHooks: Kein Name - {586292BE-F1AE-11E6-81CC-64006A5CFC23} - C:\Users\M\AppData\Roaming\Thujghprikuk\Mervichjomus.dll -> Keine Datei
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Beschränkung - Chrome <======= ACHTUNG

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{01A3239A-66E6-4A37-95D3-D88991033A6A}: [DhcpNameServer] 192.168.1.251 8.8.8.8
Tcpip\..\Interfaces\{76A32D41-DACA-45F5-872C-C9D20FEE27CB}: [DhcpNameServer] 192.168.2.1
ManualProxies: 

Internet Explorer:
==================
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com/?pc=TEJB
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-235318688-4269726762-198329688-1001 -> DefaultScope {B4D5D8A2-D50E-4C0D-BEAC-2CB6CA3D0951} URL = 
SearchScopes: HKU\S-1-5-21-235318688-4269726762-198329688-1001 -> {B4D5D8A2-D50E-4C0D-BEAC-2CB6CA3D0951} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation)
BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-08-05] (pdfforge GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-04-04] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-05-14] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-04] (Oracle Corporation)
Toolbar: HKLM-x32 - PDF Architect 4 Toolbar - {23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} - C:\Program Files (x86)\PDF Architect 4\creator-ie-plugin.dll [2016-08-05] (pdfforge GmbH)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673 [2017-02-17]
FF Extension: (Adblock Plus) - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-12]
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\features\{302110b3-b1bf-4951-82d4-8122016fa5b1}\disableSHA1rollout@mozilla.org.xpi [2017-02-17]
FF ProfilePath: C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673 [2017-02-17]
FF Homepage: Firefox\Firefox\Profiles\9079h1at.default-1481549202673 -> about:home
FF Extension: (SimilarWeb) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\@DA3566E2-F709-11E5-8E87-A604BC8E7F8B.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (FF Adr) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (Deutsch (DE) Language Pack) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\langpack-de@firefox.mozilla.org.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (Adblock Plus) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-12]
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\features\{302110b3-b1bf-4951-82d4-8122016fa5b1}\disableSHA1rollout@mozilla.org.xpi [2017-02-17]
FF SearchPlugin: C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\searchplugins\searchinme.xml [2017-02-17]
FF Extension: (UITBAutoInstaller) - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{edd7fc99-d65c-4979-85c2-ddeed30c50c7} [2016-11-18] [ist nicht signiert]
FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension
FF Extension: (PDF Architect 4 Creator) - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension [2016-09-19] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-15] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-15] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-25] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: PDF Architect 4 -> C:\Program Files (x86)\PDF Architect 4\np-previewer.dll [2016-08-05] (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-235318688-4269726762-198329688-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2017-02-15]

Chrome: 
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://www.trotux.com/?z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=hp
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.trotux.com/?z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=hp"
      
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}&z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=sp
CHR DefaultSearchKeyword: ChromeDefaultData -> trotux
CHR Profile: C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-15] <==== ACHTUNG
CHR Extension: (Kein Name) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-07]
CHR Extension: (Kein Name) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-07]
CHR Extension: (Kein Name) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-07]
CHR Extension: (Kein Name) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-07]
CHR Extension: (Kein Name) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-07]
CHR Extension: (Kein Name) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-07]
CHR Extension: (Kein Name) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-07]

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 ApHidMonitorService; C:\Program Files\Apoint2K\HidMonitorSvc.exe [87384 2014-07-12] (Alps Electric Co., Ltd.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 Apple_Cfg; C:\ProgramData\Apple\Apple Application Support\Support.dll [111104 2017-02-17] () [Datei ist nicht signiert]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042032 2016-12-13] (Microsoft Corporation)
R3 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [21840 2014-06-11] ()
R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [162992 2017-02-17] ()
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [315352 2014-06-17] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-12-09] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-09] (Intel Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-05-30] ()
R2 Ntp2NetSvc; C:\Program Files (x86)\notepad2\notepad2.exe [2340864 2017-02-16] (Don HO don.h@free.fr) [Datei ist nicht signiert]
S2 Ntp2UpSvc; C:\Program Files (x86)\Common Files\ntp2UpSvc\notepad2.exe [2340864 2017-02-16] (Don HO don.h@free.fr) [Datei ist nicht signiert]
S3 PDF Architect 4; C:\Program Files\PDF Architect 4\ws.exe [2438880 2016-08-05] (pdfforge GmbH)
S3 PDF Architect 4 CrashHandler; C:\Program Files\PDF Architect 4\crash-handler-ws.exe [1038048 2016-08-05] (pdfforge GmbH)
R2 PDF Architect 4 Creator; C:\Program Files\PDF Architect 4\creator-ws.exe [851168 2016-08-05] (pdfforge GmbH)
R2 PDF Architect 4 Manager; C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe [972056 2016-05-18] (© pdfforge GmbH.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116088 2013-12-24] (Toshiba Europe GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\M\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-02-16] (TODO: <Company name>) [Datei ist nicht signiert]
R2 WinSnare; C:\Users\M\AppData\Roaming\WinSnare\WinSnare.dll [779776 2017-02-08] (InterSect Alliance Pty Ltd) [Datei ist nicht signiert]
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe [437392 2016-10-10] (Wondershare)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\Dr.Fone for iOS\DriverInstall.exe [97792 2016-11-30] (Wondershare) [Datei ist nicht signiert]
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-05-30] (Intel® Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [191944 2014-05-09] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-02-17] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-09] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3446240 2014-06-18] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [27136 2014-03-24] (Windows (R) Win 7 DDK provider)
S1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-09-08] (Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 ZTEusbmdm6k; \SystemRoot\system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; \SystemRoot\system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; \SystemRoot\system32\DRIVERS\ZTEusbser6k.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-02-17 20:57 - 2017-02-17 20:57 - 00023730 _____ C:\Users\M\Desktop\FRST.txt
2017-02-17 20:56 - 2017-02-17 20:56 - 02422272 _____ (Farbar) C:\Users\M\Desktop\FRST64.exe
2017-02-17 19:42 - 2017-02-17 19:42 - 00000000 ____D C:\Users\M\AppData\Local\Firefox
2017-02-17 19:41 - 2017-02-17 19:41 - 00000219 _____ C:\Users\Public\Desktop\Google Chrome.url
2017-02-17 19:41 - 2017-02-17 19:41 - 00000000 ____D C:\Users\M\AppData\Roaming\Firefox
2017-02-17 19:41 - 2017-02-17 19:41 - 00000000 ____D C:\Users\M\AppData\Local\Standuck
2017-02-17 19:41 - 2017-02-17 19:41 - 00000000 ____D C:\Program Files (x86)\Standuck
2017-02-17 19:41 - 2017-02-17 19:41 - 00000000 ____D C:\Program Files (x86)\Firefox
2017-02-17 19:40 - 2017-02-17 20:17 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-02-17 19:40 - 2017-02-17 20:05 - 00000016 _____ C:\Users\Public\Documents\temp.dat
2017-02-16 12:20 - 2017-02-16 12:20 - 00000000 ____D C:\Users\M\AppData\Local\DOSBox
2017-02-16 12:14 - 2017-02-16 12:14 - 00003218 _____ C:\Windows\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-02-16 12:14 - 2017-02-16 12:14 - 00000000 ____D C:\Users\M\AppData\Roaming\WinSnare
2017-02-16 12:14 - 2017-02-16 12:14 - 00000000 ____D C:\Users\M\AppData\Roaming\WinSAPSvc
2017-02-16 12:14 - 2017-02-16 12:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
2017-02-16 12:14 - 2017-02-16 12:14 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.0)
2017-02-16 12:14 - 2017-02-16 12:14 - 00000000 ____D C:\Program Files (x86)\notepad2
2017-02-16 12:14 - 2017-02-16 12:14 - 00000000 ____D C:\Program Files (x86)\BikaQRssReader
2017-02-16 12:13 - 2017-02-16 12:13 - 00000000 ____D C:\Program Files (x86)\7ldp4n9k
2017-02-15 23:27 - 2017-02-15 23:27 - 00000306 __RSH C:\Users\M\ntuser.pol
2017-02-15 22:35 - 2017-02-15 22:35 - 00003080 _____ C:\Windows\System32\Tasks\{19F6666D-E5AA-4781-BD88-047860B4F25B}
2017-02-15 22:32 - 2017-02-15 22:32 - 00003084 _____ C:\Windows\System32\Tasks\{CA17C8C7-3267-4637-8D2D-7ABA72B5B2D0}
2017-02-15 22:28 - 2017-02-15 22:28 - 00001996 _____ C:\Windows\System32\Tasks\PNlf14iPF6
2017-02-15 22:17 - 2017-02-15 22:17 - 00000306 __RSH C:\ProgramData\ntuser.pol
2017-02-15 22:17 - 2017-02-15 22:17 - 00000000 ____D C:\Windows\system32\GroupPolicy
2017-02-15 22:16 - 2017-02-15 22:33 - 00000000 ____D C:\Program Files (x86)\Up Pro
2017-02-15 22:15 - 2017-02-15 23:20 - 00000000 ____D C:\Program Files (x86)\Ex1iV4c7ul
2017-02-15 22:14 - 2017-02-15 22:34 - 00000000 ____D C:\Windows\system32\SSL
2017-02-15 22:13 - 2017-02-16 23:37 - 00000000 ____D C:\Program Files (x86)\Gherkadomijly
2017-02-15 22:13 - 2017-02-15 23:25 - 00000000 ____D C:\Users\M\AppData\Roaming\Thujghprikuk
2017-02-15 22:13 - 2017-02-15 22:15 - 00000000 ____D C:\Users\M\AppData\Local\Ewudom
2017-02-15 22:13 - 2017-02-15 22:13 - 00006018 _____ C:\Windows\System32\Tasks\Cerigharijeied Monitor
2017-02-15 20:07 - 2017-02-15 20:07 - 00009844 _____ C:\Users\M\Desktop\Abrechnung_4149_0512_20170209.PDF
2017-02-09 19:55 - 2017-02-14 12:54 - 00000000 ____D C:\Users\M\Desktop\Praktikum
2017-02-06 12:48 - 2017-02-16 12:18 - 00000000 ____D C:\Users\M\Desktop\shm neu
2017-01-23 21:53 - 2017-01-23 21:55 - 00000000 ____D C:\Users\M\Desktop\Märklin CS 2 Update 4 1 2
2017-01-18 22:16 - 2017-01-18 22:16 - 00001638 _____ C:\Users\Public\Desktop\AnyMP4 Free iPhone Data Recovery.lnk
2017-01-18 22:16 - 2017-01-18 22:16 - 00000000 ____D C:\Users\M\AppData\Local\AnyMP4 Studio
2017-01-18 22:16 - 2017-01-18 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyMP4
2017-01-18 22:16 - 2017-01-18 22:16 - 00000000 ____D C:\ProgramData\AnyMP4 Studio
2017-01-18 22:16 - 2017-01-18 22:16 - 00000000 ____D C:\Program Files (x86)\AnyMP4 Studio

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-02-17 20:57 - 2016-01-05 21:19 - 00000000 ____D C:\FRST
2017-02-17 20:33 - 2015-02-23 19:36 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-235318688-4269726762-198329688-1001
2017-02-17 20:28 - 2016-01-30 19:54 - 00004980 _____ C:\Users\M\Desktop\aktuellste erledigungen.odt
2017-02-17 20:25 - 2016-11-18 12:07 - 00000000 ____D C:\Users\M\AppData\LocalLow\Mozilla
2017-02-17 20:12 - 2015-03-20 16:02 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-02-17 20:05 - 2015-02-23 20:25 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-02-17 20:05 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-17 20:03 - 2015-02-25 00:55 - 00000000 ____D C:\Users\M\AppData\Roaming\Skype
2017-02-17 19:41 - 2016-10-07 11:08 - 00002306 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-17 19:41 - 2015-02-23 20:17 - 00002022 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-02-17 19:41 - 2015-02-23 20:17 - 00001952 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-02-17 18:25 - 2014-05-06 05:41 - 00765582 _____ C:\Windows\system32\perfh007.dat
2017-02-17 18:25 - 2014-05-06 05:41 - 00159366 _____ C:\Windows\system32\perfc007.dat
2017-02-17 18:25 - 2014-03-18 10:47 - 01776918 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-17 18:25 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf
2017-02-16 22:22 - 2016-01-06 00:18 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-02-16 11:08 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\L2Schemas
2017-02-16 11:07 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-02-15 23:27 - 2015-02-23 19:28 - 00000000 ____D C:\Users\M
2017-02-15 23:25 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\Cursors
2017-02-15 22:11 - 2015-08-07 20:41 - 00000000 ____D C:\Program Files (x86)\WinAce
2017-02-15 09:12 - 2015-03-20 16:02 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-02-15 09:12 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-02-15 09:12 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-02-12 20:36 - 2016-04-12 20:36 - 00000000 ____D C:\Users\M\Knuddels-Stapp
2017-02-11 17:33 - 2015-12-08 21:49 - 00000000 ____D C:\Users\M\Desktop\Vertrag
2017-02-10 11:56 - 2015-12-24 21:40 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-02-10 11:56 - 2014-09-02 02:00 - 00000000 ____D C:\ProgramData\Skype
2017-02-01 12:41 - 2016-12-25 03:51 - 00000000 ____D C:\Users\M\Desktop\6a040bc1f0ba7e2e714a342db23d5905b6382f93-20161212-214503
2017-02-01 00:07 - 2016-11-18 00:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-02-01 00:07 - 2015-02-23 20:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-30 17:18 - 2016-03-07 09:58 - 00011829 _____ C:\Users\M\Desktop\Notenvergleichsrechner_neuePO__Schwerpunkt.xlsx
2017-01-30 16:06 - 2016-10-17 14:36 - 00000000 ____D C:\Users\M\Desktop\Uni
2017-01-23 23:55 - 2015-04-12 18:56 - 00045056 _____ C:\Users\M\Desktop\konzertarchiv.xls
2017-01-21 21:20 - 2016-12-14 11:51 - 00003164 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-01-21 21:20 - 2016-04-23 16:50 - 00002317 _____ C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2017-01-21 21:20 - 2015-02-25 00:23 - 00003172 _____ C:\Windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-235318688-4269726762-198329688-1001
2017-01-21 19:56 - 2016-07-20 09:22 - 00000000 ____D C:\Users\M\Desktop\RAM
2017-01-18 09:46 - 2013-08-22 16:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-01-18 09:45 - 2015-02-25 00:17 - 00000000 ____D C:\Program Files\Microsoft Office 15

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-04-22 18:20 - 2015-04-22 18:20 - 0002533 _____ () C:\Users\M\AppData\Local\recently-used.xbel
2014-09-02 01:22 - 2014-09-02 01:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Einige Dateien in TEMP:
====================
2016-01-26 15:53 - 2007-03-03 20:19 - 0069632 ____R (Huawei Technologies Co., Ltd.) C:\Users\M\AppData\Local\Temp\DataCard_Setup.exe
2016-01-26 15:53 - 2007-01-08 20:08 - 0006144 ____R () C:\Users\M\AppData\Local\Temp\ResetDevice.exe

==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-02-17 09:53

==================== Ende von FRST.txt ============================
         
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-02-2017 02
durchgeführt von M (17-02-2017 20:58:17)
Gestartet von C:\Users\M\Desktop
Windows 8.1 (Update) (X64) (2015-02-23 18:28:35)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-235318688-4269726762-198329688-500 - Administrator - Disabled)
Gast (S-1-5-21-235318688-4269726762-198329688-501 - Limited - Disabled)
M (S-1-5-21-235318688-4269726762-198329688-1001 - Administrator - Enabled) => C:\Users\M

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {A16C3F68-9280-E053-1818-342707FECF4D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.106.303.109 - ALPS ELECTRIC CO., LTD.)
Amazon 1Button App (x32 Version: 2.3.4 - Amazon) Hidden <==== ACHTUNG
AnyMP4 Free iPhone Data Recovery 7.3.28 (HKLM-x32\...\{2F81F350-B3A3-4f2a-A670-5BC3358AC1F6}_is1) (Version: 7.3.28 - AnyMP4 Studio)
Apple Application Support (32-Bit) (HKLM-x32\...\{D079CAAD-0C31-47A2-9AF5-A82F9CD9B221}) (Version: 5.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
BikaQ Rss Reader (HKLM-x32\...\{56B2B28A-E663-4D28-84A3-3846068A7D63}) (Version: 1.0.0 - BikaQ)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
DTS Sound (HKLM-x32\...\{1A938032-98EE-4C0F-9EAB-B3B5B64E28F8}) (Version: 1.01.8500 - DTS, Inc.)
Evernote v. 5.4 (HKLM-x32\...\{59071464-DAEE-11E3-9080-00163E98E7D0}) (Version: 5.4.0.3698 - Evernote Corp.)
Free Image Convert and Resize version 2.1.31.415 (HKLM-x32\...\Free Image Convert and Resize_is1) (Version: 2.1.31.415 - DVDVideoSoft Ltd.)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3643 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.0.1001 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) 4.0 (HKLM-x32\...\{001A29E3-D8DD-46C0-A7F9-B33E3DFA9338}) (Version: 17.0.1419.02 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{85b9d34f-7397-4e39-8600-07942ef6ca04}) (Version: 17.0.5 - Intel Corporation)
iTunes (HKLM\...\{81C96689-EA5B-4B7D-A04F-16326EC51BC2}) (Version: 12.5.4.42 - Apple Inc.)
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
Knuddels Standalone App (HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\Knuddels App ) (Version: "2015.12.6.0" - "Knuddels App")
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Manager (x32 Version: 4.1.4.27792 - 2015 pdfforge GmbH. All rights reserved) Hidden
Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4893.1002 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 51.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 51.0.1 (x86 de)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 51.0.1.6234 - Mozilla)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.34.26215 - pdfforge GmbH)
PDF Architect 4 Create Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDF Architect 4 Edit Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDF Architect 4 View Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.3.2 - pdfforge GmbH)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.315.0 - Tracker Software Products Ltd)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.31.423.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7285 - Realtek Semiconductor Corp.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
SecureW2 EAP Suite 1.1.3 for Windows (HKLM-x32\...\SecureW2 EAP Suite) (Version:  - )
Skype™ 7.32 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Symbaloo (HKLM-x32\...\Symbaloo) (Version: 1.0.0 - Symbaloo Launcher by Toshiba Europe GmbH)
The Last Express (HKLM-x32\...\The Last Express) (Version: 1.0 - DotEmu)
TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.01.01 - Toshiba Corporation)
TOSHIBA Desktop Assist (HKLM\...\{C4CDCEF0-0A7A-4425-887C-33E39533D758}) (Version: 1.03.06.6403 - Toshiba Corporation)
TOSHIBA Display Utility (HKLM\...\{B9A67DC9-EAD3-4B87-B733-F2BA28F0D68E}) (Version: 1.2.4.0 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{94D2A899-0C34-4420-880E-AE337E635AB0}) (Version: 2.5.2.6401 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{1844CFE2-EBA3-490A-8A5E-9BFC646342FD}) (Version: 1.1.5.6402 - Toshiba Corporation)
TOSHIBA HDD Protection (HKLM\...\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.6.02.6403 - Toshiba Corporation)
TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.20 - TOSHIBA)
TOSHIBA Password Utility (HKLM\...\{CD4B9E2C-4295-4920-82F2-C87113822E32}) (Version: 3.03.04.02 - Toshiba Corporation)
TOSHIBA PC Health Monitor (HKLM\...\{A0D34C74-70AC-45E4-9735-A11DA95A5810}) (Version: 4.00.00.6402 - Toshiba Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.2.01.56006006 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{0DFA8761-7735-4DE8-A0EB-2286578DCFC6}) (Version: 2.6.14 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{E3FCDCBE-0A13-4F73-95C1-000A51CF1C8C}) (Version: 2.6.16.0 - Toshiba Corporation)
TOSHIBA Start Screen Option (HKLM\...\{06B71035-F19F-4F76-9875-FFCCD4FC3F83}) (Version: 1.00.05.6401 - Toshiba Corporation)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0036 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{4D57ED72-6B01-40BD-9CA9-012B8FC09CEB}) (Version: 2.0.5.32002 - Toshiba Corporation)
Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.5.1 - Toshiba Europe GmbH)
TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 6.2.4.5  - Toshiba Corporation)
WEB.DE MailCheck für Mozilla Firefox (HKLM-x32\...\1&1 Mail & Media GmbH Toolbar FF) (Version: 3.0.1.1739 - 1&1 Mail & Media GmbH)
WinAce Archiver (HKLM-x32\...\WinAce Archiver) (Version: 2.69 - e-merge GmbH)
WinSnare (HKLM-x32\...\{54A54A73-D8CF-4EBF-BEA7-AD6507ACE4C5}) (Version: 4.1.0 - WinSnare) <==== ACHTUNG
WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
Wondershare Dr.Fone für iOS(Build 7.6.3.3) (HKLM-x32\...\{A26F8BBD-EC10-4bdc-8AD8-F146825A8A63}_is1) (Version: 7.6.3.3 - Wondershare Software Co.,Ltd.)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-235318688-4269726762-198329688-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\M\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {02EE2730-4C68-4CEE-9B12-E0834AAD9165} - System32\Tasks\Cerigharijeied Monitor => C:\Program Files (x86)\Gherkadomijly\prlisp.exe [2017-02-15] (Glarysoft Ltd)
Task: {089B5A9E-E8D3-45AE-AB5F-9196C5B54036} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.)
Task: {1963AB86-3CCF-4921-A86E-0C95FDFC2C41} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2014-03-12] (TOSHIBA Corporation)
Task: {23A4E842-AE98-4C0B-8BD2-7BAF8F38E306} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {244CF0E9-1DC6-4B7D-A2DC-0EE33652C114} - System32\Tasks\dts_apo_service_task => C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_task.exe [2014-06-04] ()
Task: {474488AF-0A50-4378-B8CC-355200CAEF43} - System32\Tasks\{19F6666D-E5AA-4781-BD88-047860B4F25B} => pcalua.exe -a C:\Windows\76d5fa8fd3020718f7133f7301d20d13.exe
Task: {4F2206ED-6C81-45EC-99C7-C8D654E24A86} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-15] (Adobe Systems Incorporated)
Task: {51650620-FD10-4C4B-A929-25D8C0104344} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.)
Task: {81ED1E70-4220-485C-85C4-9089ACAB275F} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: {8A239A25-68F0-4289-AE8B-96E364DA0980} - System32\Tasks\PNlf14iPF6 => C:\Program Files (x86)\Ex1iV4c7ul\updengine.exe  <==== ACHTUNG
Task: {A16E52D6-1AE2-47DE-A6B8-F659339F2216} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation)
Task: {AE0AB1BD-14CC-4495-B555-DF2F6C20A8EB} - System32\Tasks\{CA17C8C7-3267-4637-8D2D-7ABA72B5B2D0} => pcalua.exe -a "C:\Program Files (x86)\Ex1iV4c7ul\uninstall.exe"
Task: {B3129F6F-2266-4F3B-B5C6-2B1625CE58E2} - \Viqoght -> Keine Datei <==== ACHTUNG
Task: {C278E144-B7D0-4012-99F0-1BF832EA664D} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-12-24] (Toshiba Europe GmbH)
Task: {C5B33B85-8E06-43BC-B7BE-6DCD42477D3A} - System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel => C:\Program Files (x86)\BikaQRssReader\BikaQ.exe [2016-12-06] (IEC)
Task: {EE7CF08E-63FD-4CF2-91E1-3CF1FAE0F75B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation)
Task: {F6BD4D82-50B1-4C1C-857B-D6982B174360} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2014-04-03] (TOSHIBA Corporation)
Task: {F71F83E2-0465-4B27-93E1-6245D356AB57} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {F72DE3DC-C245-4A38-82A3-4AC879811071} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

Shortcut: C:\Users\M\Desktop\The Last Express Spielen (MS-DOS).lnk -> C:\Program Files (x86)\DotEmu\The Last Express\LastExpress.bat ()
Shortcut: C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DotEmu\The Last Express\The Last Express Spielen (MS-DOS).lnk -> C:\Program Files (x86)\DotEmu\The Last Express\LastExpress.bat ()

ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> --disable-quic
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> --disable-quic
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> --disable-quic

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-07-15 09:17 - 2015-07-15 09:17 - 00022528 _____ () C:\Windows\System32\ssz2clm.dll
2016-09-01 17:12 - 2016-09-01 17:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-11-17 01:28 - 2016-11-17 01:28 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-25 00:17 - 2016-05-24 08:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2012-07-19 02:38 - 2012-07-19 02:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
2017-01-18 22:16 - 2016-10-28 01:56 - 00088128 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe
2014-06-11 23:06 - 2014-06-11 23:06 - 00021840 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2017-02-17 19:41 - 2017-02-17 03:01 - 00162992 _____ () C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
2016-12-19 09:12 - 2016-12-19 09:12 - 01459712 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\ea494708300f305a0bfdb9484f99e357\Windows.UI.ni.dll
2016-12-19 09:12 - 2016-12-19 09:12 - 00521216 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Data\f68d203e69c1916668d932e1718f7b08\Windows.Data.ni.dll
2013-08-22 08:19 - 2013-08-22 07:54 - 00030208 _____ () C:\Windows\system32\WinMetadata\Windows.Foundation.winmd
2017-02-17 19:41 - 2017-02-17 07:20 - 00111104 _____ () c:\programdata\apple\apple application support\support.dll
2016-01-06 00:19 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2016-01-06 00:19 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2016-01-06 00:19 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2016-01-06 00:19 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2016-01-06 00:19 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2017-01-18 22:16 - 2015-11-16 10:10 - 00887808 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\Framework.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00013824 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\Utility.dll
2017-01-18 22:16 - 2015-06-24 05:53 - 02825216 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\IosDevice.dll
2017-01-18 22:16 - 2011-03-24 08:42 - 00334848 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtXml4.dll
2017-01-18 22:16 - 2011-03-24 08:56 - 07981056 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtGui4.dll
2017-01-18 22:16 - 2011-03-24 08:43 - 00934912 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtNetwork4.dll
2017-01-18 22:16 - 2011-03-24 08:42 - 02145792 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtCore4.dll
2017-01-18 22:16 - 2011-03-24 10:25 - 09843200 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtWebKit4.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00987136 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\libxml2.dll
2017-01-18 22:16 - 2011-03-24 09:06 - 00232960 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\phonon4.dll
2017-01-18 22:16 - 2011-03-24 09:06 - 02530816 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtXmlPatterns4.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00077824 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\zlib1.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00562072 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\SQLite3.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00025600 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qgif4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00027648 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qico4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00119808 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qjpeg4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00220672 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qmng4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00278528 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qtiff4.dll
2014-09-02 01:17 - 2013-12-09 23:26 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\amazon.de -> hxxps://amazon.de

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-235318688-4269726762-198329688-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Toshiba\standard.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{1AE20044-6F71-4787-B4F7-22D2C65F91D0}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{587D8541-F16D-4387-BC22-3B5001E958EF}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{0438D64D-1EE6-4219-A1E4-8F23A895627E}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{8890D3FA-A9D8-418A-9429-63F487CD7DF1}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{8F2A2D7E-8CB0-489A-92AC-EBCFF33CBFDE}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{8D0F9C4D-6C8D-4EA3-8EDD-594A919DFA18}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{0C6E0F95-E835-403C-B85B-D7F1D88E6194}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{A83F76AC-1574-4364-97CD-9DCF891C23FD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D1CBE926-0360-4C39-A7BB-D7F3FFEF0D99}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{63B0833A-DF61-4913-87D2-5C518357417B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{65FDEC65-2BDE-4249-B1D1-F927B1E55532}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{08FB6F16-DF51-457A-A5EA-B762C5D23C91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2C016DCA-D3CC-4EBB-A4A3-A8547F02E607}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{17E3355E-11F7-43C5-886E-44E3F2A9B8E8}] => (Allow) C:\Users\M\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [TCP Query User{1FEFDD73-2C91-4B7C-A0EC-2472218F259B}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{E4FB2BCE-031B-4943-8C30-6DB4D30FD37D}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{44DD637B-C478-4539-A783-31CD086B1199}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{728FCBDC-657D-4F11-A114-C8ECC059149E}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{C30C1B93-724C-4AB5-B803-72BED103BD9B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7FFBF84E-F820-43AA-9347-B25F5F562295}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A9375983-A0F8-43DE-B79F-B104D561C7A9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D622E66C-CBA9-4E2A-BDEF-C410CC75B8B9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A818F6FA-BACB-4911-AB9C-4D6AFF1250BD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{ED96F61E-CD4A-483B-83C3-59AA512122E8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D656335D-447D-4874-93DE-B2ACBF23C34B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{60542E9D-B3C4-46E5-8CBD-E17C468DF3A7}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LINE.exe
FirewallRules: [{3FFFBBF9-E5FB-4320-8C3B-DE58D40E45C2}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LINE.exe
FirewallRules: [{27CD1FC5-585B-4694-ACFB-6370F2BF1FD7}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LineUpdater.exe
FirewallRules: [{8DE37CC8-203E-4E72-A244-0E8B451E59F4}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LineUpdater.exe
FirewallRules: [{3F176F4F-A34E-4F02-9B48-7E47BE659802}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{DB47FF60-2FF4-4458-BD93-1A2575D8339F}] => (Allow) C:\Program Files (x86)\Standuck\Application\chrome.exe
FirewallRules: [{2ADFB605-0A1A-40C6-9613-A99910E000DC}] => (Allow) C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
FirewallRules: [{9E6CDF58-2665-4413-B1E4-7AE1768C4931}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Wiederherstellungspunkte =========================

29-01-2017 18:52:11 Geplanter Prüfpunkt
07-02-2017 22:32:12 Geplanter Prüfpunkt
17-02-2017 10:09:42 Geplanter Prüfpunkt

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: TOSHIBA Web Camera - HD
Description: USB-Videogerät
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (02/17/2017 07:41:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WerFault.exe, Version: 6.3.9600.17415, Zeitstempel: 0x54503815
Name des fehlerhaften Moduls: USER32.dll, Version: 6.3.9600.18233, Zeitstempel: 0x56bb4e1d
Ausnahmecode: 0xc0000142
Fehleroffset: 0x0009d3c2
ID des fehlerhaften Prozesses: 0x1388
Startzeit der fehlerhaften Anwendung: 0x01d2894d80d2a6a7
Pfad der fehlerhaften Anwendung: C:\Windows\SysWOW64\WerFault.exe
Pfad des fehlerhaften Moduls: USER32.dll
Berichtskennung: bf4856e2-f540-11e6-82be-303a64aa1620
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (02/17/2017 04:22:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14797

Error: (02/17/2017 04:22:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 14797

Error: (02/17/2017 04:22:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/16/2017 09:42:27 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9250

Error: (02/16/2017 09:42:27 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9250

Error: (02/16/2017 09:42:24 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/16/2017 05:05:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1297

Error: (02/16/2017 05:05:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1297

Error: (02/16/2017 05:05:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


Systemfehler:
=============
Error: (02/17/2017 08:04:41 PM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI4

Error: (02/17/2017 08:03:41 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{4545DEA0-2DFC-4906-A728-6D986BA399A9}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/17/2017 08:03:41 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{4545DEA0-2DFC-4906-A728-6D986BA399A9}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/17/2017 08:03:35 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{4545DEA0-2DFC-4906-A728-6D986BA399A9}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/17/2017 08:03:35 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{4545DEA0-2DFC-4906-A728-6D986BA399A9}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/17/2017 08:03:29 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{4545DEA0-2DFC-4906-A728-6D986BA399A9}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/17/2017 08:03:29 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{4545DEA0-2DFC-4906-A728-6D986BA399A9}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/17/2017 06:36:22 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{1B1F472E-3221-4826-97DB-2C2324D389AE}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/17/2017 06:35:43 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{BF6C1E47-86EC-4194-9CE5-13C15DCB2001}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/17/2017 06:22:46 PM) (Source: DCOM) (EventID: 10010) (User: notebook)
Description: Der Server "{1B1F472E-3221-4826-97DB-2C2324D389AE}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i3-4005U CPU @ 1.70GHz
Prozentuale Nutzung des RAM: 50%
Installierter physikalischer RAM: 4013.33 MB
Verfügbarer physikalischer RAM: 1967.7 MB
Summe virtueller Speicher: 5421.33 MB
Verfügbarer virtueller Speicher: 2975.54 MB

==================== Laufwerke ================================

Drive c: (TI31360000B) (Fixed) (Total:454.94 GB) (Free:394.99 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Ende von Addition.txt ============================
         

Alt 17.02.2017, 21:14   #2
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



der TDSS Log:

Code:
ATTFilter
Code:
ATTFilter
21:02:29.0335 0x00c0  TDSS rootkit removing tool 3.1.0.12 Nov  7 2016 07:10:01
21:02:29.0335 0x00c0  UEFI system
21:02:36.0473 0x00c0  ============================================================
21:02:36.0474 0x00c0  Current date / time: 2017/02/17 21:02:36.0473
21:02:36.0474 0x00c0  SystemInfo:
21:02:36.0474 0x00c0  
21:02:36.0474 0x00c0  OS Version: 6.3.9600 ServicePack: 0.0
21:02:36.0474 0x00c0  Product type: Workstation
21:02:36.0474 0x00c0  ComputerName: NOTEBOOK
21:02:36.0474 0x00c0  UserName: M
21:02:36.0474 0x00c0  Windows directory: C:\Windows
21:02:36.0474 0x00c0  System windows directory: C:\Windows
21:02:36.0474 0x00c0  Running under WOW64
21:02:36.0474 0x00c0  Processor architecture: Intel x64
21:02:36.0474 0x00c0  Number of processors: 4
21:02:36.0474 0x00c0  Page size: 0x1000
21:02:36.0474 0x00c0  Boot type: Normal boot
21:02:36.0474 0x00c0  CodeIntegrityOptions = 0x00000001
21:02:36.0474 0x00c0  ============================================================
21:02:36.0923 0x00c0  KLMD registered as C:\Windows\system32\drivers\22527358.sys
21:02:36.0923 0x00c0  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 9600.18505, osProperties = 0x19
21:02:37.0153 0x00c0  System UUID: {1A211BCD-3BEB-2720-0CA1-D88725E03294}
21:02:37.0585 0x00c0  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:02:37.0602 0x00c0  ============================================================
21:02:37.0602 0x00c0  \Device\Harddisk0\DR0:
21:02:37.0603 0x00c0  GPT partitions:
21:02:37.0603 0x00c0  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {C0131B0F-3239-11E4-99D8-B86B23CB1180}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x200000
21:02:37.0603 0x00c0  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {C0131B15-3239-11E4-99D8-B86B23CB1180}, Name: Basic data partition, StartLBA 0x200800, BlocksNum 0x32000
21:02:37.0603 0x00c0  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {C0131B17-3239-11E4-99D8-B86B23CB1180}, Name: Basic data partition, StartLBA 0x232800, BlocksNum 0x40000
21:02:37.0603 0x00c0  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {C0131B1D-3239-11E4-99D8-B86B23CB1180}, Name: Basic data partition, StartLBA 0x272800, BlocksNum 0x38DE0800
21:02:37.0603 0x00c0  \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {70D3DAA2-3247-11E4-9FFF-B86B23CB1180}, Name: Basic data partition, StartLBA 0x39053000, BlocksNum 0x1332945
21:02:37.0603 0x00c0  MBR partitions:
21:02:37.0603 0x00c0  ============================================================
21:02:37.0630 0x00c0  C: <-> \Device\Harddisk0\DR0\Partition4
21:02:37.0630 0x00c0  ============================================================
21:02:37.0631 0x00c0  Initialize success
21:02:37.0631 0x00c0  ============================================================
21:03:47.0304 0x12f0  ============================================================
21:03:47.0304 0x12f0  Scan started
21:03:47.0304 0x12f0  Mode: Manual; SigCheck; TDLFS; 
21:03:47.0304 0x12f0  ============================================================
21:03:47.0304 0x12f0  KSN ping started
21:03:47.0455 0x12f0  KSN ping finished: true
21:03:50.0118 0x12f0  ================ Scan system memory ========================
21:03:50.0118 0x12f0  System memory - ok
21:03:50.0118 0x12f0  ================ Scan services =============================
21:03:50.0289 0x12f0  [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1, 41FF7418887AFC8B9C96EF21C5950DD342CC9E3C0D87AFD60A05B988C1D6CC23 ] 1394ohci        C:\Windows\System32\drivers\1394ohci.sys
21:03:50.0337 0x12f0  1394ohci - ok
21:03:50.0359 0x12f0  [ AD508A1A46EC21B740AB31C28EFDFDB1, 9B1046CF0B80723149BD359B55CC0B8B3ABBEAA9038469F542A4C345C503FB02 ] 3ware           C:\Windows\system32\drivers\3ware.sys
21:03:50.0373 0x12f0  3ware - ok
21:03:50.0441 0x12f0  [ E796AE43DDD1844281DB4D57294D17C0, 21AE69615044A96041E46476BE814B52C22624B6C7EA6BFC77BB64F69C3C21F5 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
21:03:50.0475 0x12f0  ACPI - ok
21:03:50.0492 0x12f0  [ AC8279D229398BCF05C3154ADCA86813, 083E86CBE53244D24C334DB1511C77025133AE7875191845764B890A8CA5AFA9 ] acpiex          C:\Windows\system32\Drivers\acpiex.sys
21:03:50.0504 0x12f0  acpiex - ok
21:03:50.0520 0x12f0  [ A8970D9BF23CD309E0403978A1B58F3F, 9946C8477104EEC7DB197E2222F9905307F101C398CCED4B5FD0F86A5622C791 ] acpipagr        C:\Windows\System32\drivers\acpipagr.sys
21:03:50.0530 0x12f0  acpipagr - ok
21:03:50.0540 0x12f0  [ 111A89C99C5B4F1A7BCE5F643DD86F65, 41A2E49FF443927D05F7EF638518108227852984E68D4663C8761178C0B84A45 ] AcpiPmi         C:\Windows\System32\drivers\acpipmi.sys
21:03:50.0551 0x12f0  AcpiPmi - ok
21:03:50.0562 0x12f0  [ 5758387D68A20AE7D3245011B07E36E7, 77832E200E8B0D259552F6F60FE454A887E3EBBB9EA2F3590E6645289A04E293 ] acpitime        C:\Windows\System32\drivers\acpitime.sys
21:03:50.0573 0x12f0  acpitime - ok
21:03:50.0686 0x12f0  [ 89ECFB35517F62C3802B227F288B750E, 47B329FEC98DC634A9068D6B88A331B323D99E9C21D3FE330352210841E715CA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:03:50.0708 0x12f0  AdobeFlashPlayerUpdateSvc - ok
21:03:50.0754 0x12f0  [ 7C1FDF1B48298CBA7CE4BDD4978951AD, 80F4D536E1231B30E836F72ADC8814AE6AA9FEC573FB5F3F965FAC8ABCCAF0F8 ] ADP80XX         C:\Windows\system32\drivers\ADP80XX.SYS
21:03:50.0791 0x12f0  ADP80XX - ok
21:03:50.0841 0x12f0  [ BCD58DACAA1EAAADC115EDD940478F6D, F31613F583C302F62A00E6766B031531C9E193CAED563689B178BA257715B992 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
21:03:50.0868 0x12f0  AeLookupSvc - ok
21:03:50.0932 0x12f0  [ A460C3AF3755A2A79A3C8EFE72E147B5, 62CEA85DA53D86D3E7B5D79F94095C6126FFF3DEE1427BBF3DEF5EA366B4513B ] AFD             C:\Windows\system32\drivers\afd.sys
21:03:50.0960 0x12f0  AFD - ok
21:03:50.0980 0x12f0  [ 7DFAEBA9AD62D20102B576D5CAC45EC8, 9FA5207335303D1E8E9A3C9E1FB82C09AD21B04382F69D777A67E48EE91D2093 ] agp440          C:\Windows\system32\drivers\agp440.sys
21:03:50.0991 0x12f0  agp440 - ok
21:03:51.0023 0x12f0  [ FE14D249D39368CA62D8DA6BC94AC694, E1036E22BFBD3750FD2D3DA6AB939B2DD54E824F4BD3E6539EF0E45AB5453DD1 ] ahcache         C:\Windows\system32\DRIVERS\ahcache.sys
21:03:51.0036 0x12f0  ahcache - ok
21:03:51.0075 0x12f0  [ 14A45BE6F5678339F0EC5752D9849410, DD0F60E96FAC68FBD5B86382E541408C613BD0F871D0E0A1EF9AB6E7B26E545C ] ALG             C:\Windows\System32\alg.exe
21:03:51.0087 0x12f0  ALG - ok
21:03:51.0106 0x12f0  [ 7589DE749DB6F71A68489DCE04158729, 5F35EDD50737985595C9D6703237CA2ADE49AA5443331020899698EB5114A0FB ] AmdK8           C:\Windows\System32\drivers\amdk8.sys
21:03:51.0119 0x12f0  AmdK8 - ok
21:03:51.0136 0x12f0  [ B46D2D89AFF8A9490FA8C98C7A5616E3, BE0765B5423B690E0F097FECD9717FAA95BFDFFDC6CF1B93DE5A19A1B7797879 ] AmdPPM          C:\Windows\System32\drivers\amdppm.sys
21:03:51.0149 0x12f0  AmdPPM - ok
21:03:51.0163 0x12f0  [ D2BF2F94A47D332814910FD47C6BBCD2, FE273D77D119D958676E1197D9EA7B008E3B05C6192B1962A81D4223ED204C35 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
21:03:51.0176 0x12f0  amdsata - ok
21:03:51.0196 0x12f0  [ A8E04943C7BBA7219AA50400272C3C6E, 794C0BD12DF0392654E9A37AE4A24B5BE2D83F1F24F74DD48A1A0BF3AB8B1FF8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
21:03:51.0217 0x12f0  amdsbs - ok
21:03:51.0228 0x12f0  [ CEA5F4F27CFC08E3A44D576811B35F50, 89DF64B81BD109BAABAE93A4603C1617241219F38DDAF325EFE6BD35FF6FD717 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
21:03:51.0239 0x12f0  amdxata - ok
21:03:51.0301 0x12f0  [ 5CF7519C039D0D3F1E348CEABBF23ECA, 434FF48D8CC538B66F03608F3820B1FEDE242F08F715169733A28439FE6AEF24 ] ApfiltrService  C:\Windows\system32\DRIVERS\Apfiltr.sys
21:03:51.0334 0x12f0  ApfiltrService - ok
21:03:51.0382 0x12f0  [ 7F825E61EC81CF17992BA623C911BB2B, 3CB72938BD3C88E16EA6C75BA593A9259F0DA97D71B7C4333372784C8B0FA5C7 ] ApHidMonitorService C:\Program Files\Apoint2K\HidMonitorSvc.exe
21:03:51.0390 0x12f0  ApHidMonitorService - ok
21:03:51.0422 0x12f0  [ 415DD71628795197F7AFC176CBADC74E, 5F0359053A6CD6EE239139E0E6F46E1FA9A73F017C0CE9B7BC052216B2C846EC ] AppID           C:\Windows\system32\drivers\appid.sys
21:03:51.0434 0x12f0  AppID - ok
21:03:51.0456 0x12f0  [ 88358135810B9DFD830A9D3A8C3D149A, DF914DA3828EE2310895D156342E3B3DF5E8C6F6F9B851C359E82A1F48180D4B ] AppIDSvc        C:\Windows\System32\appidsvc.dll
21:03:51.0469 0x12f0  AppIDSvc - ok
21:03:51.0509 0x12f0  [ 734622FBA766DBD65B1803549B24A04A, 3B6872B87A60D4DA265D3B8AB0561A929CFE2C097419183E93D3843422363C89 ] Appinfo         C:\Windows\System32\appinfo.dll
21:03:51.0536 0x12f0  Appinfo - ok
21:03:51.0622 0x12f0  [ 7D811EA7A2AAA49B0446D42CBC1CD338, AFECE5E44E48F756C7EB81D95C9237552AF8A9C02CBE756E0F3D3C6524DE49AD ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
21:03:51.0643 0x12f0  Apple Mobile Device Service - ok
21:03:51.0746 0x12f0  [ 1D1858712DA61C744F1EBBBA1B4EE800, 6342CA5039911428324C95C46F5EDFDC7C31E0232B3952B363D673D68C6AC9DA ] Apple_Cfg       C:\ProgramData\Apple\Apple Application Support\Support.dll
21:03:51.0758 0x12f0  Apple_Cfg - detected UnsignedFile.Multi.Generic ( 1 )
21:03:52.0083 0x12f0  Apple_Cfg ( UnsignedFile.Multi.Generic ) - warning
21:03:52.0083 0x12f0  Force sending object to P2P due to detect: Apple_Cfg
21:03:52.0301 0x12f0  Object send P2P result: true
21:03:52.0586 0x12f0  [ 35E28923A23ADABAA5A1B43256D0AB58, A5F3AF8BBEE58B2165BAFACC5FF8B167B55B020998D3D1565C2229ED8753B269 ] AppReadiness    C:\Windows\system32\AppReadiness.dll
21:03:52.0631 0x12f0  AppReadiness - ok
21:03:52.0711 0x12f0  [ E0F846ADE7DED88981D0908DE56FF160, D8F536438091878724A5004849306ADFB96A2778A9D958ED3DCC0CD9E35160BB ] AppXSvc         C:\Windows\system32\appxdeploymentserver.dll
21:03:52.0761 0x12f0  AppXSvc - ok
21:03:52.0796 0x12f0  [ 65045784366F7EC5FB4E71BCF923187B, 53C215C64FF12E44B097F7CB88E8482438CE0ACBD3C68D8FD38BA0D0D8747FAA ] arcsas          C:\Windows\system32\drivers\arcsas.sys
21:03:52.0811 0x12f0  arcsas - ok
21:03:52.0822 0x12f0  [ 3DB7721F06BC2FEDB25029EA23AB27DA, 221861148C66FE53E4D6EE49C6E656479AB5804A2D348A280A1CD8093E8AB788 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
21:03:52.0846 0x12f0  AsyncMac - ok
21:03:52.0864 0x12f0  [ 74B14192CF79A72F7536B27CB8814FBD, 0CF6BBB63FFE0C12777664D80B2797923844C8392D0FD81D7962EE5EE2C3C3D9 ] atapi           C:\Windows\system32\drivers\atapi.sys
21:03:52.0875 0x12f0  atapi - ok
21:03:52.0908 0x12f0  [ 431FE56F5A2F5937994CB2DA330B47DB, E5AED551529A21494114959251FDF566802DD6D9B9D86A937A0EECE53338CAC7 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
21:03:52.0938 0x12f0  AudioEndpointBuilder - ok
21:03:52.0974 0x12f0  [ 0F03CC00645D7F841879A048787D6AC7, 3ECD2486157469F2EDB63D4868338D1445F2909153DF0AFFE432083730EEE3F5 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
21:03:53.0012 0x12f0  Audiosrv - ok
21:03:53.0048 0x12f0  [ 3C6ED74AF41DD1A5585CE5EF3D00915F, A742F576407776634E5A8E49C60023FFDF395DE0B2DE36662A23F85B79405ED2 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
21:03:53.0067 0x12f0  AxInstSV - ok
21:03:53.0105 0x12f0  [ A4A73F631FE2AA2826FBE4A399B04DEF, 973AACE8DC8DA669D0DF20F17EFDEEABB90AA046AC980948D16A62D39A606A79 ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
21:03:53.0137 0x12f0  b06bdrv - ok
21:03:53.0159 0x12f0  [ 8CC7F7E4AFCBA605921B137ED7992C68, 71406E6D6E9964740A6D90B05329D5492BB90AF40E0630CF2FBF4BA4BA14F2DD ] BasicDisplay    C:\Windows\System32\drivers\BasicDisplay.sys
21:03:53.0172 0x12f0  BasicDisplay - ok
21:03:53.0179 0x12f0  [ 38A82F4EE8C416A6744B6D30381ED768, 9EAAE5F43BA09359130AC04B1DCA0F5D4DF32ED89C02DC5CEB640918948847F7 ] BasicRender     C:\Windows\System32\drivers\BasicRender.sys
21:03:53.0194 0x12f0  BasicRender - ok
21:03:53.0219 0x12f0  [ C1ABB0F7E3BEA48A0417BDF6FF14AB21, 1CAC63A1A0FB9855A27EE977794576A860F6650C9EF7667FFB27F2A2FF721857 ] bcmfn2          C:\Windows\System32\drivers\bcmfn2.sys
21:03:53.0231 0x12f0  bcmfn2 - ok
21:03:53.0279 0x12f0  [ 174394F4EF93C117BF7BE3878046A1B1, D58E868342D1DAFC4B04384A3713F729DF07F408AA6AE4762E6A4244F976526A ] BDESVC          C:\Windows\System32\bdesvc.dll
21:03:53.0307 0x12f0  BDESVC - ok
21:03:53.0322 0x12f0  [ EC19013E4CF87609534165DF897274D6, 8ED45537CF2D58D759A587CCBFDADD5580C7447B0C3B172CF19ECC7585E073FC ] Beep            C:\Windows\system32\drivers\Beep.sys
21:03:53.0338 0x12f0  Beep - ok
21:03:53.0404 0x12f0  [ 5059D93764340D4EAEDF49C47133118F, 26C5779469E04BEAFD290B619CA355648F3911C66D41B22D2C3DCA909FCA0F6E ] BFE             C:\Windows\System32\bfe.dll
21:03:53.0445 0x12f0  BFE - ok
21:03:53.0510 0x12f0  [ 48554994279BFE17A3D2B00076D0CB1A, 6521B1EC0BC6B01F63976370D89FE7DC2E7404899F68B6FAC37A9173B9C5D489 ] BITS            C:\Windows\System32\qmgr.dll
21:03:53.0560 0x12f0  BITS - ok
21:03:53.0623 0x12f0  [ B5C2F92EE1106DFE7BB1CCE4D35B6037, E399C390687589194D8AAD385055F0CFA7D52AD9E837D8FF95008B8EB2B34E50 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
21:03:53.0642 0x12f0  Bonjour Service - ok
21:03:53.0676 0x12f0  [ 4938A9236300A356F97E378491EE4844, 60D892960D48EEF48F8EC4DE4F174EBD0BC0E7B28B6D8723D554CD1979EB55B4 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
21:03:53.0690 0x12f0  bowser - ok
21:03:53.0729 0x12f0  [ FA601515FF2B59F25FDD8EDB1D2A1104, 21DFB53241F8E880F7546B9ADF38F47D6AD0782EC7F8F0284ED69DE7CEF7DCB9 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
21:03:53.0748 0x12f0  BrokerInfrastructure - ok
21:03:53.0792 0x12f0  [ BC111AADACD0BF59D56547461D13AB6E, 91E3619930C29EE4B2683683888BA7EE3CF6B1DDB0C19A14E0880470CBE40EF4 ] Browser         C:\Windows\System32\browser.dll
21:03:53.0817 0x12f0  Browser - ok
21:03:53.0849 0x12f0  [ A8F23D453A424FF4DE04989C4727ECC7, AE4A9081395C7379F1C947EF8243F7609F90C843E086B8E77E1A2C06E36D4381 ] BthAvrcpTg      C:\Windows\System32\drivers\BthAvrcpTg.sys
21:03:53.0860 0x12f0  BthAvrcpTg - ok
21:03:53.0897 0x12f0  [ 1104A31260CCF4318C884E0AE6C513BF, A8F83B558944DEF0F84414A11DC3CB90C3A92377B46760EC0A9B8BC22FB0D5C7 ] BthEnum         C:\Windows\System32\drivers\BthEnum.sys
21:03:53.0909 0x12f0  BthEnum - ok
21:03:53.0951 0x12f0  [ 272A62B660A48AEF366F8A1836CED19F, 78EFAC6B1B2313482329BBFFBF0DDA6462BD88E5BE3C817C5E8E0EAF3074C925 ] BthHFEnum       C:\Windows\System32\drivers\bthhfenum.sys
21:03:53.0963 0x12f0  BthHFEnum - ok
21:03:53.0975 0x12f0  [ 71FE2A48E4C93DDB9798C024880B6C07, 8E93DE29C61A5FA64216231228CB3C4A1A693FE87CAA2C070BCAD7BE2D8ED000 ] bthhfhid        C:\Windows\System32\drivers\BthHFHid.sys
21:03:53.0987 0x12f0  bthhfhid - ok
21:03:54.0051 0x12f0  [ 9307A4B743D277C499CDA8E19E5687AC, 7A01989EC3D54581F292BDEDC9B9445F2ABD50165102617E3089BDD061C63A19 ] BthHFSrv        C:\Windows\System32\BthHFSrv.dll
21:03:54.0071 0x12f0  BthHFSrv - ok
21:03:54.0100 0x12f0  [ D30C67473A2E229662D21F27EAA9AAA5, D009C4836B0DFE963D8E3DEEDE611068838F2BBCAB146E6D70692FAB838E11F1 ] BthLEEnum       C:\Windows\system32\DRIVERS\BthLEEnum.sys
21:03:54.0116 0x12f0  BthLEEnum - ok
21:03:54.0146 0x12f0  [ 66B791F6B11DC4303DD18A224A501542, 502AE4D6FFC6B0FCED081B0E0F61F699F96F20DFEE737B53828F5DEE3BD0FCB1 ] BTHMODEM        C:\Windows\System32\drivers\bthmodem.sys
21:03:54.0157 0x12f0  BTHMODEM - ok
21:03:54.0200 0x12f0  [ FEA8FC81431AD93F44D5FBFBBF096AA7, C0581DF6B2AD24836604B083F4866F93A3F4D9091D382029948A5E6221EDF788 ] BthPan          C:\Windows\System32\drivers\bthpan.sys
21:03:54.0213 0x12f0  BthPan - ok
21:03:54.0286 0x12f0  [ 0CC00ADC1B84C93FB46E1A0974E956E1, 64C759244651B916901F4D0C82C3D6034532A20714A72FD26FC9D050B99E230B ] BTHPORT         C:\Windows\System32\Drivers\BTHport.sys
21:03:54.0331 0x12f0  BTHPORT - ok
21:03:54.0377 0x12f0  [ 043A0F37631BF453F16D478B71320F46, C368296B802984F438852927B8A40EA3F4205724A05828F3173F08EC17228356 ] bthserv         C:\Windows\system32\bthserv.dll
21:03:54.0390 0x12f0  bthserv - ok
21:03:54.0435 0x12f0  [ 08EA90955AED2D959EE67DF6EDF0E2B6, 0A70AA67E5DD24C473C66A570C0FEBA9D398A0F0AD8386FE05D01C4D16346968 ] BTHUSB          C:\Windows\System32\Drivers\BTHUSB.sys
21:03:54.0453 0x12f0  BTHUSB - ok
21:03:54.0476 0x12f0  [ 2FA6510E33F7DEFEC03658B74101A9B9, 61C8C8E3F09B427711464C974EE22E1E01C48E10DB54A4EC9901F482FC36C978 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
21:03:54.0494 0x12f0  cdfs - ok
21:03:54.0531 0x12f0  [ C6796EA22B513E3457514D92DCDB1A3D, 2B893F3950C6B913B934C2089B69F3B0B77F229AE1820907E598455CBB78139C ] cdrom           C:\Windows\System32\drivers\cdrom.sys
21:03:54.0545 0x12f0  cdrom - ok
21:03:54.0583 0x12f0  [ 41C0D7B1A6D4AD119BA6AC0487EA5C8E, 516C2B34BA7507D0DA4148B4ABC0A8C36286570D4EA5C60B28647B1249C15018 ] CertPropSvc     C:\Windows\System32\certprop.dll
21:03:54.0613 0x12f0  CertPropSvc - ok
21:03:54.0623 0x12f0  [ BE9936EDD3267FAAFF94A7835867F00B, 3CEEF2377D45ED38C7CD3CE4C746EC5EA7277EFEC728A5438F0EF5F62FC7C859 ] circlass        C:\Windows\System32\drivers\circlass.sys
21:03:54.0638 0x12f0  circlass - ok
21:03:54.0694 0x12f0  [ 9DA497AEAF35AA7BF7710132FC2A9906, D38DF749222BD0B6E8E6442CC79D56CF827A1430ACAB4F85F7FC469DD31A211C ] CLFS            C:\Windows\system32\drivers\CLFS.sys
21:03:54.0725 0x12f0  CLFS - ok
21:03:54.0883 0x12f0  [ 45AF5F89D707C3F64AC59B627AE34A30, 3E0D50463133FD7D57419258C88D80FF47F2729636D7836EE2567F94B0BA0358 ] ClickToRunSvc   C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
21:03:54.0980 0x12f0  ClickToRunSvc - ok
21:03:55.0036 0x12f0  [ EF6EF85DADC3184A10D8F2F7159973CB, 42FCB286CED95A5DEBC5C0C894FCBC4818A2C818BB71087142FB51A08A0BE96B ] CmBatt          C:\Windows\System32\drivers\CmBatt.sys
21:03:55.0045 0x12f0  CmBatt - ok
21:03:55.0097 0x12f0  [ EFC79D3224D19FD926FFEA0A24729FEF, 41B0B41F7270C82691453679E03194845B9AF08C28800BF39D3CEB7CB1530BB8 ] CNG             C:\Windows\system32\Drivers\cng.sys
21:03:55.0128 0x12f0  CNG - ok
21:03:55.0160 0x12f0  [ 03AAED827C36F35D70900558B8274905, 8E44A23C6013FFAE7769F99CAA3B1D6288DE00A38937F9056903AC265B503AFA ] CompositeBus    C:\Windows\System32\drivers\CompositeBus.sys
21:03:55.0180 0x12f0  CompositeBus - ok
21:03:55.0191 0x12f0  COMSysApp - ok
21:03:55.0198 0x12f0  [ A1FF7DFBFBE164CF92603C651D304DD2, 470ACE5A75E64FC62C950037201199857E974803625DC73BEDBCF6FA4DDD496C ] condrv          C:\Windows\system32\drivers\condrv.sys
21:03:55.0221 0x12f0  condrv - ok
21:03:55.0309 0x12f0  [ C220ADD94A1E5D93C2C0C3CA0D2C583F, 84E42D047D6BD5BEBBE719E8617BC664B026EABDF61AFC5527C48EF03518A18C ] cphs            C:\Windows\SysWow64\IntelCpHeciSvc.exe
21:03:55.0329 0x12f0  cphs - ok
21:03:55.0383 0x12f0  [ 6324F0D18FB52833BA64BC828E29054C, 04118FA1BDFC512F76E4A81FEF34C78B6BD98429DB1D65123B6802B4A1E30584 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
21:03:55.0428 0x12f0  CryptSvc - ok
21:03:55.0476 0x12f0  [ 315BA4BC19316D72B2E037534E048B93, 69613635DB23E6A935673B1025C2010ED3E195473D25368CF74234C4C36910BE ] dam             C:\Windows\system32\drivers\dam.sys
21:03:55.0496 0x12f0  dam - ok
21:03:55.0569 0x12f0  [ 7830CEA509693DE0817DF2F3F2D80E89, 7B1786CD225E2D6BCFA484D0BFB81DD162D5713EAEC80C53317CC6950E3D17F3 ] DcomLaunch      C:\Windows\system32\rpcss.dll
21:03:55.0612 0x12f0  DcomLaunch - ok
21:03:55.0661 0x12f0  [ 95E1ABFB27F8A62ED764805775F0D2F3, 692865DA60C93481E01592883678B2C51FD9AC9A835DFB00A8E3F2DFEE7AB0ED ] defragsvc       C:\Windows\System32\defragsvc.dll
21:03:55.0687 0x12f0  defragsvc - ok
21:03:55.0725 0x12f0  [ FF086DEF5995558CCB1B5AAC2110195D, CED52FF01F9247BFDAFC5C7EFC538F8638146ED715574A422496EE0F846CB079 ] DeviceAssociationService C:\Windows\system32\das.dll
21:03:55.0748 0x12f0  DeviceAssociationService - ok
21:03:55.0784 0x12f0  [ 2C02AFF8383D893F8DBEB07A84F6E77C, 7CC34BAC67E2988E3D16DD6EB6F6785CD2460E3EF7FBD0BD5F86E49793BD473E ] DeviceInstall   C:\Windows\system32\umpnpmgr.dll
21:03:55.0800 0x12f0  DeviceInstall - ok
21:03:55.0834 0x12f0  [ FBFF94FC1FE0699A6BC5ACE270AB9EA1, 7D67E7BE539D9D515A1A6B9282C72114310E874DD1FE51E71F002DBB0E1439FB ] Dfsc            C:\Windows\system32\Drivers\dfsc.sys
21:03:55.0847 0x12f0  Dfsc - ok
21:03:55.0908 0x12f0  [ 3EEAADA3125431980E5804ED7143458A, 381E12C83E3211C255B321D35536F4049D67E31061F8D82155E4D4509E97F43D ] Dhcp            C:\Windows\system32\dhcpcore.dll
21:03:55.0937 0x12f0  Dhcp - ok
21:03:56.0019 0x12f0  [ 0AC9F83A5508935DE89C447473085EEA, 223782B17BACEFB0A663EB13514B68B919C95EF641CDDA7AC30CB239BC4307EC ] DiagTrack       C:\Windows\system32\diagtrack.dll
21:03:56.0078 0x12f0  DiagTrack - ok
21:03:56.0120 0x12f0  [ 8B1E62881D5AC68E673CD94B136B34AC, A0C50F17041E43AC07B67A74F2C408820316201439F47CDEA37A4F5891CC0E6F ] disk            C:\Windows\system32\drivers\disk.sys
21:03:56.0145 0x12f0  disk - ok
21:03:56.0166 0x12f0  [ EB70A894708D1BC176AFD690FF06085F, 0DD2A97F5E1B38D1F7C0D44E50F09EA222B18B3B074CC9C8CD25A7526CB1A112 ] dmvsc           C:\Windows\System32\drivers\dmvsc.sys
21:03:56.0178 0x12f0  dmvsc - ok
21:03:56.0233 0x12f0  [ 561CBB163EB3C8221D9B1D7D1E5CA477, 4D235E73CC127769A257B31A92180552276EC8DDD991F1106815FADEF385E72D ] Dnscache        C:\Windows\System32\dnsrslvr.dll
21:03:56.0258 0x12f0  Dnscache - ok
21:03:56.0290 0x12f0  [ 811EACBCC7C51A03AE11F13CC27B2AB6, FAB94F84950FFB7D3649BAFB8D96D43B880D7FDE8D5B879472AE26C4BC4203B0 ] dot3svc         C:\Windows\System32\dot3svc.dll
21:03:56.0308 0x12f0  dot3svc - ok
21:03:56.0348 0x12f0  [ B99CB575986789A93A683DCF292A43A1, 6ACEA31C723B74003E106FC8303542FCC6DBC4952B6B523F6590D006BE57238D ] DPS             C:\Windows\system32\dps.dll
21:03:56.0365 0x12f0  DPS - ok
21:03:56.0403 0x12f0  [ 00C594D5A1DBD22AD8B2902B9F6EFF94, 2920D62B5F7C49A8AFA80FCAD1E834BBAA670AEBDD7E6F21F0496D1D3CCB4E90 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
21:03:56.0413 0x12f0  drmkaud - ok
21:03:56.0446 0x12f0  [ 263625A4F616538EB867B6306A6590DB, 2A064720C247EAA3446EFDCC9E01D84CBA875905D78DFED0FBD62D1EE422D416 ] DsmSvc          C:\Windows\System32\DeviceSetupManager.dll
21:03:56.0463 0x12f0  DsmSvc - ok
21:03:56.0506 0x12f0  [ DF955BB8B993CF414FD7E718D2419DF8, D15F0AEF3DF51EA55DB95D960758EAFF6BF4BD01F19CDD33C8492E3FB6145918 ] dts_apo_service C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
21:03:56.0514 0x12f0  dts_apo_service - ok
21:03:56.0618 0x12f0  [ F74B839FA0F4E6060CA1DA6B8DA17941, EF493E1F55FCD6A8C32B3D5D5809B7EFCCC9829E9A347522D1E6FE080D41BF37 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
21:03:56.0688 0x12f0  DXGKrnl - ok
21:03:56.0727 0x12f0  [ E253530BD5EDE28F1FF6AF93C4D8034D, 787A70C3E946348F066FB8EB81FCE60157217D93FD78ADC631B5835E8D76A253 ] Eaphost         C:\Windows\System32\eapsvc.dll
21:03:56.0741 0x12f0  Eaphost - ok
21:03:56.0917 0x12f0  [ 114BCFDF367FF37C3F1B0A96AF542E4D, D385BC1D91BC1406091C8C3691C07A90BD60EDE05B1384E5AA3506FCB909C857 ] ebdrv           C:\Windows\system32\drivers\evbda.sys
21:03:57.0072 0x12f0  ebdrv - ok
21:03:57.0119 0x12f0  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] EFS             C:\Windows\System32\lsass.exe
21:03:57.0135 0x12f0  EFS - ok
21:03:57.0154 0x12f0  [ 43531A5993380CC5113242C29D265FD9, EE0076D96F7F3CF29884AC7A67C08A429115A7201354A1FB5DE45FD63ABB4960 ] EhStorClass     C:\Windows\system32\drivers\EhStorClass.sys
21:03:57.0168 0x12f0  EhStorClass - ok
21:03:57.0184 0x12f0  [ 6F8E738A9505A388B1157FDDE7B3101B, 3696CA634102B41EEA11EB9DCA0B24439D8636AED4A7190C138C5E64A2EFB514 ] EhStorTcgDrv    C:\Windows\system32\drivers\EhStorTcgDrv.sys
21:03:57.0204 0x12f0  EhStorTcgDrv - ok
21:03:57.0224 0x12f0  [ DFFFAE1442BA4076E18EED5E406FA0D3, 329FC6FB8D14BEACDBE2A5D4C496EDEA485E838B1DF27566E278F8F8E0D8E82E ] ErrDev          C:\Windows\System32\drivers\errdev.sys
21:03:57.0237 0x12f0  ErrDev - ok
21:03:57.0302 0x12f0  [ F00C593994D57C75273F820653440536, 2DC986D9890EC907405FB2045E6F55ACC384169B45F0B56CCB1A953CF71D9A5D ] EventSystem     C:\Windows\system32\es.dll
21:03:57.0333 0x12f0  EventSystem - ok
21:03:57.0439 0x12f0  [ BF220856C02DF9AB74786BE92246A0E1, 9F35F4A08967634206B965BF94469380C0ACCF8A6C973E90ED85ECECF284CE34 ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
21:03:57.0470 0x12f0  EvtEng - ok
21:03:57.0497 0x12f0  [ 7729D294A555C7AEB281ED8E4D0E01E4, 7269E79D72CCE477AC108294D0DDFB59CF533B03C587599C5AB0507C43A0B6D4 ] exfat           C:\Windows\system32\drivers\exfat.sys
21:03:57.0522 0x12f0  exfat - ok
21:03:57.0558 0x12f0  [ 7C4E0D5900B2A1D11EDD626D6DDB937B, 732F310F8F6016C56F432A81636B13CE0124A802FE8DD91287B618EED22C9A1D ] fastfat         C:\Windows\system32\drivers\fastfat.sys
21:03:57.0578 0x12f0  fastfat - ok
21:03:57.0634 0x12f0  [ 304B6AEC4639A7CCCCF544C6BA6177B2, B75CDD52FD3890B3008E06C503945D1E36478F0EC5E067C8DBC2822D7935D24B ] Fax             C:\Windows\system32\fxssvc.exe
21:03:57.0665 0x12f0  Fax - ok
21:03:57.0685 0x12f0  [ 5D8402613E778B3BD45E687A8372710B, EE9EA10805168D309A609B9019AEC5961EE46D18207B5E0EA2DE4064A5770AF8 ] fdc             C:\Windows\System32\drivers\fdc.sys
21:03:57.0697 0x12f0  fdc - ok
21:03:57.0733 0x12f0  [ 020D2F29009F893ADEFF4405B4B44565, 9F8501064C72933D1442DA00E70392B30D0207EB7D60F50E6648FF363799E6F1 ] fdPHost         C:\Windows\system32\fdPHost.dll
21:03:57.0745 0x12f0  fdPHost - ok
21:03:57.0784 0x12f0  [ E80D2EDD2F88B6E20076A0A4F5A5A245, E3CD6E0BE152B22E8A7340EFFD10CCDB1B632CD3EDF487E83F697D2E22A7D594 ] FDResPub        C:\Windows\system32\fdrespub.dll
21:03:57.0797 0x12f0  FDResPub - ok
21:03:57.0829 0x12f0  [ 47AB7D16EDE434B934AA4D661456C2D5, D375A92FB3E4BB0A8DA5270DACC888E53FB9F514516039FE6DAE4D4EF6B9A970 ] fhsvc           C:\Windows\system32\fhsvc.dll
21:03:57.0845 0x12f0  fhsvc - ok
21:03:57.0868 0x12f0  [ BCFD8B149B3ADF92D0DB1E909CAF0265, 002B085C131473642450176B4B8359F3E5B04350AFB659B9C0F9EB587D1181E7 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
21:03:57.0881 0x12f0  FileInfo - ok
21:03:57.0892 0x12f0  [ A1A66C4FDAFD6B0289523232AFB7D8AF, 0F5832F626BB62190D5F3A088CE6E048D8A400CCF9EA527F06973CAD96D3A81C ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
21:03:57.0911 0x12f0  Filetrace - ok
21:03:57.0999 0x12f0  [ F0798D632FAFF92282ACE51E8A585A87, 55ACEE6EE3C5795C5B4D7738C6064AA088279C722A6B999E2C805313688EE5B1 ] FirefoxU        C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
21:03:58.0010 0x12f0  FirefoxU - ok
21:03:58.0023 0x12f0  [ BE743083CF7063C486A4398E3AEFE59A, 85796D89943DD6FE3932C1ED6CF01470C1B4DFD243C390B07055FFDA3C231551 ] flpydisk        C:\Windows\System32\drivers\flpydisk.sys
21:03:58.0036 0x12f0  flpydisk - ok
21:03:58.0082 0x12f0  [ C1FB505A73FA2E9019D32444AB33B75A, 765F0635C18295855CA4C0394192E8B94BA2EA1C4D74F86B720358ABA019FFAA ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
21:03:58.0112 0x12f0  FltMgr - ok
21:03:58.0186 0x12f0  [ 1EFEF3B4EF2B241263F0F791EA128598, B6CADC254B0779E43E0D6AB6125A7E7ED8FF50C3158911681BA7B43160A08176 ] FontCache       C:\Windows\system32\FntCache.dll
21:03:58.0241 0x12f0  FontCache - ok
21:03:58.0306 0x12f0  [ 1C52387BF5A127F5F3BFB31288F30D93, 90D13F60170CD74304F3036A90D596AA3E1E134455A780310BDF67AC7815F2E7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:03:58.0317 0x12f0  FontCache3.0.0.0 - ok
21:03:58.0354 0x12f0  [ A7C31B168F371E8E6796219F23E354DB, C51C9BF568F1E96CBBE57D2432B38F93F40520086DDB6AAAAC48CBCD1691B441 ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
21:03:58.0367 0x12f0  FsDepends - ok
21:03:58.0378 0x12f0  [ 09F460AFEDCA03F3BF6E07D1CCC9AC42, B832091BC9B2C2FE38A4BCA132ABB58251E851F21EC6F39636E73777AB9A5791 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
21:03:58.0389 0x12f0  Fs_Rec - ok
21:03:58.0450 0x12f0  [ D4AB6EE3D715BC44C00277FD934FAACF, DE8A8B14D7BA73BA1B5A833DE193CA65EDFE512A57D84F4F2CE19D9646D97F4E ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
21:03:58.0489 0x12f0  fvevol - ok
21:03:58.0511 0x12f0  [ 9591D0B9351ED489EAFD9D1CE52A8015, AC64C236C3AE545FCE8ED44A4A87FB86265A453BA60026EC9A4DE2B631E99996 ] FxPPM           C:\Windows\System32\drivers\fxppm.sys
21:03:58.0527 0x12f0  FxPPM - ok
21:03:58.0545 0x12f0  [ FC3EF65EE20D39F8749C2218DBA681CA, 12980F1DE99B25E6920A33556F3ABDA5EC9BFE4757BE602130B5E939D8D25CE3 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
21:03:58.0558 0x12f0  gagp30kx - ok
21:03:58.0593 0x12f0  [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:03:58.0601 0x12f0  GEARAspiWDM - ok
21:03:58.0630 0x12f0  [ 0BF5CAD281E25F1418E5B8875DC5ADD1, 0929AD8437DD78234553D8B2CDF0D6838FD54ACDE1918AFEBE48684EB32A07A3 ] gencounter      C:\Windows\System32\drivers\vmgencounter.sys
21:03:58.0643 0x12f0  gencounter - ok
21:03:58.0685 0x12f0  [ 8DF1254093B5C354CE725EB6B9B0DE19, DE6C5661CC076DA44B8A5D044FDB7280EDCF38D322A98C14FDC82E25586B3014 ] GPIOClx0101     C:\Windows\system32\Drivers\msgpioclx.sys
21:03:58.0700 0x12f0  GPIOClx0101 - ok
21:03:58.0787 0x12f0  [ 9678FD4747A4F2E2318245EE6099482E, C76AE30E8BA77DC330F9CFE5ECEA58FAE0995396742923B564A2257DE24D7B32 ] gpsvc           C:\Windows\System32\gpsvc.dll
21:03:58.0843 0x12f0  gpsvc - ok
21:03:58.0907 0x12f0  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:03:58.0918 0x12f0  gupdate - ok
21:03:58.0926 0x12f0  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:03:58.0936 0x12f0  gupdatem - ok
21:03:58.0971 0x12f0  [ 56F69F7C25FB67C970997D7066DBC593, 83E03A82237DCC5BCB3E722ACECACEF3510CAA619F33E0D7C4D902A482E90418 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:03:58.0994 0x12f0  HdAudAddService - ok
21:03:59.0024 0x12f0  [ D4B7ED39C7900384D9E5C1283F1E7926, F93F98858067B40F1C071EAD0F8E85442A78B95342BC692AF4D726540634923F ] HDAudBus        C:\Windows\System32\drivers\HDAudBus.sys
21:03:59.0037 0x12f0  HDAudBus - ok
21:03:59.0055 0x12f0  [ 10A70BC1871CD955D85CD88372724906, 2480A74854D0A89FF028EE9BA41224D4B2F9B0863066BFC43097920794FEE08D ] HidBatt         C:\Windows\System32\drivers\HidBatt.sys
21:03:59.0066 0x12f0  HidBatt - ok
21:03:59.0086 0x12f0  [ 42F88B57CAE42FC10059C887B3FCFCEA, 9363AA2B8E839A6935A7C6A36C491938DF78024886DCCE6D29CB18E1D6A6D806 ] HidBth          C:\Windows\System32\drivers\hidbth.sys
21:03:59.0100 0x12f0  HidBth - ok
21:03:59.0121 0x12f0  [ C241A8BAFBBFC90176EA0F5240EACC17, 571E20B87818618BE9179986177D55739A240F04D1F740B3C1B7809B9427B767 ] hidi2c          C:\Windows\System32\drivers\hidi2c.sys
21:03:59.0134 0x12f0  hidi2c - ok
21:03:59.0151 0x12f0  [ 9BDDEE26255421017E161CCB9D5EDA95, B766FD5E31708F29384F69418FC33C4BCC6E3064AA553D5B1D30EE0B8B1BFB40 ] HidIr           C:\Windows\System32\drivers\hidir.sys
21:03:59.0163 0x12f0  HidIr - ok
21:03:59.0196 0x12f0  [ EA85B5093DF7B5C3E80362B053740AE2, 1D4251385402A2ADEE8FA1642F54180304F88337DA74989BDE44025ABB145FE5 ] hidserv         C:\Windows\system32\hidserv.dll
21:03:59.0210 0x12f0  hidserv - ok
21:03:59.0246 0x12f0  [ 49676FEC898AB2A11B157F848269A56E, 011E6DDEF9570212520F92FEFD205E1F8104F198B57C40D11BE857FCBCC5F68D ] HidUsb          C:\Windows\System32\drivers\hidusb.sys
21:03:59.0259 0x12f0  HidUsb - ok
21:03:59.0289 0x12f0  [ 93C4315F47F8D635C6DB0DF49FCE10EE, 70C52B8927D54ACD23F27948780B522974250FD5CD81AA9801C3F158C402889F ] hkmsvc          C:\Windows\system32\kmsvc.dll
21:03:59.0308 0x12f0  hkmsvc - ok
21:03:59.0355 0x12f0  [ AC49522ED106BD4B545D6614D71C2445, 40BD738A301170378ECFC031635EB04E2F812B676376CADDD6607ECABEC9255F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:03:59.0374 0x12f0  HomeGroupListener - ok
21:03:59.0426 0x12f0  [ 99932E30CE0283B73BB6E5019E150394, 1F88C2F56A7B8E1F75E6359281F418F9661DA4FB7B7D7B14FA7F718B15D4DCE0 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:03:59.0452 0x12f0  HomeGroupProvider - ok
21:03:59.0479 0x12f0  [ A6AACEA4C785789BDA5912AD1FEDA80D, D197012A5DA6AB3F76FF298336DF0CF027C07ECC71267BAEF5912DE12893E096 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
21:03:59.0492 0x12f0  HpSAMD - ok
21:03:59.0560 0x12f0  [ 76A6FDA32A21515B67633497D8FDB1E4, 7DCAEC3186EAFDD4A53BCD8AAE9B82CBA8871C89B929FFD3BA43E675B95B2495 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
21:03:59.0608 0x12f0  HTTP - ok
21:03:59.0634 0x12f0  [ 90656C0B3864804B090434EFC582404F, BDB60050B729AACB9E009AC7129BEBD6298BBD8A9DB14B817D02E8E13669BD6E ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
21:03:59.0645 0x12f0  hwpolicy - ok
21:03:59.0671 0x12f0  [ 6D6F9E3BF0484967E52F7E846BFF1CA1, C982966BDE6A3E6773D9441ADA7A3B08D13511DFC68D04DF303248B942423F38 ] hyperkbd        C:\Windows\System32\drivers\hyperkbd.sys
21:03:59.0681 0x12f0  hyperkbd - ok
21:03:59.0696 0x12f0  [ 907C870F8C31F8DDD6F090857B46AB25, 308664A31717383D06185875E76C6612407A9F04E7DB28404F574A5706C6715D ] HyperVideo      C:\Windows\system32\DRIVERS\HyperVideo.sys
21:03:59.0708 0x12f0  HyperVideo - ok
21:03:59.0737 0x12f0  [ 49EE0AE9E5B64FFBBD06D55C4984B598, 8866627F9241B24A59C81D8BCC67A4DCA87576F589599BA291D0E323F679EB4D ] i8042prt        C:\Windows\System32\drivers\i8042prt.sys
21:03:59.0751 0x12f0  i8042prt - ok
21:03:59.0769 0x12f0  [ 5D90E32E36CE5D4C535D17CE08AEAF05, 976A463343E8C8308AFBE9E64DF56C430D2241DE002430D00318AB065EB72E4A ] iaLPSSi_GPIO    C:\Windows\System32\drivers\iaLPSSi_GPIO.sys
21:03:59.0776 0x12f0  iaLPSSi_GPIO - ok
21:03:59.0789 0x12f0  [ DD05E7E80F52ADE9AEB292819920F32C, E71AB6A50B0F90C8F94569CE89F66F915A0A4A00D4AC091B2E5E750D88CFC334 ] iaLPSSi_I2C     C:\Windows\System32\drivers\iaLPSSi_I2C.sys
21:03:59.0800 0x12f0  iaLPSSi_I2C - ok
21:03:59.0848 0x12f0  [ 25555186E4FBDF0E30A5DBFC9B9A73F9, 4A9DAC2B56389C5955C343E202C6E81CD3A608E78A4BB7E6ED560719DF02C955 ] iaStorA         C:\Windows\system32\drivers\iaStorA.sys
21:03:59.0878 0x12f0  iaStorA - ok
21:03:59.0920 0x12f0  [ 08BFE413B0B4AA8DFA4B5684CE06D3DC, 95DEEBB203E12EE6E191F5247A74C04AEC0E16DE981FADDC4D6C42EE41D8D079 ] iaStorAV        C:\Windows\system32\drivers\iaStorAV.sys
21:03:59.0947 0x12f0  iaStorAV - ok
21:03:59.0971 0x12f0  [ A2200C3033FA4EF249FC096A7A7D02A2, 5819F5C2020DE2EEE339B0C08CD4B1E3490EAFBBEA1277CE649DB5A5150986B0 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
21:03:59.0997 0x12f0  iaStorV - ok
21:04:00.0023 0x12f0  [ DDE3551C8F25285C5FDF7681933C968D, 3D131AEFB713507BDC473167485987BC90214138F5916DE20EF084F3B3136004 ] ibtusb          C:\Windows\system32\DRIVERS\ibtusb.sys
21:04:00.0035 0x12f0  ibtusb - ok
21:04:00.0042 0x12f0  IEEtwCollectorService - ok
21:04:00.0191 0x12f0  [ 712B795D0920264F2B166D2313FFC43D, 3B9CE043D170B6CFA43573916D293F5E6EE8A8372C72F48F428702D5E36BF0CA ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
21:04:00.0380 0x12f0  igfx - ok
21:04:00.0417 0x12f0  [ C8D1E95D5FE51CABB4041ADD7FF2DE38, 84541189FA24195002536D34C4390FDCCFAF199440190F5D4D33BE2F291889CF ] igfxCUIService1.0.0.0 C:\Windows\system32\igfxCUIService.exe
21:04:00.0437 0x12f0  igfxCUIService1.0.0.0 - ok
21:04:00.0502 0x12f0  [ 5697FD05EC6915A1E7193D658D8D6E05, 0179C3AF29880AA21F609CB471034EA5FA49324ACCE12736866675C037EBEC7A ] IKEEXT          C:\Windows\System32\ikeext.dll
21:04:00.0546 0x12f0  IKEEXT - ok
21:04:00.0576 0x12f0  [ FC7C456AF9B9811499EDBD10616832EE, CA2D8B0E672D3AE449C2FF0B9E142D74E8C72FD877D11162A9F7CC51AF58220F ] intaud_WaveExtensible C:\Windows\system32\drivers\intelaud.sys
21:04:00.0586 0x12f0  intaud_WaveExtensible - ok
21:04:00.0770 0x12f0  [ 733AE8B72C826C71B3941474AD34A6FA, B9684AA192183028994A13F57C67735F21D003E5FCBC0806C5E250A146B5D557 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
21:04:00.0897 0x12f0  IntcAzAudAddService - ok
21:04:00.0947 0x12f0  [ 890144FA6AB42F2B54EE633BF96A019A, 8741904C66170BA11C78D31681E3759537C0BF2338538678BC64234DB8FDE93F ] IntcDAud        C:\Windows\system32\DRIVERS\IntcDAud.sys
21:04:00.0971 0x12f0  IntcDAud - ok
21:04:01.0018 0x12f0  [ DAE6C3099D291EED8922A65C29ABCF52, AD0A932345382824122F84AF97A8609BAE1B916A3B9FD608779A1411E37D3643 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
21:04:01.0048 0x12f0  Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
21:04:01.0262 0x12f0  Detect skipped due to KSN trusted
21:04:01.0262 0x12f0  Intel(R) Capability Licensing Service Interface - ok
21:04:01.0334 0x12f0  [ D45226E3E7A25F1E7CE8DF8FD0A2A098, 7BD74E9E3CB0A83D26BA3FD8177C6B9BA46A8695B6569CF7887FDC87947DA2D6 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
21:04:01.0372 0x12f0  Intel(R) Capability Licensing Service TCP IP Interface - ok
21:04:01.0431 0x12f0  [ 57739E742ABC085C2A4340D4404B4A8B, B4B85C35AC96D11F5940AFCB15A2B2A41D70E3C392E1D4D9353899FA140FF281 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
21:04:01.0442 0x12f0  Intel(R) ME Service - ok
21:04:01.0472 0x12f0  [ 4E448FCFFD00E8D657CD9E48D3E47157, 4A958CF0BF8DAEAE5E008500BA67CE89B21388592811274331EE39CAC1043A00 ] intelide        C:\Windows\system32\drivers\intelide.sys
21:04:01.0484 0x12f0  intelide - ok
21:04:01.0517 0x12f0  [ A770340FC02B999EF0DE6C2A6BC8437C, 214567BE706B21BEA7EC13AF6B10FBFF658000511DBBA79BAA28D1D4EFD029A7 ] intelpep        C:\Windows\system32\drivers\intelpep.sys
21:04:01.0529 0x12f0  intelpep - ok
21:04:01.0549 0x12f0  [ 47E74A8E53C7C24DCE38311E1451C1D9, 79B06E37A552C8A847404D4C572CDB8CF525354D8AE3BEBC06892B7C3B330761 ] intelppm        C:\Windows\System32\drivers\intelppm.sys
21:04:01.0562 0x12f0  intelppm - ok
21:04:01.0585 0x12f0  [ 9DB76D7F9E4E53EFE5DD8C53DE837514, 07BA4EDA9BE9139A689A2C3EFC1D1A4F3D1216625ED145F313398292A2CD5703 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:04:01.0602 0x12f0  IpFilterDriver - ok
21:04:01.0661 0x12f0  [ B452623C1DE60544054E784D94A7AA47, 57AECDEE0AB2B80DFFE11E43608988D46E9169288CB56D644DDE2CAFED6AFD40 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
21:04:01.0707 0x12f0  iphlpsvc - ok
21:04:01.0746 0x12f0  [ C800DCD904016B2BF6AB541083770A3A, 95A8FB9AB2818A4F44AFCBF2715B0B3024DCE38E1406EA639F2A5ECA105D2290 ] IPMIDRV         C:\Windows\System32\drivers\IPMIDrv.sys
21:04:01.0760 0x12f0  IPMIDRV - ok
21:04:01.0794 0x12f0  [ B7342B3C58E91107F6E946A93D9D4EFD, D5DA3C02C5C5A343785745EF6983CC9B5FBD3FB8D49FE9B450523E50212D1A32 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
21:04:01.0812 0x12f0  IPNAT - ok
21:04:01.0862 0x12f0  [ A9E19D4C0E9487544B0A87D511514DA9, 83767BA2A7EE1DE39DBF824B57D898355F8C5E3CE146CA280B0E336428837E70 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
21:04:01.0893 0x12f0  iPod Service - ok
21:04:01.0912 0x12f0  [ AE44C526AB5F8A487D941CEB57B10C97, A783A2EAF7A6FF450FB3F189A5930036FA60D125C42171AC44B6FE2E3DBD6F7A ] IRENUM          C:\Windows\system32\drivers\irenum.sys
21:04:01.0928 0x12f0  IRENUM - ok
21:04:01.0951 0x12f0  [ 8AFEEA3955AA43616A60F133B1D25F21, E99359A4F1D653790133F145CF7C9F97399FD75C5E135AA7E5F989BB660789AF ] isapnp          C:\Windows\system32\drivers\isapnp.sys
21:04:01.0962 0x12f0  isapnp - ok
21:04:02.0004 0x12f0  [ AD3C1F4BD9167420F04052FDA197CF29, 82B687092DFC50E8885656AF06BFB7559930750F4905BC4DBDA3A5D334A443D1 ] iScsiPrt        C:\Windows\System32\drivers\msiscsi.sys
21:04:02.0027 0x12f0  iScsiPrt - ok
21:04:02.0047 0x12f0  [ A90C843F4FDD7A07129BA73C6BE13976, A76DEA9F09E3B2F18D3B646A0DD39E2773EC62E2F3C55421BA61C12190D78C1C ] iwdbus          C:\Windows\System32\drivers\iwdbus.sys
21:04:02.0056 0x12f0  iwdbus - ok
21:04:02.0095 0x12f0  [ 52069AEB42D3D0F97CBCA1085EBF55E6, ADB2EFFF563B3FE113FCD156FD1E469BC24FC1D68AFEDCA21306F76592C9FF88 ] jhi_service     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
21:04:02.0109 0x12f0  jhi_service - ok
21:04:02.0136 0x12f0  [ 5917AFE4A3F695A54B99C1849C8207FE, DD57638966F2F0387DCF9DA4BBAEE3CDD8CC6F1A2D49581A0374D46A565BED4F ] kbdclass        C:\Windows\System32\drivers\kbdclass.sys
21:04:02.0150 0x12f0  kbdclass - ok
21:04:02.0174 0x12f0  [ 8CD840A062F6BDF41DDE3ACB96164B72, AEAE867F3557C1CE6B931E19D7144A3BD3CBABD81B1542667680D54FC24DEBE1 ] kbdhid          C:\Windows\System32\drivers\kbdhid.sys
21:04:02.0186 0x12f0  kbdhid - ok
21:04:02.0223 0x12f0  [ 813871C7D402A05F2E3A7075F9584A05, FF0C2F87EB083F8CE74C679D80C845CDFBFBBC70BE818F899F3336BBB54A3FFB ] kdnic           C:\Windows\system32\DRIVERS\kdnic.sys
21:04:02.0235 0x12f0  kdnic - ok
21:04:02.0253 0x12f0  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] KeyIso          C:\Windows\system32\lsass.exe
21:04:02.0266 0x12f0  KeyIso - ok
21:04:02.0307 0x12f0  [ 304DA394D958BC3B62AF6DF514005B01, 8D17777C82F034E800181E82D30FCED800CBC46CD659AE2E0D972CA1381BD4C2 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
21:04:02.0321 0x12f0  KSecDD - ok
21:04:02.0366 0x12f0  [ 3D4AE520CD6F6FFE549DD195C1F515BE, 2AD3E07F504CE50956C391FD4633D20B354A854C940B3563A67B79BB6E40218F ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
21:04:02.0384 0x12f0  KSecPkg - ok
21:04:02.0412 0x12f0  [ 11AFB527AA370B1DAFD5C36F35F6D45F, 757AD234284467ADB826F7CA0251F58D48866B91995BC867DEA4BAF676947163 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
21:04:02.0424 0x12f0  ksthunk - ok
21:04:02.0455 0x12f0  [ C1591A66028C71147A3E2EAB0B1CCB7E, 82F3D5DCC1614398A144D9791E4BAA814DBA9112677341FD57D5E9834CEDEB41 ] KtmRm           C:\Windows\system32\msdtckrm.dll
21:04:02.0478 0x12f0  KtmRm - ok
21:04:02.0513 0x12f0  [ CA2828DDE4B09FEFFDB7CE68B3D8D00A, B514792FF1EF36C678BB51644A1C420105D5E2CD6DD5A89A3FB252D08277A40C ] LanmanServer    C:\Windows\system32\srvsvc.dll
21:04:02.0536 0x12f0  LanmanServer - ok
21:04:02.0576 0x12f0  [ 3DBD9100745F9B8506B8FEC6FE6CCDE3, C3EF2856A1680AFDE133887E48946CF9CAB6755C3BDC07F0326965DCD4096F62 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:04:02.0597 0x12f0  LanmanWorkstation - ok
21:04:02.0640 0x12f0  [ 8B9F3796EC1762CF255BDB324E5529C8, F73D6BEF19BE20AEB18DA82CB63E9D8B50ACBBE4ED9B646EF0C9F598F6B81F94 ] lfsvc           C:\Windows\System32\GeofenceMonitorService.dll
21:04:02.0667 0x12f0  lfsvc - ok
21:04:02.0691 0x12f0  [ C09010B3680860131631F53E8FE7BAD8, 35F2A06D5F29478D22ABDCC20DA893EF9D96504C65594A0CEA674D1C21B04FF8 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
21:04:02.0707 0x12f0  lltdio - ok
21:04:02.0755 0x12f0  [ DAE98CC96C5EE308BF4EA7B18F226CB8, 7A6CC56BF075010707715AB6608764291E358EDF27C806A025532869004C686B ] lltdsvc         C:\Windows\System32\lltdsvc.dll
21:04:02.0776 0x12f0  lltdsvc - ok
21:04:02.0799 0x12f0  [ 1E2662D847B7D9995C65D90D254A7E0F, AFD4063D2071FFCB6B0EAC0715276D986F42326919C86E525DCE12E1109A93E2 ] lmhosts         C:\Windows\System32\lmhsvc.dll
21:04:02.0811 0x12f0  lmhosts - ok
21:04:02.0858 0x12f0  [ E2952760B05A256FB1412D20A41C89C1, B5AF47DF90D5DC8E6549DE1AFF897669E8200D08083D43DF86E34F6EE19C59DA ] LMS             C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
21:04:02.0875 0x12f0  LMS - ok
21:04:02.0906 0x12f0  [ C755AE4635457AA2A11F79C0DF857ABC, E03D1ACAC155287291FE1BD0B653953ADC94279A74D0152088D698FAA796460F ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
21:04:02.0922 0x12f0  LSI_SAS - ok
21:04:02.0943 0x12f0  [ ADAC09CBE7A2040B7F68B5E5C9A75141, 7865DA7E91404F3642BC444B97F6B7AA42B9523D5EDD7F6365DA236B8EC3410F ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
21:04:02.0959 0x12f0  LSI_SAS2 - ok
21:04:02.0978 0x12f0  [ 04D1274BB9BBCCF12BD12374002AA191, 4B9618F8D25F2278DE1610A70ACAADB074D171D162C3AF27D464F5DC800A8E60 ] LSI_SAS3        C:\Windows\system32\drivers\lsi_sas3.sys
21:04:02.0993 0x12f0  LSI_SAS3 - ok
21:04:03.0012 0x12f0  [ 327469EEF3833D0C584B7E88A76AEC0C, 3D88B5A2D68F93F01B39C6E3D8D5C7A2A20686EFC756086E66AFFF1BC3019B85 ] LSI_SSS         C:\Windows\system32\drivers\lsi_sss.sys
21:04:03.0026 0x12f0  LSI_SSS - ok
21:04:03.0071 0x12f0  [ 9A7A7E45DAED2E8C2816716D8D28236A, C94787988826E546A8DC752BD6BE4EA7423DC3762B2D371DB297A63F865A95FF ] LSM             C:\Windows\System32\lsm.dll
21:04:03.0108 0x12f0  LSM - ok
21:04:03.0149 0x12f0  [ DDEE191AB32DFC22C6465002ECDF5EE4, 190C3930A8449118F9FEDF43C482837EF1C255E6D67F9651156E66A1E2BC6553 ] luafv           C:\Windows\system32\drivers\luafv.sys
21:04:03.0163 0x12f0  luafv - ok
21:04:03.0169 0x12f0  massfilter - ok
21:04:03.0196 0x12f0  [ 78BFF5425E044086E74E78650A359FBB, 294738C10F3ED933D4EC40EA0659372FCF19A3C6D45D356917438CA495F2CB45 ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
21:04:03.0207 0x12f0  MBAMProtector - ok
21:04:03.0290 0x12f0  [ F1A89A34388B5626F1548D393B23ECB1, EA00AC76C4C8C9340753B58A3313C9177A9B98F9F1BDE08F184CD0F53D0C186F ] MBAMService     C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
21:04:03.0332 0x12f0  MBAMService - ok
21:04:03.0400 0x12f0  [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy   C:\Windows\system32\drivers\MBAMSwissArmy.sys
21:04:03.0412 0x12f0  MBAMSwissArmy - ok
21:04:03.0445 0x12f0  [ 898415AC0B5F1D2A9A48ABCB68A6DC4B, E1FD9AE5E22E3E5A18288E66A6184E92A4B63A1274DCE147A7728BB09C6A225E ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
21:04:03.0456 0x12f0  MBAMWebAccessControl - ok
21:04:03.0478 0x12f0  [ EB5C03A070F30D64A6DF80E53B22F53F, 12051B6AEBDEE1E28F24364F25A52BA3A6E282ECF86D6290E34BD38E6D4E066D ] megasas         C:\Windows\system32\drivers\megasas.sys
21:04:03.0494 0x12f0  megasas - ok
21:04:03.0542 0x12f0  [ F6F13533196DE7A582D422B0241E4363, B3CD9B08937AFFF12141B38634AF3A56F5AC5FF3EF03941802B9841DEC559469 ] megasr          C:\Windows\system32\drivers\megasr.sys
21:04:03.0578 0x12f0  megasr - ok
21:04:03.0611 0x12f0  [ EB1D78140D6634C32A46AB1006105EDC, 586F988A7272A7E3F6AA2CC9A001A08A3D178A011AE8C095BB7EAD9FFB45AAB1 ] MEIx64          C:\Windows\system32\DRIVERS\TeeDriverx64.sys
21:04:03.0622 0x12f0  MEIx64 - ok
21:04:03.0657 0x12f0  [ 4C5179DB61B9E14BEC15CDC4B152B2E9, 9048BEC7AD6A3F4B640E99B1F0365AC9A46740B188758FBB2C160EF30AD6E64B ] MMCSS           C:\Windows\system32\mmcss.dll
21:04:03.0682 0x12f0  MMCSS - ok
21:04:03.0695 0x12f0  [ 8B38C44F69259987C95135C9627E2378, E698B82D4EFFF56D66C7FC9866369BA5736FDBDBE2028CC421C51E70DEA74727 ] Modem           C:\Windows\system32\drivers\modem.sys
21:04:03.0721 0x12f0  Modem - ok
21:04:03.0735 0x12f0  [ 601589000CC90F0DF8DA2CC254A3CCC9, D1238A386C41B6C368D9A44B7C112C943995B5403E2A5B4B7346B266DDB0C5A0 ] monitor         C:\Windows\System32\drivers\monitor.sys
21:04:03.0747 0x12f0  monitor - ok
21:04:03.0778 0x12f0  [ 08374E4E5B8914DE6067CBA99F61E930, CBB1390D6523FC968BEDF78FD13699488621ACB2CD1DF55D1606316090548661 ] mouclass        C:\Windows\System32\drivers\mouclass.sys
21:04:03.0790 0x12f0  mouclass - ok
21:04:03.0804 0x12f0  [ 5FCBAB60598AE119E02B4C27DE6B99EA, 36F30094F700DE41C293047ACB49ED1961DD927BEDAD8DFDAB7023D4D24CB0DE ] mouhid          C:\Windows\System32\drivers\mouhid.sys
21:04:03.0816 0x12f0  mouhid - ok
21:04:03.0851 0x12f0  [ 24DABC0A77FAFDC0E379AB3B30F61BB6, E66624ABBF1D742879035F9161F9D3713DE7B759B3D3CF8B96C9E397A02FCF82 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
21:04:03.0865 0x12f0  mountmgr - ok
21:04:03.0913 0x12f0  [ ADF79A49E942C91D1FC9863CBFDD6B58, C2B2A792C4717133DCAE6297EE3F5D985B11D3C1E68A8DC23985AC6B78ACDE98 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:04:03.0929 0x12f0  MozillaMaintenance - ok
21:04:03.0968 0x12f0  [ 6FC047578785B0435F4E2660946D1ADC, 8AEA5659F01FC2F75160922C69622502DABA39F33CB90D5178DD679A1CDE617D ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
21:04:03.0980 0x12f0  mpsdrv - ok
21:04:04.0044 0x12f0  [ D1418745A5472F3930A288E05B9E2C05, 95785F0FA7EE239459C0288DB37E9E54648029FD6FE45A61E6343526D67FFA32 ] MpsSvc          C:\Windows\system32\mpssvc.dll
21:04:04.0085 0x12f0  MpsSvc - ok
21:04:04.0125 0x12f0  [ 3F818C1518DA702C8F10259095C9BDE0, B98C1A6F9A3C01A10503B2B2C45CC89AFF17B346B15990F4DB4820F68BDC62C8 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
21:04:04.0141 0x12f0  MRxDAV - ok
21:04:04.0189 0x12f0  [ C3B0566DE49265AE98405825938C20A1, F8BCA4A5AF21B841C998D4772DA9FF84E45F1356AA1285A1D48C06574A81CA4C ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
21:04:04.0211 0x12f0  mrxsmb - ok
21:04:04.0269 0x12f0  [ 15D7AF1A26CCEBA32DF21A8E2098F463, 84390806AD3A9651DAB803E9257EEE851B898ED2AB56D8936E8C9F6B41967243 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:04:04.0289 0x12f0  mrxsmb10 - ok
21:04:04.0320 0x12f0  [ 0790EEB1EC199F8BE8259E47B373ED23, F9330F43B40675CCB60804182EF04BFBA3837ED14C798788A4B27D65A646D1C7 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:04:04.0337 0x12f0  mrxsmb20 - ok
21:04:04.0370 0x12f0  [ F3C060444777A59FC63D920719E43CCD, 8766A2746E3DFB0749E902F458141269335CA6F0CEDCA3D5F8C204637C19E783 ] MsBridge        C:\Windows\system32\DRIVERS\bridge.sys
21:04:04.0385 0x12f0  MsBridge - ok
21:04:04.0422 0x12f0  [ 915747E010A9414B069173284A9B93F4, 8A335C28FE1EF96DD71485877F2E86155D24B5614ACE05468F4B07E2ACD56331 ] MSDTC           C:\Windows\System32\msdtc.exe
21:04:04.0438 0x12f0  MSDTC - ok
21:04:04.0458 0x12f0  [ D13329FBF8345B28AB30F44CC247DC08, 9C7EC2D4D65E6510EB5B9E61BB0D14F725D7E8FE98D65161C3971E43EF1AB6EB ] Msfs            C:\Windows\system32\drivers\Msfs.sys
21:04:04.0471 0x12f0  Msfs - ok
21:04:04.0487 0x12f0  [ C6B474E46F9E543B875981ED3FFE6ADD, E16687E52FB649C23D92159A1F036CB662202C1E58D961EECDAA528AA4FA669A ] msgpiowin32     C:\Windows\System32\drivers\msgpiowin32.sys
21:04:04.0499 0x12f0  msgpiowin32 - ok
21:04:04.0515 0x12f0  [ 65C92EB9D08DB5C69F28C7FFD4E84E31, D709BA4723225321F665B1157A33A4AE230420752308EF535DA9A41CAC164628 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
21:04:04.0526 0x12f0  mshidkmdf - ok
21:04:04.0535 0x12f0  [ 52299F086AC2DAFD100DD5DC4A8614BA, B36BE0FC96798E5EB8C193C318970E3906961E3ABC3BFAAD73138C76D9A95B0B ] mshidumdf       C:\Windows\System32\drivers\mshidumdf.sys
21:04:04.0546 0x12f0  mshidumdf - ok
21:04:04.0558 0x12f0  [ 36D92AF3343C3A3E57FEF11C449AEA4C, ECC85AA1E530DF55B4A4545798219F87F0FCA66DDD2E37BCEF0850D3C9129DD2 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
21:04:04.0568 0x12f0  msisadrv - ok
21:04:04.0597 0x12f0  [ A06142B3850B06972F1C89748FAA2C02, B1CCC5C8D100FEB384FCC85FED2A77F47DA4C9BA5F6889A130F4D73E30ACAA78 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
21:04:04.0617 0x12f0  MSiSCSI - ok
21:04:04.0623 0x12f0  msiserver - ok
21:04:04.0631 0x12f0  [ A9BBBD2BAE6142253B9195E949AC2E8D, 599D2952D4E0B0B3E02D91E38A30F4900B1ADA330716B887B156A1CB9A3E6EE9 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
21:04:04.0643 0x12f0  MSKSSRV - ok
21:04:04.0681 0x12f0  [ 51B3AC0560848CD6D65AC2033E293113, 73A27E88774C6929328E6C9FC9C389F4DF76D4D4D5CBFC4F51651CC308829628 ] MsLldp          C:\Windows\system32\DRIVERS\mslldp.sys
21:04:04.0695 0x12f0  MsLldp - ok
21:04:04.0712 0x12f0  [ 7B2128EB875DCBC006E6A913211006D6, 97BBD7FF770741FBFC0F181A609AD0954EA926DA203B742E8F08C89AD8FE476E ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
21:04:04.0725 0x12f0  MSPCLOCK - ok
21:04:04.0745 0x12f0  [ 1E88171579B218115C7A772F8DE04BD8, B9EAA835D0BF8F9C4DF8403D95EF1400E8AE38F28F9DBA87657DE2129FEF02D2 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
21:04:04.0757 0x12f0  MSPQM - ok
21:04:04.0779 0x12f0  [ BBE2A455053E63BECBF42C2F9B21FAE0, 7C5DF563499DF59DF9895A1581E47ADF5FD54C94ECEF6C886CDB60E5E95A6DAE ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
21:04:04.0805 0x12f0  MsRPC - ok
21:04:04.0826 0x12f0  [ 8D6B7D515C5CBCDB75B928A0B73C3C5E, 1EB4DC3DD21D2627C78EC3F9931D9E5D033169087E43B5D7C17BF1FF2A0028CD ] mssmbios        C:\Windows\System32\drivers\mssmbios.sys
21:04:04.0837 0x12f0  mssmbios - ok
21:04:04.0855 0x12f0  [ 115019AE01E0EB9C048530D2928AB4A2, 6E2275E85EACF2D0FC784792E0D72A165589D33CBAB3BCFA8E271CA09566C925 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
21:04:04.0867 0x12f0  MSTEE - ok
21:04:04.0885 0x12f0  [ 96D604A35070360F0DD4A7A8AF410B5E, F94DD1A3566C7C8D0A76D6E1E2530552A9B7F99C5DA0DE11829325EAB9F8B7ED ] MTConfig        C:\Windows\System32\drivers\MTConfig.sys
21:04:04.0897 0x12f0  MTConfig - ok
21:04:04.0933 0x12f0  [ 438EA7A2D8D4F9B8AFB64748ACA70BA8, AEEB7B657B645C4006C6D5E8D07ECE581DEE7AD22EA1A587C552574990CF091B ] Mup             C:\Windows\system32\Drivers\mup.sys
21:04:04.0946 0x12f0  Mup - ok
21:04:04.0967 0x12f0  [ B8C35C94DCB2DFEAF03BB42131F2F77F, F0FCF367CA8F722D6ABCF7F363CD406D890D71452E91C3FC6677B47AD74D6324 ] mvumis          C:\Windows\system32\drivers\mvumis.sys
21:04:04.0979 0x12f0  mvumis - ok
21:04:05.0010 0x12f0  [ 1EE90E273094252917843D111E898C94, D0D7D155E3CA022BC1F718327165E44F954A40B96259DEE5266C48ADCC8B4556 ] MyWiFiDHCPDNS   C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
21:04:05.0027 0x12f0  MyWiFiDHCPDNS - ok
21:04:05.0072 0x12f0  [ 8DF30698BDD9492A9D45A4B94FB4A82A, 26B1B2D7E785E29B8BCB74C467C66AE4EBDD481ACFF36334F3BDF4506B778244 ] napagent        C:\Windows\system32\qagentRT.dll
21:04:05.0101 0x12f0  napagent - ok
21:04:05.0152 0x12f0  [ 008F7CED69FD5B30CBDE1E03C6F36A27, D4ADA7834C470B17A3CD976012DC5A511B32545B9F91D23D09A85722E0B75320 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
21:04:05.0176 0x12f0  NativeWifiP - ok
21:04:05.0211 0x12f0  [ BFCE1225D10619029E68946929CEB64C, 499F560331FFBA82E3D673B47F027FDAB7BEE4F2CB5B811D69E0218839F6E6A5 ] NcaSvc          C:\Windows\System32\ncasvc.dll
21:04:05.0228 0x12f0  NcaSvc - ok
21:04:05.0269 0x12f0  [ 267C97373110B7AFD3B46DF60B6CBB85, CEBB99F71D47634BB9C04DF2836DF6B47F15B3073FEFC237F85526DF01E4E38B ] NcbService      C:\Windows\System32\ncbservice.dll
21:04:05.0285 0x12f0  NcbService - ok
21:04:05.0322 0x12f0  [ 0813B71EAF097208DC76CE0605B48AF0, A93A2E6A8FB77B58AC4D580E6F8BF307A25BADC9493994F9BE235EBFB0E1DB22 ] NcdAutoSetup    C:\Windows\System32\NcdAutoSetup.dll
21:04:05.0337 0x12f0  NcdAutoSetup - ok
21:04:05.0393 0x12f0  [ 97DC5967F65503213FD1F1B3E4A6F983, 3EC515856C7CE9B30032F963DC04190F66EE62402A819781DC45B7D088C84229 ] NDIS            C:\Windows\system32\drivers\ndis.sys
21:04:05.0444 0x12f0  NDIS - ok
21:04:05.0485 0x12f0  [ 8CECC8DA55F3274181FD1EA28AD76664, 188112424CEF97FB926A0FB915260B803555A775DD2E1846725A9C8616300F42 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
21:04:05.0497 0x12f0  NdisCap - ok
21:04:05.0528 0x12f0  [ 269882812E9A68FFF1AFE1283D428322, 50B99EBC42DA9B46A8C2C28C9BADCF58AE3079535CDD1227D0F5C86291C715FF ] NdisImPlatform  C:\Windows\system32\DRIVERS\NdisImPlatform.sys
21:04:05.0544 0x12f0  NdisImPlatform - ok
21:04:05.0562 0x12f0  [ 82821F4EEC776B4CF11695A38F3ABA46, 23184F9D31E662855DC4D23EFE7C2FE00E5487D3762B6024704A5D8C87762E1C ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
21:04:05.0574 0x12f0  NdisTapi - ok
21:04:05.0607 0x12f0  [ B832B35055BA2B7B4181861FF94D8E59, 2E60E5D503E88D27E35ECFEE265D51328E93A9C7B9B931F86D9CBC947636BB00 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
21:04:05.0619 0x12f0  Ndisuio - ok
21:04:05.0624 0x12f0  [ 1F58E48EF75F34C35D8E93A0DC535CFE, D65619A6C4B1747F8B05DA08A44EF0E46B5CC384880E04E4755A2BA6CDB3C4EA ] NdisVirtualBus  C:\Windows\System32\drivers\NdisVirtualBus.sys
21:04:05.0643 0x12f0  NdisVirtualBus - ok
21:04:05.0682 0x12f0  [ C3755FCF9A0B5C6FE8ED9E873B85D3CE, 4D3DAFAFA5FB2930522D6DA536E3A731BABE0C24613C190D2330DB415D1A6515 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
21:04:05.0698 0x12f0  NdisWan - ok
21:04:05.0708 0x12f0  [ C3755FCF9A0B5C6FE8ED9E873B85D3CE, 4D3DAFAFA5FB2930522D6DA536E3A731BABE0C24613C190D2330DB415D1A6515 ] NdisWanLegacy   C:\Windows\system32\DRIVERS\ndiswan.sys
21:04:05.0726 0x12f0  NdisWanLegacy - ok
21:04:05.0760 0x12f0  [ DDD7F92A83F74D1476B71FBA9530A8DC, D3F94FC9F48854E09B0B77CE5E1C1DB948D54EAC63C5583437051BB893B5A386 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
21:04:05.0775 0x12f0  NDProxy - ok
21:04:05.0787 0x12f0  [ 3083926D1CC5B56EA0786527B557DD1B, 3C3F0CA0D43398576DBE8F677B353ADDA7E8F56829874958CE668E31261C1590 ] Ndu             C:\Windows\system32\drivers\Ndu.sys
21:04:05.0800 0x12f0  Ndu - ok
21:04:05.0848 0x12f0  [ 42FF4975D032CAE558AE4BB8448F6E5A, 0B8FACF3382443DED79A8004A6AA14C32471A6A1C6BAA543AA9F3FEC52620A6D ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
21:04:05.0861 0x12f0  NetBIOS - ok
21:04:05.0913 0x12f0  [ 9DC17B7D9D84C37C102D379FCC7D4942, D522022ED4395686837E96F57EE29F8065FB749D1195B60D2A406FB33F696C09 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
21:04:05.0932 0x12f0  NetBT - ok
21:04:05.0954 0x12f0  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] Netlogon        C:\Windows\system32\lsass.exe
21:04:05.0966 0x12f0  Netlogon - ok
21:04:06.0007 0x12f0  [ 8F074B62E66B6117D9598C62A12069C5, 5FDB19045D3E2F6D0F0C5158AC2ECB0D5404CD2AF7A319755D7E3753CA3B7CF3 ] Netman          C:\Windows\System32\netman.dll
21:04:06.0028 0x12f0  Netman - ok
21:04:06.0080 0x12f0  [ 4A04B1CD5BFB4A978C5F60E86D6C3E45, A946922C1C38ADD3CF9D3B09DDCC301AE4DAC960A081B2F42B32BE1E7095B3FD ] netprofm        C:\Windows\System32\netprofmsvc.dll
21:04:06.0111 0x12f0  netprofm - ok
21:04:06.0160 0x12f0  [ 1092B3190E69E0C5ECBCE90F171DE047, C16106EEFC324EE80E5F659CB71A5DD69FA800D36D829F5B0E6AD3393BD1BAF7 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:04:06.0175 0x12f0  NetTcpPortSharing - ok
21:04:06.0204 0x12f0  [ D4DCE03870314D3354F3501F9DDD4123, 5BFE8299B3F72B8C39A4965365CBF5BA151024451F02DD872FAD1CC35CF94CEA ] netvsc          C:\Windows\System32\drivers\netvsc63.sys
21:04:06.0218 0x12f0  netvsc - ok
21:04:06.0436 0x12f0  [ 619EE1E89B759F4C3B3B684D1FF24A6D, 3654F7F3AB3FF55C6EE3F5CC17CDC660B9C2A2EDEC4CA118BC8660D38E14C191 ] NETwNb64        C:\Windows\system32\DRIVERS\Netwbw02.sys
21:04:06.0552 0x12f0  NETwNb64 - ok
21:04:06.0812 0x12f0  [ B636B4A8E59A73033B766EA7FD7C3B81, CAC8614DEE83623DE56C969C668A33366793779084B6A23F59ADC98392115F8C ] NETwNe64        C:\Windows\system32\DRIVERS\NETwew02.sys
21:04:06.0966 0x12f0  NETwNe64 - ok
21:04:07.0026 0x12f0  [ E94EB2A95D7D016E119C4D6868788831, 3E4A925D23262FBA0A6432DD635FBE94B0CEF76BD9BB323254B66977497FEE2A ] NlaSvc          C:\Windows\System32\nlasvc.dll
21:04:07.0050 0x12f0  NlaSvc - ok
21:04:07.0085 0x12f0  [ 8F44A2F57C9F1A19AC9C6288C10FB351, 310274DDBAC0FE4BE54ECD3B90C97D82A0F9F5CFCA7A35711A36164DE4B94074 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
21:04:07.0099 0x12f0  Npfs - ok
21:04:07.0105 0x12f0  [ CBDB4F0871C88DF930FC0E8588CA67FC, 7E4AA3EA81A9D532F236FD7896744F07ED07CA9B37A9F18A9778BCCCC67490F2 ] npsvctrig       C:\Windows\System32\drivers\npsvctrig.sys
21:04:07.0117 0x12f0  npsvctrig - ok
21:04:07.0158 0x12f0  [ 0F12A72A753CFD7FB0631EE8D08FE983, 860A96471F6CD90DDA9AB3A48E95CEAD826C87D2FA98A00EF91B61C44A4C8B82 ] nsi             C:\Windows\system32\nsisvc.dll
21:04:07.0171 0x12f0  nsi - ok
21:04:07.0209 0x12f0  [ 0E046FF5823B95326D10CF1B4AF23541, 39D22715003746527AB4BFEDED8C34B695DAF589091AE7F3A2A2C4B8A35675A9 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
21:04:07.0224 0x12f0  nsiproxy - ok
21:04:07.0335 0x12f0  [ 9980B262DBE439AE6BDC91AA985F19EE, E998E4CAE9CD103ADA9CA3C737C4DAD017D056828BFA42A41C7B4E4E108FB13C ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
21:04:07.0444 0x12f0  Ntfs - ok
21:04:07.0476 0x12f0  Ntp2NetSvc - ok
21:04:07.0519 0x12f0  Ntp2UpSvc - ok
21:04:07.0545 0x12f0  [ EF1B290FC9F0E47CC0B537292BEE5904, DBC07BBC54EBC2D2E576B23A4CE116B3DA988577AD0D96CB7289A6748A60F9EA ] Null            C:\Windows\system32\drivers\Null.sys
21:04:07.0560 0x12f0  Null - ok
21:04:07.0584 0x12f0  [ BC6B5942AFF25EBAF62DE43C3807EDF8, CB0FA194084B8C309039D571B5760FDA800E9531B8660C499B4F9977BA5C36D5 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
21:04:07.0599 0x12f0  nvraid - ok
21:04:07.0612 0x12f0  [ 1F43ABFFAC3D6CA356851D517392966E, 6FD7621F67BA94B0E1D8F43BEC2951DBCDEEA1E848BB265AC169E27C01DA68F2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
21:04:07.0628 0x12f0  nvstor - ok
21:04:07.0646 0x12f0  [ 6934A936A7369DFE37B7DBA93F5E5E49, 0900FEEB0CE8D09F0FC60630B5B986034A8BCD3882ED66E47170810C32492892 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
21:04:07.0662 0x12f0  nv_agp - ok
21:04:07.0700 0x12f0  [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:04:07.0714 0x12f0  ose - ok
21:04:07.0757 0x12f0  [ 26657F3B4F39A0E64AF859278B599C4E, 3DD65E0BCEF3045DBA29FB8171CA3FCC9781AED3A1C7A160CF26388CE80A3683 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
21:04:07.0779 0x12f0  p2pimsvc - ok
21:04:07.0826 0x12f0  [ FD8F61F0D1F64BBB3D835F39A3F979C9, E5C5F86576488EA7F605E26C06EE5AFB36506A446F60C894D55E0A148BF7F02D ] p2psvc          C:\Windows\system32\p2psvc.dll
21:04:07.0854 0x12f0  p2psvc - ok
21:04:07.0886 0x12f0  [ 57DCE4FB0467986AE78E1C6FC5240D32, F7F3ADD1B48E4D6BB0A664A2FE556F71ED7453054B4FB667A29BE050C845045B ] Parport         C:\Windows\System32\drivers\parport.sys
21:04:07.0901 0x12f0  Parport - ok
21:04:07.0937 0x12f0  [ BAFF6122CFC9F95CA175AD8C348179A4, 079A912D951DF6A57BC1BDB0D182977EE9592751EC9DDCDA2932BDEDB333850C ] partmgr         C:\Windows\system32\drivers\partmgr.sys
21:04:07.0949 0x12f0  partmgr - ok
21:04:08.0000 0x12f0  [ ABE95ABE27A8BD9701782BBCD82C9925, AE3BA1E9ECDE692374D8DAC95A8DAA289DD2470E3D8D58EFAD9F83A37F3AC8E5 ] PcaSvc          C:\Windows\System32\pcasvc.dll
21:04:08.0026 0x12f0  PcaSvc - ok
21:04:08.0064 0x12f0  [ 91ED124E261EA8FAA1C0FFDF2A71B0C4, 20E41A38067395D03184938983A9BE459717A1941352972DBC28D83D542319EC ] pci             C:\Windows\system32\drivers\pci.sys
21:04:08.0084 0x12f0  pci - ok
21:04:08.0098 0x12f0  [ 346E38FCC6859A727DD28AFAD1F0AFF4, FF3DA26F79B3BC3A5B8A8AA0B9139B9EF70297F4EA1203B1E68FB5A212C3AA58 ] pciide          C:\Windows\system32\drivers\pciide.sys
21:04:08.0108 0x12f0  pciide - ok
21:04:08.0123 0x12f0  [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397, 27A7AF2127B699F4579CB77936F38DC102211E26E5E2947DB808756FE06FC98E ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
21:04:08.0142 0x12f0  pcmcia - ok
21:04:08.0174 0x12f0  [ BF28771D1436C88BE1D297D3098B0F7D, 5F7630916A76A8CF31289E9C577F522B999C74C39E541CD40E62BD53004BEF74 ] pcw             C:\Windows\system32\drivers\pcw.sys
21:04:08.0186 0x12f0  pcw - ok
21:04:08.0218 0x12f0  [ 24A8DFC07E4BAF29AEA26E383D4CC886, 1B903FE52CD816662D37A8113930B4B7019B6996D49F1982D8F42933A3525A67 ] pdc             C:\Windows\system32\drivers\pdc.sys
21:04:08.0231 0x12f0  pdc - ok
21:04:08.0413 0x12f0  [ 87B3DE5B911F767C388D5A56A73D9E93, 7C845A6E9D706BC7CDFD32F9BDEA52BF2FD3D90D45BCF2D48CE704D58F00D23D ] PDF Architect 4 C:\Program Files\PDF Architect 4\ws.exe
21:04:08.0498 0x12f0  PDF Architect 4 - ok
21:04:08.0545 0x12f0  [ 9049B0504C1CB438C0154F72FD7ABC28, 882141B00074CB2EDD3CB7DA745DF4347DA62A90A7E104719DBC13A8BA56B253 ] PDF Architect 4 CrashHandler C:\Program Files\PDF Architect 4\crash-handler-ws.exe
21:04:08.0595 0x12f0  PDF Architect 4 CrashHandler - ok
21:04:08.0662 0x12f0  [ 5F83EDC4A22BC7CC9507E43335C3524E, E349816313DA261C1787159085D920CE975B122DB9FEEBAA132D6593B6DD03EC ] PDF Architect 4 Creator C:\Program Files\PDF Architect 4\creator-ws.exe
21:04:08.0694 0x12f0  PDF Architect 4 Creator - ok
21:04:08.0805 0x12f0  [ 06B2368D9B342AE8E02C929B72E07804, 4EBCFCE5FFE934369ADD035A804BC24160BF94A796A42592B328A35A26DAB79E ] PDF Architect 4 Manager C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe
21:04:08.0846 0x12f0  PDF Architect 4 Manager - ok
21:04:08.0896 0x12f0  [ 0ECEE590F2E2EF969FB74A6FC583A1E6, 1C611D9225C863CF32125F684B324C58BDE1942F4F283F5674133200AC505D44 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
21:04:08.0932 0x12f0  PEAUTH - ok
21:04:09.0016 0x12f0  [ 8E3C640FFF5A963F570233AE99C0FFF3, 3DE978B005BF2E88BA858CE37D9E27BD3584642B8412E22C300A1E739743838A ] PerfHost        C:\Windows\SysWow64\perfhost.exe
21:04:09.0031 0x12f0  PerfHost - ok
21:04:09.0121 0x12f0  [ 70B39E7241F750A248798CE82C44596D, 54A72199EB277EE586611DCBC21654786FD2196F91D5884C4F531297893CC3EC ] pla             C:\Windows\system32\pla.dll
21:04:09.0183 0x12f0  pla - ok
21:04:09.0219 0x12f0  [ 2C02AFF8383D893F8DBEB07A84F6E77C, 7CC34BAC67E2988E3D16DD6EB6F6785CD2460E3EF7FBD0BD5F86E49793BD473E ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
21:04:09.0240 0x12f0  PlugPlay - ok
21:04:09.0268 0x12f0  [ 4570F8A37D221660F3A09D6F4DD4BA94, 0EA190CFFA53DF9CCA2D53A4EF1BCB837BA3F2489A3AC5BD11F6D6ED811D118E ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
21:04:09.0280 0x12f0  PNRPAutoReg - ok
21:04:09.0323 0x12f0  [ 26657F3B4F39A0E64AF859278B599C4E, 3DD65E0BCEF3045DBA29FB8171CA3FCC9781AED3A1C7A160CF26388CE80A3683 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
21:04:09.0347 0x12f0  PNRPsvc - ok
21:04:09.0399 0x12f0  [ 0FF8507A8B901B904E98EB36B9E347EE, FE4A9A6159A8490F3155D166656748722EFDEDCDC447C09155A5AD6D9F5D294D ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
21:04:09.0423 0x12f0  PolicyAgent - ok
21:04:09.0467 0x12f0  [ C8DD82C3035E60D671B8CC5DF128D3A9, 6AABF632CBEDA9A7B553BC9134FF100CB6FDC88000D499D2883408FCEDD97576 ] Power           C:\Windows\system32\umpo.dll
21:04:09.0484 0x12f0  Power - ok
21:04:09.0515 0x12f0  [ E075CC071022BD4E9BE7C024717C0E0A, BE65A8C1082AE8DF8C37CA06B2BCC521478AC153EA7388B03F7FAE3913920E75 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
21:04:09.0533 0x12f0  PptpMiniport - ok
21:04:09.0696 0x12f0  [ E3514CE7CB4AF80ECCA383F065BC77C0, 1EA06D358A07EB9DFB703CEFC4EB834B947B899E0ACFE1C494E2DAED63F1D4B5 ] PrintNotify     C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
21:04:09.0807 0x12f0  PrintNotify - ok
21:04:09.0846 0x12f0  [ ECD373F9571C745894367CC2635EA44F, E08B2A1017DAE1BF10B986DAFAD14BDE20D79703E0EF3A8C700A3753908C1392 ] Processor       C:\Windows\System32\drivers\processr.sys
21:04:09.0858 0x12f0  Processor - ok
21:04:09.0891 0x12f0  [ 6E409D818C6B342544EAE741B1422B85, B4ADFB7809FC42C432C984C3AC13FAFD1B7AD53BCC7FB16E86371DE4C829DD1A ] ProfSvc         C:\Windows\system32\profsvc.dll
21:04:09.0910 0x12f0  ProfSvc - ok
21:04:09.0952 0x12f0  [ FC0141B4A5AD6D637D883C1A89FC45C5, DCE8942C02EEDAE7A57707CA60CAC3A8CD6BA68E6571E405CA882D4DD6D69E43 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
21:04:09.0967 0x12f0  Psched - ok
21:04:10.0003 0x12f0  [ DAA9DEE0A5D5F238C4EE54C2C7FB67C5, 7EC8C603BD92699AC35BDCD294F13BEE90D5C2C195FD93A3F16928BFCF53CA93 ] QWAVE           C:\Windows\system32\qwave.dll
21:04:10.0023 0x12f0  QWAVE - ok
21:04:10.0057 0x12f0  [ 83868EB2924E6BC21A54337C65D614D1, 8D1BE01EBD190231153B867C32120DC8FBFBD32050448A778134D435D76A0B07 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
21:04:10.0070 0x12f0  QWAVEdrv - ok
21:04:10.0080 0x12f0  [ B337B1F1E82A83E20A1743E008E25C0F, A2E8AF041B4CAB78AEE28A2147A189FF0F9D2FCEFB167D60FBBA0A787A5A5BE7 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
21:04:10.0091 0x12f0  RasAcd - ok
21:04:10.0130 0x12f0  [ D5ECE7E7F349EB3C4B152AFF3577280D, 3A5D3E440D1ED72D654BBFE30A73667F055C0AD04375C22C202F21BF75B612B2 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
21:04:10.0143 0x12f0  RasAgileVpn - ok
21:04:10.0183 0x12f0  [ 044638489B4A5FE5334F46C5314A0826, E06CC2A9EF369794DAD69FBB5AFD1676D4283DDAB2AD5E3EFE454C473F62F955 ] RasAuto         C:\Windows\System32\rasauto.dll
21:04:10.0199 0x12f0  RasAuto - ok
21:04:10.0230 0x12f0  [ 235624C147E3CB4C288D5D3D8E8D64A2, B3F182019DBAD9C761FE9F62EAED34AD5902B41A13A766D814FC3E2EA29D8D92 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
21:04:10.0244 0x12f0  Rasl2tp - ok
21:04:10.0276 0x12f0  [ 15C0034561FE5B03FA376F1A6232478B, 0F9B5C2BD7D8803FF3C5ED957D3F0859F2A59B74510E4659FBF05EDCBF230208 ] RasMan          C:\Windows\System32\rasmans.dll
21:04:10.0304 0x12f0  RasMan - ok
21:04:10.0322 0x12f0  [ 5247F308C4103CDC4FE12AE1D235800A, E567CD33CA1897D53795E071B7AFBAF98B2C8F725F8BED0BA90F5EF611520E48 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
21:04:10.0342 0x12f0  RasPppoe - ok
21:04:10.0377 0x12f0  [ 41F631007A158FEBB67F0E2AD1601BBA, EB5EA7277F4178BC27E55BF850AEBCD84B6BED80B2383CFB29548824AAFED135 ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
21:04:10.0393 0x12f0  RasSstp - ok
21:04:10.0455 0x12f0  [ D67ED4AB59D1EF66B05AD1A81AC28B26, 72E750A9A6B484D8BEDE52FA6DABEF4D95765DE491152E1F6C856D0590B50C28 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
21:04:10.0476 0x12f0  rdbss - ok
21:04:10.0497 0x12f0  [ 6B21EBF892CD8CACB71669B35AB5DE32, 0AD8E14FEF16FB2559F5FC8AFBC9D49E4E24F43CF65F480DBF9FAB593269B419 ] rdpbus          C:\Windows\System32\drivers\rdpbus.sys
21:04:10.0508 0x12f0  rdpbus - ok
21:04:10.0541 0x12f0  [ 680C1DAE268B6FB67FA21B389A8B79EF, 856911F77BDD8830C3D683EBE8AF399FB3A54C7D8D0B34EA37D903377F0A39BD ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
21:04:10.0557 0x12f0  RDPDR - ok
21:04:10.0578 0x12f0  [ BC8A79C625568DDB7DCA49D0C2741A64, AB0A7ED9EC2282EC0356D27EA4F70515943E41C2112428B787636B8BEC278933 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
21:04:10.0592 0x12f0  RdpVideoMiniport - ok
21:04:10.0605 0x12f0  [ A26AEC49F318FEE141DDDB2C5F99B3E6, 246AD79FF27E79DEDCB0AAA7C22A8EA6349DEDAC863413A1E378E68FD94C9C4F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
21:04:10.0624 0x12f0  rdyboost - ok
21:04:10.0692 0x12f0  [ 2D39BCFA4DD1081B8F282B623456B858, DD8C433B66B6661F4DBD1784CBD334441B508BE84932DD443F7AD51CEA192BA9 ] ReFS            C:\Windows\system32\drivers\ReFS.sys
21:04:10.0740 0x12f0  ReFS - ok
21:04:10.0808 0x12f0  [ 37F021CF7D670D305C1687781173069E, 286D6D04B0A9C4399086BE8DDA5126CDE462EE3B9F5B40A65CD9CD2B7C160886 ] RegSrvc         C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
21:04:10.0818 0x12f0  RegSrvc - ok
21:04:10.0859 0x12f0  [ DF78648AC3C8DC9D70E6714AF785382F, 56E104939ED0AB5B26AE07BAB1BBB7D15828DBD3A2AD35361423D7ADDA4BA551 ] RemoteAccess    C:\Windows\System32\mprdim.dll
21:04:10.0881 0x12f0  RemoteAccess - ok
21:04:10.0927 0x12f0  [ AC8785B53F8436058C90450DA1840AE7, CC1FFC2713910211F8A6AD532DBB9253ACD188CBD784F1BE6613DF382825A3C1 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
21:04:10.0944 0x12f0  RemoteRegistry - ok
21:04:10.0988 0x12f0  [ DC66AE45816614D2999DCD3834DCCC4E, 1C26225135E851DDD1307F52401DD7055B26B3F3B8FDD693B21042C2896E235A ] RFCOMM          C:\Windows\System32\drivers\rfcomm.sys
21:04:11.0007 0x12f0  RFCOMM - ok
21:04:11.0026 0x12f0  [ 65B9FDE300A6DECC03BA44C4616DCAD6, CAD992982733DD20282A3453DC4E554AE1FC077C35479C0CA4E8BC3A9DCD3BB0 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
21:04:11.0042 0x12f0  RpcEptMapper - ok
21:04:11.0073 0x12f0  [ A737B433ABAF3F2DCB2BD7B4CC582B26, 3B5706B0CF0969A9F82060FD4DCC745F2D83C066B663FE8A4F0F493B64032C9C ] RpcLocator      C:\Windows\system32\locator.exe
21:04:11.0087 0x12f0  RpcLocator - ok
21:04:11.0153 0x12f0  [ 7830CEA509693DE0817DF2F3F2D80E89, 7B1786CD225E2D6BCFA484D0BFB81DD162D5713EAEC80C53317CC6950E3D17F3 ] RpcSs           C:\Windows\system32\rpcss.dll
21:04:11.0191 0x12f0  RpcSs - ok
21:04:11.0210 0x12f0  [ 2D05A5508F4685412F2B89E8C2189ABC, 82F12B4E0E73411A121EFD35FBD3B44CBBC0AE96ACFBB45D8C3C3777E2EA320D ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
21:04:11.0229 0x12f0  rspndr - ok
21:04:11.0269 0x12f0  [ FA1A7DB4E607908BE8A0A2CB426DBD68, B13C51E9E85CB9A32EC4FE9A13976D52E678B2A743AFE112721510863733FF69 ] RSUSBVSTOR      C:\Windows\System32\Drivers\RtsUVStor.sys
21:04:11.0286 0x12f0  RSUSBVSTOR - ok
21:04:11.0336 0x12f0  [ 3AB1AA5155684F40E2F5215A258D2471, 3D6A5F603FA6809651A006EA31F57920A45642B6B9E8EC80E5399D1301F635E4 ] RTL8168         C:\Windows\system32\DRIVERS\Rt630x64.sys
21:04:11.0387 0x12f0  RTL8168 - ok
21:04:11.0412 0x12f0  [ 1A063730F221B2746FF00457AE17E4F0, 39A3C258CBFE3BC566C63528C9020A3BC9409736AE5289C08A7BA471D8409263 ] s3cap           C:\Windows\System32\drivers\vms3cap.sys
21:04:11.0424 0x12f0  s3cap - ok
21:04:11.0453 0x12f0  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] SamSs           C:\Windows\system32\lsass.exe
21:04:11.0466 0x12f0  SamSs - ok
21:04:11.0483 0x12f0  [ C624A1B32211C3166EDB3F4AB02A30B7, 6B2A4607DB52D74242787ED9DF9067058983D310431D8612D2B0236E6201E681 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
21:04:11.0496 0x12f0  sbp2port - ok
21:04:11.0544 0x12f0  [ 74A3B67F03877D06B09B1B40C5ED582E, A8FF9BF416F0BF365BFB4E1796859825C811A74B5E54DDDCE8345193BEEBE206 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
21:04:11.0563 0x12f0  SCardSvr - ok
21:04:11.0600 0x12f0  [ 8B9C4D55B4A536FB01C360DDB9533574, 9B939FE68F6F9C171ED0D91E2CE1E67515295D34EC23606BCDFD097DCC8CFD4A ] ScDeviceEnum    C:\Windows\System32\ScDeviceEnum.dll
21:04:11.0619 0x12f0  ScDeviceEnum - ok
21:04:11.0651 0x12f0  [ 13BEA6C882D4D877A5A85CA149C86BC1, 8E9BE5C2A36D5881D9985C3A31309FE03966EA13A3541D3C5B542AB67FA0D55F ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
21:04:11.0663 0x12f0  scfilter - ok
21:04:11.0746 0x12f0  [ 3151A020E03DDE31AAC49F35C5EFB4DB, 5ABB1103009979F86C862357E28F37C2744979F2C99F7CF6ABB4EB1B8416B3F6 ] Schedule        C:\Windows\system32\schedsvc.dll
21:04:11.0797 0x12f0  Schedule - ok
21:04:11.0838 0x12f0  [ 41C0D7B1A6D4AD119BA6AC0487EA5C8E, 516C2B34BA7507D0DA4148B4ABC0A8C36286570D4EA5C60B28647B1249C15018 ] SCPolicySvc     C:\Windows\System32\certprop.dll
21:04:11.0857 0x12f0  SCPolicySvc - ok
21:04:11.0884 0x12f0  [ C54B6B2170BF628FD42F799A66956D75, BCF460A124CAA6F1F1A9A7BCBDCC2D5E39B0404D96B7C9FFAC806E041782B91E ] sdbus           C:\Windows\System32\drivers\sdbus.sys
21:04:11.0905 0x12f0  sdbus - ok
21:04:12.0055 0x12f0  [ D777F1417D9BB9F66CD9D9C3B61F730F, 0CBD830EB9D2B0F1946131F20907793B2D68A3BCEEC3EA5416972149F73DC815 ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
21:04:12.0112 0x12f0  SDScannerService - ok
21:04:12.0138 0x12f0  [ 0B1E929D11A8E358106955603FAC65E8, A5EC91BFC0873EC6AB1D0DB4E91654BD35339BD680E7E82DA2DC64996B4AE515 ] sdstor          C:\Windows\System32\drivers\sdstor.sys
21:04:12.0154 0x12f0  sdstor - ok
21:04:12.0315 0x12f0  [ 94653C9CFDC15B30EEECD94BA7219654, 59F54AC9BC79C1BFBEA84992181C58AF434A3DDDF473C9BE942D3462875A8375 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
21:04:12.0466 0x12f0  SDUpdateService - ok
21:04:12.0534 0x12f0  [ A7C46DA2D7C25DAA810E1DE4B14D1478, 4A995EFBBB7B192CC25B24286D4864160692F4D16EA13E7138D17272B495ED6B ] SDWSCService    C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
21:04:12.0554 0x12f0  SDWSCService - ok
21:04:12.0572 0x12f0  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
21:04:12.0583 0x12f0  secdrv - ok
21:04:12.0613 0x12f0  [ 6627154693B6C2B8A59727F5B38728E8, F08251EE3436400295F120D48F3763E6F11BBF4132D674AD3E8112B6B3538455 ] seclogon        C:\Windows\system32\seclogon.dll
21:04:12.0629 0x12f0  seclogon - ok
21:04:12.0679 0x12f0  [ 81FE9A81EDF8016816C9E91FBFBF7D35, 87FB92A3D15F312F0B9C423EF851061A944B013E5668D8C9A441B4DC0EB690AF ] SENS            C:\Windows\System32\sens.dll
21:04:12.0697 0x12f0  SENS - ok
21:04:12.0730 0x12f0  [ 6E4012AE67F09F867EF620C8D5524C0B, 63933E51F8E413E63481369CE2F9FD224560550FBD3BD2B4573E9F4AD88708A2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
21:04:12.0749 0x12f0  SensrSvc - ok
21:04:12.0768 0x12f0  [ DB2FF24CE0BDD15FE75870AFE312BA89, 7DB0D978C92CD0A0A81F7AB46FE323B4929CEA01585B0F330921E6DFA7DE1B85 ] SerCx           C:\Windows\system32\drivers\SerCx.sys
21:04:12.0781 0x12f0  SerCx - ok
21:04:12.0799 0x12f0  [ 0044B31F93946D5D41982314381FE431, 95B8A94BA9EF770F29ACD5B23D447EC2B6CF1CB3D0030343BA1550AC31F6E2A5 ] SerCx2          C:\Windows\system32\drivers\SerCx2.sys
21:04:12.0814 0x12f0  SerCx2 - ok
21:04:12.0850 0x12f0  [ 1F0135949A6AD6025F363F80FE268251, DB2D503863143F2251E589F7B0B3E9FBF997D7333D54C55856590B5080B5513D ] Serenum         C:\Windows\System32\drivers\serenum.sys
21:04:12.0861 0x12f0  Serenum - ok
21:04:12.0874 0x12f0  [ 81633C87B42B63BA484A6177179AC750, A22BA40E9EC74E88D8098CBDC954E1D63B832FCB789E3C7B731DE5DA39BEE2CA ] Serial          C:\Windows\System32\drivers\serial.sys
21:04:12.0887 0x12f0  Serial - ok
21:04:12.0912 0x12f0  [ 148195AE95D9BC7375A08846439FDAC1, 3A2F78FD18AA7A6D659921E19335E943894530874AC5AB5E7219CEF28FA54F7A ] sermouse        C:\Windows\System32\drivers\sermouse.sys
21:04:12.0923 0x12f0  sermouse - ok
21:04:12.0979 0x12f0  [ 389458EA0B5FAEBA325FAC47B9ED589E, F7F37A1F1E912069F65E4629FF733F080AE675DF6FE255AF48F5E23EB47D0622 ] SessionEnv      C:\Windows\system32\sessenv.dll
21:04:13.0002 0x12f0  SessionEnv - ok
21:04:13.0022 0x12f0  [ 472B7A5AC181C050888DB454663DD764, C950A8615D57BFD455E18880398350642B2E1D6B951EC9754FD8D429F3418835 ] sfloppy         C:\Windows\System32\drivers\sfloppy.sys
21:04:13.0034 0x12f0  sfloppy - ok
21:04:13.0081 0x12f0  [ 8081FF3DAE8159FE8956B09BC29CE983, AC0F305AEE8B1AB2E1275F1D33EC1D2F3E23F234F831BD9D41F415A94A19D3AB ] SharedAccess    C:\Windows\System32\ipnathlp.dll
21:04:13.0112 0x12f0  SharedAccess - ok
21:04:13.0185 0x12f0  [ 7FD9A61A3523A61FC135D61D6E160314, 409E1CF7A62FD90CBC31AEAFBB7230B02DBEC6CFCA2D266D221A7643FAEBA13B ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:04:13.0220 0x12f0  ShellHWDetection - ok
21:04:13.0246 0x12f0  [ 2F518D13DD6F3053837FE606F1A2EA1F, 64109296CE95BD233525688A350D575CF97B9464659AA07CF78B307B6ADBC835 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
21:04:13.0262 0x12f0  SiSRaid2 - ok
21:04:13.0284 0x12f0  [ 1AC9A200A9C49C4508F04AAFFCA34A3F, 972BCB2A39169155F74111FAC74ACCD8F50E34EADCF087833B0980827627BBF4 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
21:04:13.0298 0x12f0  SiSRaid4 - ok
21:04:13.0358 0x12f0  [ B72B80E6FF423C5011E745CB76DA9A08, 18A6B9D46E91AD4D463EB5CB832702392D2E162577F90C328B515FCE69FABD15 ] SkypeUpdate     C:\Program Files (x86)\Skype\Updater\Updater.exe
21:04:13.0385 0x12f0  SkypeUpdate - ok
21:04:13.0426 0x12f0  [ 3C84DCCE5B322F745A75CA8BA3A0F6B3, 1FB94A8A1C63D6FDB82E28ED5B696B3CB1F64183A89A3B5153B266C292CB7815 ] smphost         C:\Windows\System32\smphost.dll
21:04:13.0440 0x12f0  smphost - ok
21:04:13.0471 0x12f0  [ D0EB0DF8C603BBA084351A92732B1CBE, E24ED8F78EF41C1BC17386AE4BBCE0DC892C5B89B12C03FC9FB61D359B13F1B4 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
21:04:13.0486 0x12f0  SNMPTRAP - ok
21:04:13.0540 0x12f0  [ 546B88E6906EE9813EFE314DC95E3488, FC172C2DCC7ACDBBC9CE07CFCBAEDFAEAD2641A037E126174525DBE8BA660CC4 ] spaceport       C:\Windows\system32\drivers\spaceport.sys
21:04:13.0566 0x12f0  spaceport - ok
21:04:13.0588 0x12f0  [ F337BE11071818FC3F5DC2940B6BDE34, D5CFF00E5DF37045F71AEE101AC9B270EBB29F372F404757B58600E9966C7E4D ] SpbCx           C:\Windows\system32\drivers\SpbCx.sys
21:04:13.0600 0x12f0  SpbCx - ok
21:04:13.0665 0x12f0  [ FCB156A6745631A67DEA61827061D483, 9275ABFA1E1E595969A71C0DA228D18D1B868BF46E097E1276142BD80F8A32C9 ] Spooler         C:\Windows\System32\spoolsv.exe
21:04:13.0718 0x12f0  Spooler - ok
21:04:13.0969 0x12f0  [ F264662C057A54AA2DE41B3C7551712F, 2C123C6ACD967CDF1AD2855187CF3D8357B16A4FD9C2F18AE54CFA384165FA11 ] sppsvc          C:\Windows\system32\sppsvc.exe
21:04:14.0226 0x12f0  sppsvc - ok
21:04:14.0296 0x12f0  [ 36B082C7A764A34FB1DC72D975870B61, 572CB632D9FDC1183F7BF8BFCBC51765C647945E0C13D1C91ADE3D0E76DF83BC ] srv             C:\Windows\system32\DRIVERS\srv.sys
21:04:14.0318 0x12f0  srv - ok
21:04:14.0364 0x12f0  [ F5849909D4B29B4E3D4445F943E5C7E3, 3FCA1423753716FE1AFDD27EE1E13C4D779A3C976185B5C998EF1A9A39BFC186 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
21:04:14.0398 0x12f0  srv2 - ok
21:04:14.0421 0x12f0  [ FABC49666708EA562549E78E6FBF3191, BE1FEBFC259308B39C727915C41A67CD50720A6E2A68D148F4F2F926AED43B02 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
21:04:14.0439 0x12f0  srvnet - ok
21:04:14.0479 0x12f0  [ CF6C3037839CF78421A94F9060C2886F, CA98C180AE03F5BE8FEFFBA75BD98DEE2AD4FA975E1EF83215C9CD2476946811 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
21:04:14.0501 0x12f0  SSDPSRV - ok
21:04:14.0536 0x12f0  [ 198A737DBA666F4808D62E9A8277A6B7, 90B6E5E2ACE95D850C913A3A1DA1F966C44955C530004C228FA93B2A536F5C27 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
21:04:14.0552 0x12f0  SstpSvc - ok
21:04:14.0568 0x12f0  [ 366DEA74BBA65B362BCCFC6FC2ADFD8B, 4D28122AB9D8DAB724021E6513B4474BD34FCEDF47769B1D27AC7551FCA002F8 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
21:04:14.0583 0x12f0  stexstor - ok
21:04:14.0630 0x12f0  [ 63E9CE568CF1192771A5F0460DE7D2B9, C27B21FD2C14AD41A59EF62EB8AC95C08EB13CCB1CEECD8378B8CDD4DC352E69 ] stisvc          C:\Windows\System32\wiaservc.dll
21:04:14.0661 0x12f0  stisvc - ok
21:04:14.0677 0x12f0  [ 0ED2E318ABB68C1A35A8B8038BDB4C90, 5C3ABC245F4BCFE64E646D9C0E2F5E211244956C84D03084C71FF6A7E0CDED30 ] storahci        C:\Windows\system32\drivers\storahci.sys
21:04:14.0693 0x12f0  storahci - ok
21:04:14.0708 0x12f0  [ 8B9486B64E5FC17FB9CC04CA10B77A34, C1EAC9D27DC83E4C56B890D97988C3CCFAE3877309610601F2E3FFFE97686D43 ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
21:04:14.0724 0x12f0  storflt - ok
21:04:14.0771 0x12f0  [ 0EDD1F4D470C775740625B06A60C9DD5, 94964D0A793B1C984E87095249EE383A5E669D05BA6BF9F655587887E6CE3C19 ] stornvme        C:\Windows\system32\drivers\stornvme.sys
21:04:14.0771 0x12f0  stornvme - ok
21:04:14.0818 0x12f0  [ A45F5AC9D8069D0EC66E3CA73103073B, 996788F1C58E016E8E5CF3FD1D220A3C40AFFD6C21361A34636415DB12E0D381 ] StorSvc         C:\Windows\system32\storsvc.dll
21:04:14.0833 0x12f0  StorSvc - ok
21:04:14.0849 0x12f0  [ 548759755BC73DAD663250239D7E0B9F, D31A05A8CE800B539420B6E545F1F4BF6E4B02EAF8366DE89CAF13A83C6CA48D ] storvsc         C:\Windows\system32\drivers\storvsc.sys
21:04:14.0865 0x12f0  storvsc - ok
21:04:14.0896 0x12f0  [ E395BE02F80A79A6CF973BA38DBB8135, 4C6F85B0EB8E7725BA720F9742561D229726C0D7C17505D1E79F19A5626F6325 ] svsvc           C:\Windows\system32\svsvc.dll
21:04:14.0911 0x12f0  svsvc - ok
21:04:14.0943 0x12f0  [ 65454187E0F8B6C0DCECB0287D06EC43, 87550000CF5B3C1DF3E69633934AFE8554AE40B6638F190D3185AD63F1D7A2EE ] swenum          C:\Windows\System32\drivers\swenum.sys
21:04:14.0958 0x12f0  swenum - ok
21:04:15.0005 0x12f0  [ 1C71D72D4997A284128FBEE770726330, 21682BDE74A1108FED1124FB1EA35A03CBFA94ABE1B89CC0FADB4DD82596C43E ] swprv           C:\Windows\System32\swprv.dll
21:04:15.0052 0x12f0  swprv - ok
21:04:15.0115 0x12f0  [ 7E85DB0463AD2403AE84AD162B162279, 996C42ECAFC6E24C623068AFAFCC0A2612526333AF9315F7536C6D40C2570632 ] SysMain         C:\Windows\system32\sysmain.dll
21:04:15.0177 0x12f0  SysMain - ok
21:04:15.0208 0x12f0  [ D73DBBB96CEE90C2856164AAD8543425, D11ADB5D4C5DD355314CA656D375D0062CAE7462E866F94F1B26D5803F65DCB2 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
21:04:15.0240 0x12f0  SystemEventsBroker - ok
21:04:15.0275 0x12f0  [ D6A71B95ACF71ACA63B67232059F1BCD, C5CEC032E7AB507500D1CC7A4E65DA6322412C798201A9D770CBDE892E50DFC8 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:04:15.0290 0x12f0  TabletInputService - ok
21:04:15.0341 0x12f0  [ 5A5BAB1CA9621E73E25EE4744B67CDA6, 479EBD7BAE1E2AD431153FDC016742F7A8D824716EAB1A4CA87EBBD21D61DECD ] TapiSrv         C:\Windows\System32\tapisrv.dll
21:04:15.0357 0x12f0  TapiSrv - ok
21:04:15.0466 0x12f0  [ 2F10C145F517419E17203632FCDA0A13, 143F5837AE79E3EDB98F17A4661ECD5BCBFEB317077286B51E765560339B53A8 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
21:04:15.0575 0x12f0  Tcpip - ok
21:04:15.0669 0x12f0  [ 2F10C145F517419E17203632FCDA0A13, 143F5837AE79E3EDB98F17A4661ECD5BCBFEB317077286B51E765560339B53A8 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
21:04:15.0778 0x12f0  TCPIP6 - ok
21:04:15.0810 0x12f0  [ 41CF802064F72E55F50CA0A221FD36D4, 70ABCDF9E96611E8C83042C581575E26649FE479475E8E118CD3FF6CB1C84C3F ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
21:04:15.0810 0x12f0  tcpipreg - ok
21:04:15.0857 0x12f0  [ E0BD2D83875464FEEEB242CBA8B7E073, A3067165128F36035FA9F3CBA55CFED736E180C495497FA7332B3D97908C3D90 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
21:04:15.0857 0x12f0  tdx - ok
21:04:15.0904 0x12f0  [ 550ECEA4386BC8AB6549E4613C76E938, 122408BCF189613997AA80CA6DF375FFCF81BE334B91F45A034EE6844CDE6B40 ] TemproMonitoringService C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
21:04:15.0919 0x12f0  TemproMonitoringService - ok
21:04:15.0935 0x12f0  [ 232D185D2337F141311D0CF1983E1431, 02EB56D3F26174AF1741C1A444CE30DE84D5BAF583C1A52C7A953BCC52445547 ] terminpt        C:\Windows\System32\drivers\terminpt.sys
21:04:15.0935 0x12f0  terminpt - ok
21:04:16.0013 0x12f0  [ C50997E282576DA492EBA66B059D4196, EBD793CB396F9503376207FA60353F5672DEDB620C8E01C8D6AE0030B3B03339 ] TermService     C:\Windows\System32\termsrv.dll
21:04:16.0075 0x12f0  TermService - ok
21:04:16.0107 0x12f0  [ 2180DBCE75B914E5E5BBFFFAAE97AA21, 8000AECC8855903DB50ABA7E304396D1FCEAE8DC9ADD4FC50275CF24B4D914DE ] Themes          C:\Windows\system32\themeservice.dll
21:04:16.0138 0x12f0  Themes - ok
21:04:16.0153 0x12f0  [ 4C5D93E2CCA6799A0D159F9CF5AF0903, E44007ED1ECAEB174E2378B363BFC7CA18A193CD554C645E60EF62DEF47BF7D6 ] Thotkey         C:\Windows\System32\drivers\Thotkey.sys
21:04:16.0169 0x12f0  Thotkey - ok
21:04:16.0185 0x12f0  [ C543A60A5629BE336A5BF844A802F725, D29FE96B636A9C8AE06AC0F10CCDE57062BDA35C4FB707D4945B46662217C519 ] Thpdrv          C:\Windows\system32\DRIVERS\thpdrv.sys
21:04:16.0200 0x12f0  Thpdrv - ok
21:04:16.0200 0x12f0  [ 981FF023805AF650B8900DAA9C78B929, C78E8CFD20E5C90755DA0E29B222902EC9C2A061006FE1015FC3F64A2DC81CF4 ] Thpevm          C:\Windows\system32\drivers\Thpevm.SYS
21:04:16.0216 0x12f0  Thpevm - ok
21:04:16.0247 0x12f0  [ 2FFD608E2D8BFF5B422358587C123FC2, D7F4D2AA477A976DCACC3EDF7C4BB7094AE6FAD5E2E36CFD859B1F6B8F67D2AA ] Thpsrv          C:\Windows\system32\ThpSrv.exe
21:04:16.0263 0x12f0  Thpsrv - ok
21:04:16.0294 0x12f0  [ 4C5179DB61B9E14BEC15CDC4B152B2E9, 9048BEC7AD6A3F4B640E99B1F0365AC9A46740B188758FBB2C160EF30AD6E64B ] THREADORDER     C:\Windows\system32\mmcss.dll
21:04:16.0310 0x12f0  THREADORDER - ok
21:04:16.0341 0x12f0  [ B5ED9CC61798C7D44BD535D40B89EFB5, 1BDCEAA9AF2096381870D92129C748F4EE06A1167ABA9367B9DD43BAF27E3F5B ] TimeBroker      C:\Windows\System32\TimeBrokerServer.dll
21:04:16.0372 0x12f0  TimeBroker - ok
21:04:16.0435 0x12f0  [ 7421BB9A1B8C093B809FE1B0547F4A5D, 763C6AAC39D9FEF168A9C49057A2A14612903EE462DFD39EA52ED93C13D72FDB ] TMachInfo       C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
21:04:16.0450 0x12f0  TMachInfo - ok
21:04:16.0497 0x12f0  [ D8069B711BE5BEA3D769C1C7547F535B, EFC32951BA7B9CCB46BAD076E267D40295B46CCC884163D391E4ACC55C47B149 ] TOSHIBA eco Utility Service C:\Program Files\TOSHIBA\Teco\TecoService.exe
21:04:16.0513 0x12f0  TOSHIBA eco Utility Service - ok
21:04:16.0544 0x12f0  [ A884A627C0B6E8B238759FC73C1AAAAF, 5D6E38664B6175F5F541D838675429CEE9FA1492A7E25B48E98794B5EB8B6973 ] tosrfec         C:\Windows\System32\drivers\tosrfec.sys
21:04:16.0544 0x12f0  tosrfec - ok
21:04:16.0591 0x12f0  [ 36391C3953D191A2AF4556D5D706C641, 5191A35C86B6C98F2CBDDC23B5311ED62310345CEDE084A54BBF70CCF0F84C50 ] tos_sps64       C:\Windows\system32\drivers\tos_sps64.sys
21:04:16.0607 0x12f0  tos_sps64 - ok
21:04:16.0654 0x12f0  [ 5D39CC18C62D4C8B45801F0E390A94CA, 26372CD41211EC3ABDB4CF94D5900B7304FEC8C0E274BCA286C949DA6F0EB283 ] TPCHSrv         C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
21:04:16.0669 0x12f0  TPCHSrv - ok
21:04:16.0700 0x12f0  [ 80A2FC1A089A71F2DBE5D8394FFB009F, DEA30E751F6EA42E43E16869713FC7E37832B15DAFA0062B1798DFA476981385 ] TPM             C:\Windows\system32\drivers\tpm.sys
21:04:16.0716 0x12f0  TPM - ok
21:04:16.0763 0x12f0  [ 884113C2BB703FE806C8608B75F34831, 24DE5750CA4363455412BABB0B1FAB08497153E8F158ED44958F100410F93506 ] TrkWks          C:\Windows\System32\trkwks.dll
21:04:16.0779 0x12f0  TrkWks - ok
21:04:16.0841 0x12f0  [ 44A94FB4C76528D2382FFE04B05827C3, B0BCDF7CD1D65E61A9061D539D83527A89B69583958F8A26C6BF9766C1B61E0C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:04:16.0857 0x12f0  TrustedInstaller - ok
21:04:16.0872 0x12f0  [ BF8F54CA37E9C9D6582C31C5761F8C93, 337C566792F6FB9B7FD5D1D4384B767CFE4CF5DBB2E4688CCC36CBB018A0DD0F ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
21:04:16.0888 0x12f0  TsUsbFlt - ok
21:04:16.0919 0x12f0  [ 20185BEB7512EDE4EFECDFA148AC9F99, 6F539478493C0F87F3DDF67A4A6D4D41E9474EEF21434E856350CE149A34EA9F ] TsUsbGD         C:\Windows\System32\drivers\TsUsbGD.sys
21:04:16.0935 0x12f0  TsUsbGD - ok
21:04:16.0966 0x12f0  [ E85916632CD3B9E9B546968DB950BF42, DECE3852C763CC6293C7D1B772296C43A0AE1E47BBCC4979C96B3B2AD70413F3 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
21:04:16.0982 0x12f0  tunnel - ok
21:04:16.0997 0x12f0  [ 878D283B927B790B1D5685F723150A87, 31D83D96B2BBE45C367879BB34A8BA474D0F90861E5DBBAED3D74151A5A78275 ] TVALZ           C:\Windows\system32\drivers\TVALZ.SYS
21:04:16.0997 0x12f0  TVALZ - ok
21:04:17.0029 0x12f0  [ 7B05B5B492E6E248C2B38CD04B4D3A96, 1E18025DDB5EDEBD30F2FAC8D121F55D768B71DA42D919E1A0E98E2E31AA73C8 ] TVALZFL         C:\Windows\system32\Drivers\TVALZFL.sys
21:04:17.0044 0x12f0  TVALZFL - ok
21:04:17.0060 0x12f0  [ F6EEAD052943B5A3104C1405BB856C54, FE422813E6C1012E9F392EFF2AE4C6D3A4DBD9CB2BD5E6A5CAB57D4E89A29468 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
21:04:17.0075 0x12f0  uagp35 - ok
21:04:17.0091 0x12f0  [ FE6067B1FD4E63650C667B33D080565B, 2C330ED00E49BA55E25564230E0DFB8A35F2B5320EB18D4AF7CAACFA9A449044 ] UASPStor        C:\Windows\System32\drivers\uaspstor.sys
21:04:17.0107 0x12f0  UASPStor - ok
21:04:17.0169 0x12f0  [ 807F8CF3E973305FC435C61CBBEE2A49, 43CDEAC2BFC5091C11DFC0E7F7171AF9A598AE56CB056C3CF382AE7807F79EF0 ] UCX01000        C:\Windows\System32\drivers\ucx01000.sys
21:04:17.0185 0x12f0  UCX01000 - ok
21:04:17.0232 0x12f0  [ C61EAF8E1E4B2F62BA4FDF457440B2C6, 961F76A789925234AC27F56AAE34556FA06088D71580B42C24B0BC209EAFD67E ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
21:04:17.0251 0x12f0  udfs - ok
21:04:17.0267 0x12f0  [ 9578691F297E1B1F519970FE6D47CB21, 080C352AAF22A16A4F3C4AB4DCEA5BFA656457C73F735CEBA30516FDACCF6301 ] UEFI            C:\Windows\System32\drivers\UEFI.sys
21:04:17.0283 0x12f0  UEFI - ok
21:04:17.0334 0x12f0  [ A867F0F978EE64C87FADC3B100869EE4, 2686BE85F963D0D0BB275E92E5B543280D8742CF10772303E3189D0719B6A277 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
21:04:17.0350 0x12f0  UI0Detect - ok
21:04:17.0365 0x12f0  [ 5EAB5117DDB24FC4D39E6FFFCF1837B9, 2BC709240867F161E94BE6625A04F478EAAA3EEE7BC7C37ED0DFA9EEA5928E98 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
21:04:17.0381 0x12f0  uliagpkx - ok
21:04:17.0397 0x12f0  [ DA34C39A18E60E7C3FA0630566408034, 2F162504214053894C72760D9933D01DBF3578609FE5E2376C3272818599FE32 ] umbus           C:\Windows\System32\drivers\umbus.sys
21:04:17.0412 0x12f0  umbus - ok
21:04:17.0412 0x12f0  [ AE8294875E5446E359B1E8035D40C05E, AE0357BAB47C07C3576BC76951CD258C009BC5A1B93259D2122A841BD9CDA8FA ] UmPass          C:\Windows\System32\drivers\umpass.sys
21:04:17.0428 0x12f0  UmPass - ok
21:04:17.0475 0x12f0  [ A023F267A262D5DA6CE1436D9C5E8FD9, 92AD7AF91184C244A7E392F49663143193A80D5D81114546A00F18227DE31D23 ] UmRdpService    C:\Windows\System32\umrdp.dll
21:04:17.0491 0x12f0  UmRdpService - ok
21:04:17.0538 0x12f0  [ C98493DD8E6A50154FAC75C15E1C36BB, CECD1C826C8F7AF05468871BF6A0ACDBB6B0202F4F87F48C6D367E5BD699E800 ] upnphost        C:\Windows\System32\upnphost.dll
21:04:17.0569 0x12f0  upnphost - ok
21:04:17.0600 0x12f0  [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64       C:\Windows\System32\Drivers\usbaapl64.sys
21:04:17.0616 0x12f0  USBAAPL64 - ok
21:04:17.0647 0x12f0  [ FF78D053A05E5A394F4E3C1816CC65A8, 5DAE02414271231F5FDBB751AFEB99874779B467947020815D4AE54432D4269D ] usbccgp         C:\Windows\System32\drivers\usbccgp.sys
21:04:17.0663 0x12f0  usbccgp - ok
21:04:17.0710 0x12f0  [ 0139248F6B95CF0D837B5B46A2722D40, 38E3E704E0364F07732DB418AEBD126B040FB3CDB7D78EA36E8605D50D528A80 ] usbcir          C:\Windows\System32\drivers\usbcir.sys
21:04:17.0725 0x12f0  usbcir - ok
21:04:17.0741 0x12f0  [ C996CBEF922B5653A01E3F50DDCE2F86, 231EB5A36E7EE242197E796D3B4AB12F945D2C8570587BC8D57D45530A0C59B4 ] usbehci         C:\Windows\System32\drivers\usbehci.sys
21:04:17.0756 0x12f0  usbehci - ok
21:04:17.0819 0x12f0  [ CD81683F4553677B9BF5163A922153EB, 6B304B0D68B9BFF0245EC755CDAAF9DF59DF3A081727E32CB66672929F0DBC50 ] usbhub          C:\Windows\System32\drivers\usbhub.sys
21:04:17.0835 0x12f0  usbhub - ok
21:04:17.0881 0x12f0  [ 5C90D5379B53590FBB24BBAD4FA682EE, DC036340510C1C0999AB1CB845F8E6EB8B7696BAC9BBE6E936454C0000D1E9D4 ] USBHUB3         C:\Windows\System32\drivers\UsbHub3.sys
21:04:17.0897 0x12f0  USBHUB3 - ok
21:04:17.0913 0x12f0  [ A0F0484C97D6441ED6A75D7426ECCC9E, FF928ADE1C5464E581BF929F7383D5762D110EA6C7E31A6F0887EA7357ADBEFE ] usbohci         C:\Windows\System32\drivers\usbohci.sys
21:04:17.0928 0x12f0  usbohci - ok
21:04:17.0960 0x12f0  [ 4D655E3B684BE9B0F7FFD8A2935C348C, 3A7FC1748C5AEA8CFE0E7C22ADC77E3DCA475455FC16D9C6A5C16EB5E949A516 ] usbprint        C:\Windows\System32\drivers\usbprint.sys
21:04:17.0975 0x12f0  usbprint - ok
21:04:18.0022 0x12f0  [ 9D168BFA334D47BE404367EB58D4E130, 23279CBE6ACBD074E7B268BA2EDA14E2255C41F8117173B2BBE653D8259ECFA2 ] USBSTOR         C:\Windows\System32\drivers\USBSTOR.SYS
21:04:18.0038 0x12f0  USBSTOR - ok
21:04:18.0069 0x12f0  [ FC974B03C8B87455F44F734C8F31A3C8, D69F6EE8030F7DF96FF151D9EAA6AE65417ACAC5A267C7DB96E9611D5BC42D2C ] usbuhci         C:\Windows\System32\drivers\usbuhci.sys
21:04:18.0085 0x12f0  usbuhci - ok
21:04:18.0131 0x12f0  [ 5C8F604F6DC74177CDD8372D7B1ADFF0, C1DE9A37A7A01CCCBFCE13C1E5B26683F620AB21EDA5A14C82022E2F49C84484 ] usbvideo        C:\Windows\System32\Drivers\usbvideo.sys
21:04:18.0147 0x12f0  usbvideo - ok
21:04:18.0178 0x12f0  [ 44603DA5A87FB491EF59C889EBBB4DDB, 59AA9B6B0B5D66F9312CD3F999D0D9F12F1A2C5D230365AD7287CD71FD86961C ] USBXHCI         C:\Windows\System32\drivers\USBXHCI.SYS
21:04:18.0210 0x12f0  USBXHCI - ok
21:04:18.0225 0x12f0  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] VaultSvc        C:\Windows\system32\lsass.exe
21:04:18.0241 0x12f0  VaultSvc - ok
21:04:18.0288 0x12f0  [ C41B43417F77FCB2D2D81C9C2B9A85FE, 88EE5D47BFB2A6FE0B5C56479FA3C4B829E8ABCE0FB001C45C42E2E8B4A4EF62 ] VBoxNetAdp      C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys
21:04:18.0288 0x12f0  VBoxNetAdp - ok
21:04:18.0319 0x12f0  [ FEB26E3B8345A7E8D62F945C4AE86562, 3AAFE87C402FC8E92542DFE60EC9540559863065F88D429A16D7B1BF829223FF ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
21:04:18.0335 0x12f0  vdrvroot - ok
21:04:18.0413 0x12f0  [ 8A4D808D1EC7C1C47B2C8BF488A9A07A, 63C07312ADB6F8A8BDE93361C30AC63DAB4DE1141AF54630EEF11E54B0BF983D ] vds             C:\Windows\System32\vds.exe
21:04:18.0460 0x12f0  vds - ok
21:04:18.0475 0x12f0  [ A026EDEAA5EECAE0B08E2748B616D4BD, 2525A54DC7F49DDFBB999C22BF3FAB6D9E9F70C0806E58D81E90AC59F9F46089 ] VerifierExt     C:\Windows\system32\drivers\VerifierExt.sys
21:04:18.0491 0x12f0  VerifierExt - ok
21:04:18.0553 0x12f0  [ 8ABB4BABF59F092DF0B43778D8FD1884, 94C2100CE86448543A8DD586AD4A128AB9EB37959238D70F33EF59202270AC6C ] vhdmp           C:\Windows\System32\drivers\vhdmp.sys
21:04:18.0585 0x12f0  vhdmp - ok
21:04:18.0600 0x12f0  [ 06D38968028E9AB19DE9B618C7B6D199, 62022297A47F440D1C82CA0B0E57C0C8E9D5033D83DD3B40492B218DF65EBF68 ] viaide          C:\Windows\system32\drivers\viaide.sys
21:04:18.0616 0x12f0  viaide - ok
21:04:18.0631 0x12f0  [ 511AD3FF957A0127E6BD336FF6F89C38, 55325BFD0857A1204F7F6F8ED8C91C07B0E20A50402105708E7365ECD9E25A21 ] vmbus           C:\Windows\system32\drivers\vmbus.sys
21:04:18.0647 0x12f0  vmbus - ok
21:04:18.0678 0x12f0  [ DA40BEA0A863CE768C940CA9723BF81F, 567C0C3F422325635808B0CF76E05D3B6187F96845C33F85F92F98C9FE53A5B8 ] VMBusHID        C:\Windows\System32\drivers\VMBusHID.sys
21:04:18.0678 0x12f0  VMBusHID - ok
21:04:18.0725 0x12f0  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicguestinterface C:\Windows\System32\ICSvc.dll
21:04:18.0756 0x12f0  vmicguestinterface - ok
21:04:18.0788 0x12f0  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicheartbeat   C:\Windows\System32\ICSvc.dll
21:04:18.0803 0x12f0  vmicheartbeat - ok
21:04:18.0835 0x12f0  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
21:04:18.0866 0x12f0  vmickvpexchange - ok
21:04:18.0897 0x12f0  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicrdv         C:\Windows\System32\ICSvc.dll
21:04:18.0928 0x12f0  vmicrdv - ok
21:04:18.0960 0x12f0  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicshutdown    C:\Windows\System32\ICSvc.dll
21:04:18.0975 0x12f0  vmicshutdown - ok
21:04:19.0007 0x12f0  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmictimesync    C:\Windows\System32\ICSvc.dll
21:04:19.0038 0x12f0  vmictimesync - ok
21:04:19.0069 0x12f0  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicvss         C:\Windows\System32\ICSvc.dll
21:04:19.0100 0x12f0  vmicvss - ok
21:04:19.0132 0x12f0  [ 436E1A724E7E683F6B612D3D58F04241, 939B5EF0090DF3759295F88402FD0EA33F499DDA9F89E5D0E90D1F9AED65D491 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
21:04:19.0147 0x12f0  volmgr - ok
21:04:19.0178 0x12f0  [ CCB9E901F7254BF96D28EB1B0E5329B7, F0E3CA4EFA544CDAEF4092284CF3EC7DF07F806A770285E281816457AD8813F5 ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
21:04:19.0194 0x12f0  volmgrx - ok
21:04:19.0245 0x12f0  [ 17F7B0F2298D97F4B6C7A69511033D3D, 5BDFC225F31553786726808FB7952940FC05CA72B3977D684056F42AFAA59565 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
21:04:19.0276 0x12f0  volsnap - ok
21:04:19.0310 0x12f0  [ DAC438FB5FF85A9E72806E2341D5D732, B1D1EFCA8C588A6BF53CEC941CC59702C366F15C7D5943431736EC857E57C0A2 ] vpci            C:\Windows\System32\drivers\vpci.sys
21:04:19.0311 0x12f0  vpci - ok
21:04:19.0327 0x12f0  [ 4539F45F9F4C9757A86A56C949421E07, DEC362314B2C66414F39354AFE79C02B18BF4EEF90787FB58307F6EB62237E2C ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
21:04:19.0343 0x12f0  vsmraid - ok
21:04:19.0421 0x12f0  [ D0CBA7B3531CCF2ADB985856D5F92434, 7FCBBCAF1AA85DCE8D75FB38DC4848AE12E8DD913CEBBC37BCD3D0123F0A3CAB ] VSS             C:\Windows\system32\vssvc.exe
21:04:19.0483 0x12f0  VSS - ok
21:04:19.0514 0x12f0  [ 0849B7260F26FE05EA56DED0672E2F4B, 7EAC0E7988F45CB4133A15932955B7B03CE715C967A3BAC9999D81543EBCAEC5 ] VSTXRAID        C:\Windows\system32\drivers\vstxraid.sys
21:04:19.0546 0x12f0  VSTXRAID - ok
21:04:19.0577 0x12f0  [ 71066FF95C487327E44C8AF1B72EBE8B, EA2729126B452CAE0C80D07501779D804B08E47F1217B61D53277B40869FEC25 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
21:04:19.0577 0x12f0  vwifibus - ok
21:04:19.0608 0x12f0  [ 29AB43937FFDA0B0FB56984226E698C6, 6A1A559964FE5D594E54988C46149969E6FFD5A8D5A6862E14648B608794CC29 ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
21:04:19.0624 0x12f0  vwififlt - ok
21:04:19.0624 0x12f0  [ 8B8624A93E3F88CB923AEB05B6313227, 2856B63CD376BF2B1A9129581E7B9207588D4EAFD29A2C8D98F176FEAFDE26A9 ] vwifimp         C:\Windows\system32\DRIVERS\vwifimp.sys
21:04:19.0639 0x12f0  vwifimp - ok
21:04:19.0686 0x12f0  [ DC821E811EFBB65CDD77FBB8B6ECA385, B7C8AACDF81DBA298F2F384983D36B269876C31F0398D89BF9070217A069B96F ] W32Time         C:\Windows\system32\w32time.dll
21:04:19.0718 0x12f0  W32Time - ok
21:04:19.0733 0x12f0  [ 0910AB9ED404C1434E2D0376C2AD5D8B, 62585CA5F1375BDA440D28D5DF1ADDC9DE3DDFA196D49BBFF3456A5A09EE1C6B ] WacomPen        C:\Windows\System32\drivers\wacompen.sys
21:04:19.0749 0x12f0  WacomPen - ok
21:04:19.0780 0x12f0  [ 6505C9E72910F91D4C317EECF22D1DE6, 838BAEA6F0BBA916B3291EB165F65DA2F4EC35395678D450EEEB1E540A123FC4 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
21:04:19.0796 0x12f0  Wanarp - ok
21:04:19.0811 0x12f0  [ 6505C9E72910F91D4C317EECF22D1DE6, 838BAEA6F0BBA916B3291EB165F65DA2F4EC35395678D450EEEB1E540A123FC4 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
21:04:19.0827 0x12f0  Wanarpv6 - ok
21:04:19.0905 0x12f0  [ 841345442390953CBC8801B95D3D0540, FD4F9FD2C4C60A1A580177FFF2E9035009AC6A38E78D4236B0ED4773E3B263EE ] wbengine        C:\Windows\system32\wbengine.exe
21:04:19.0968 0x12f0  wbengine - ok
21:04:20.0014 0x12f0  [ 0F1DFA2FED73FA78B8C3CDE332A870F6, 1089F6F585F5350D349A640EBD3117832DF6B3657EB6667CB00AE217E04ACA17 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
21:04:20.0046 0x12f0  WbioSrvc - ok
21:04:20.0061 0x12f0  [ 0EAEC313B24837613621B4A2536ED382, 61C194ED7FA7D65BBE61A546D5FCA52F52AB08324E084D3EC23C9706E9BF0175 ] Wcmsvc          C:\Windows\System32\wcmsvc.dll
21:04:20.0077 0x12f0  Wcmsvc - ok
21:04:20.0108 0x12f0  [ F6B4C2280FF7C7156AC8A4687B9DA35E, 1899D584D7469BB49355D84080051E2575B033E6312009D9C6C1DD3F7F9AA4C5 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
21:04:20.0139 0x12f0  wcncsvc - ok
21:04:20.0171 0x12f0  [ B7BF1D783F5B2484E8CE1C0C78257F16, 468601199FCCF63DBAE86EE6B8825EA85B2A1EE177413353FFA2CC9CA5249FCD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:04:20.0186 0x12f0  WcsPlugInService - ok
21:04:20.0218 0x12f0  [ 81285DDC994F03379DB46419300B2DCB, 98D3622E11F375718AEA1DE3B5F0104DDAB4F96B6D4C19788C14F7B338A6F235 ] WdBoot          C:\Windows\system32\drivers\WdBoot.sys
21:04:20.0233 0x12f0  WdBoot - ok
21:04:20.0280 0x12f0  [ CB6C63FF8342B467E2EF76E98D5B934D, BE017CE91E3BAB293DE6ECF143797CCE3F33CC63024437472B4E38C6961AD884 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
21:04:20.0311 0x12f0  Wdf01000 - ok
21:04:20.0358 0x12f0  [ 26B8FED3F3B85F5F0C4BD03FD00B9941, 7F94FE7954498223B33C025258DB588A3AC9FF25C58EEAD204514FD20652FE40 ] WdFilter        C:\Windows\system32\drivers\WdFilter.sys
21:04:20.0374 0x12f0  WdFilter - ok
21:04:20.0421 0x12f0  [ F581F9C9D6953FABFA24E67105F0B614, 5A7BB72523D1C53BBE68700537D7AE0D150BC7E4B8227A916B2E29EE4CA267A9 ] WdiServiceHost  C:\Windows\system32\wdi.dll
21:04:20.0436 0x12f0  WdiServiceHost - ok
21:04:20.0436 0x12f0  [ F581F9C9D6953FABFA24E67105F0B614, 5A7BB72523D1C53BBE68700537D7AE0D150BC7E4B8227A916B2E29EE4CA267A9 ] WdiSystemHost   C:\Windows\system32\wdi.dll
21:04:20.0452 0x12f0  WdiSystemHost - ok
21:04:20.0499 0x12f0  [ CE67080F00E0AF32755096CEA6430ABA, 0E5D626F9F76C0BC63B2D246AD66D9CBF7D92F34B56398417BCFD0C331DBD282 ] WdNisDrv        C:\Windows\system32\Drivers\WdNisDrv.sys
21:04:20.0499 0x12f0  WdNisDrv - ok
21:04:20.0530 0x12f0  WdNisSvc - ok
21:04:20.0577 0x12f0  [ A70CAF5EA36CBA5FCA24244306D4D5C6, 76C3E20B62B89D9699A1E817377FAD70B144B877BCC5C850A5B64CC68184D8DA ] WebClient       C:\Windows\System32\webclnt.dll
21:04:20.0593 0x12f0  WebClient - ok
21:04:20.0639 0x12f0  [ 384E1D04FE20845B2559D292F17A9FA1, AD3B0B2B2219691AC30FEEC8AFDB3BBB74B51BB7D02038AE2B4DEA514E245315 ] Wecsvc          C:\Windows\system32\wecsvc.dll
21:04:20.0671 0x12f0  Wecsvc - ok
21:04:20.0702 0x12f0  [ 455014F4E48B67EBE0F032E2B0E06BF2, A36435784A034B27056A0E606683A20C69F1B0AB2B6BAEDEAEAA190F6287CAEF ] WEPHOSTSVC      C:\Windows\system32\wephostsvc.dll
21:04:20.0718 0x12f0  WEPHOSTSVC - ok
21:04:20.0749 0x12f0  [ F13DBA57CEA9B7074B95EDCA6AD2635E, 1D9BA4841EF1343A5D9096B5FE27FC65DC1901D6683DD13516171638549666B5 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
21:04:20.0780 0x12f0  wercplsupport - ok
21:04:20.0811 0x12f0  [ FD7E58B6AA3EABF2D12B9762A20E11E4, 4C5E2E246C5C70074866BB3DBC2AAF483ECE4345004CCB8D1FE285047268685D ] WerSvc          C:\Windows\System32\WerSvc.dll
21:04:20.0827 0x12f0  WerSvc - ok
21:04:20.0874 0x12f0  [ 715ABA3DD164D06457A2A3C92F6EA9D5, E6F8269D2FFC4A548B65724C0A3F53756ED15E47229861FBD40B656EE40FE166 ] WFPLWFS         C:\Windows\system32\DRIVERS\wfplwfs.sys
21:04:20.0889 0x12f0  WFPLWFS - ok
21:04:20.0905 0x12f0  [ 8C840E1FD7584E74BD0CC1EA581EC187, 148E534A94B4882E7396B13FABE17407802292E7890713540080D03D5629C81D ] WiaRpc          C:\Windows\System32\wiarpc.dll
21:04:20.0921 0x12f0  WiaRpc - ok
21:04:20.0936 0x12f0  [ 5F66B7BB330AA80067FC66149A692620, 92C5D7115A168A23108B65EEEB5FBA8FA43D781855355792596D2419160263C2 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
21:04:20.0952 0x12f0  WIMMount - ok
21:04:20.0952 0x12f0  WinDefend - ok
21:04:21.0014 0x12f0  [ 0E70990EC2E5D2331AA5E88DB0CFB826, 79DFF565C3FCBC691E8FEB669CEC00E340FD2A2AFA4488D23A7CC63A2A98A5C1 ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
21:04:21.0061 0x12f0  WinHttpAutoProxySvc - ok
21:04:21.0108 0x12f0  [ FC8BD690321216C32BB58B035B6D5674, D61698DB19D9DB2593B60B6BA13F7B7735667206F41D751D507135469D6D3CDD ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
21:04:21.0124 0x12f0  Winmgmt - ok
21:04:21.0233 0x12f0  [ 427873F889F2F508BE8BE982219CE578, CA8DCFB774BF0F747295A7A0CB46A6177DE12AD6BD58266182206C41A3C9001E ] WinRM           C:\Windows\system32\WsmSvc.dll
21:04:21.0336 0x12f0  WinRM - ok
21:04:21.0461 0x12f0  [ F2813A2A50E8E5DAB055174699060683, 018988E9FEC8702AFFE60870860A9D04A6BBFA6A898C8F23353E6FC1B96B6A13 ] WinSAPSvc       C:\Users\M\AppData\Roaming\WinSAPSvc\WinSAP.dll
21:04:21.0492 0x12f0  WinSAPSvc - detected UnsignedFile.Multi.Generic ( 1 )
21:04:21.0649 0x12f0  WinSAPSvc ( UnsignedFile.Multi.Generic ) - warning
21:04:21.0852 0x12f0  [ 6495CD0C0D8C9A0B4CD1C5490F21C9F5, 018D643739CA511635B379442ED4BD519ECB2E31B09E4494D8F977B6720B241F ] WinSnare        C:\Users\M\AppData\Roaming\WinSnare\WinSnare.dll
21:04:21.0883 0x12f0  WinSnare - detected UnsignedFile.Multi.Generic ( 1 )
21:04:22.0039 0x12f0  WinSnare ( UnsignedFile.Multi.Generic ) - warning
21:04:22.0039 0x12f0  Force sending object to P2P due to detect: WinSnare
21:04:22.0258 0x12f0  Object send P2P result: true
21:04:22.0445 0x12f0  [ 3AF1FA17F1C4ACBDB660D8F98B1A9C13, 99B0851410B462685F6705EBF832D10943FB9634030B02D15BF5D0C66F26F2C2 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
21:04:22.0461 0x12f0  WinUsb - ok
21:04:22.0555 0x12f0  [ DC079BA8390089E4EBCA63D27EEA3ECB, 4D549217A68292E2B16C09FD9F84317011EE54A2DAF4E2AB85554267DF0D3249 ] WlanSvc         C:\Windows\System32\wlansvc.dll
21:04:22.0618 0x12f0  WlanSvc - ok
21:04:22.0727 0x12f0  [ 06BF5897949A8F24893F792E876B71F5, 9D3719492A86BF52A56E2EA798FD6FDB5862A03F6D360FCC4B0CEA9BE9792AE4 ] wlidsvc         C:\Windows\system32\wlidsvc.dll
21:04:22.0789 0x12f0  wlidsvc - ok
21:04:22.0805 0x12f0  [ 2834D9D3B4F554A39C72F00EA3F0E128, D10124343C67FE9A0B711AD569BB8080495FCEA0ECEF9AC3F3FBD6865F436A44 ] WmiAcpi         C:\Windows\System32\drivers\wmiacpi.sys
21:04:22.0821 0x12f0  WmiAcpi - ok
21:04:22.0868 0x12f0  [ B96F7A1236C3F21212DE2C40A3DDB005, 5A29EBB6DA036E303611EB1304192655021405BB05452FD37886DDE604FF0D9D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
21:04:22.0883 0x12f0  wmiApSrv - ok
21:04:22.0899 0x12f0  WMPNetworkSvc - ok
21:04:22.0930 0x12f0  [ 7FC5667DF73D4B04AA457CC3A4180E09, CB7B014945DCA16B6D120DBE0E5876C4C867A4ACD3C3536AEADC14B908613D4E ] Wof             C:\Windows\system32\drivers\Wof.sys
21:04:22.0946 0x12f0  Wof - ok
21:04:23.0039 0x12f0  [ EDFA5CEDBE174FAAA4A09A6B297AEA42, 5998FE15462E4AD9C7B1444E5E2C17BD470DA3A5D474A0A118E02E47DADC678A ] workfolderssvc  C:\Windows\system32\workfolderssvc.dll
21:04:23.0102 0x12f0  workfolderssvc - ok
21:04:23.0149 0x12f0  [ A2468CC3509394A33C4C32F99563D845, 62690C7D41F382DF74B8F4B942647842858E37DE35FF2DE028192E4D09ABB2C5 ] wpcfltr         C:\Windows\system32\DRIVERS\wpcfltr.sys
21:04:23.0149 0x12f0  wpcfltr - ok
21:04:23.0196 0x12f0  [ 19F4DF69876DA7E9C4965351560FE6B7, 127247A7964F55EE3AF842D25120F5ACD387632BEE2BF3D28FAC05840CEA19BA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
21:04:23.0196 0x12f0  WPCSvc - ok
21:04:23.0247 0x12f0  [ DBDCE2378F65F0A07D4644AC103037E7, 99714F0CD31297C9831BAF04768F467F6E0BF710C859CEDCA83069226BF1A68A ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
21:04:23.0263 0x12f0  WPDBusEnum - ok
21:04:23.0294 0x12f0  [ 9F2904B55F6CECCD1A8D986B5CE2609A, E19ED4DD3CEF3A22C058FC324824604FB3FC98A029C94E6C2A3389F938D680B6 ] WpdUpFltr       C:\Windows\system32\drivers\WpdUpFltr.sys
21:04:23.0294 0x12f0  WpdUpFltr - ok
21:04:23.0311 0x12f0  [ AE072B0339D0A18E455DC21666CAD572, AB1DAEA25E2C7AD610818D4B4783F6D4190D85EBB3963BBAD410E8CEA7899EDB ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
21:04:23.0315 0x12f0  ws2ifsl - ok
21:04:23.0409 0x12f0  [ 7F78CEC3A96BEF80E1D20439BDE08A53, F59C53991F0CA399C7DBB1F2D20E278050AC6D6C7B3449053D9176E8AE84F86B ] WsAppService    C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe
21:04:23.0425 0x12f0  WsAppService - ok
21:04:23.0471 0x12f0  [ 501D5EFAB9711039479AE48401386D2B, C8C1184DE93E9D2C4E8A60E4E9980745C4E5470E5DA9B59165D18705330ADEFE ] wscsvc          C:\Windows\System32\wscsvc.dll
21:04:23.0487 0x12f0  wscsvc - ok
21:04:23.0518 0x12f0  [ F586F3F1BF962FE9AE4316E0D896B22F, 8D0AD48D79294567123D943D0F5B6D5A32D7A82B129A24DC821D3095AFAA100B ] WSDPrintDevice  C:\Windows\System32\drivers\WSDPrint.sys
21:04:23.0534 0x12f0  WSDPrintDevice - ok
21:04:23.0565 0x12f0  [ E9882425F2B45E7242AB8E4C2A88FAC8, 21A7C6EB0225BAF8BA0E56C1034143E519DF834027B884094B1DB370F91280A9 ] WsDrvInst       C:\Program Files (x86)\Wondershare\Dr.Fone for iOS\DriverInstall.exe
21:04:23.0581 0x12f0  WsDrvInst - detected UnsignedFile.Multi.Generic ( 1 )
21:04:23.0721 0x12f0  Detect skipped due to KSN trusted
21:04:23.0721 0x12f0  WsDrvInst - ok
21:04:23.0737 0x12f0  WSearch - ok
21:04:23.0909 0x12f0  [ 6B2D71124C1EA86B74412F414C42431D, 078CC6C9667EF6BDA3E6900BC26A5A5B030CAA66928A6BBB7B7DC43C5C199EDC ] WSService       C:\Windows\System32\WSService.dll
21:04:24.0050 0x12f0  WSService - ok
21:04:24.0221 0x12f0  [ F3F60C88A6BBC8D0C68FE5B1C91181AF, AF9A4D282CD4BB1127BC3F48AB89DC294408D96F7906553C636F37D1503CFA48 ] wuauserv        C:\Windows\system32\wuaueng.dll
21:04:24.0331 0x12f0  wuauserv - ok
21:04:24.0393 0x12f0  [ 481286719402E4BAEFEA0604AB1B5113, F3CF65DF2AB39F79AE4C1335831408418E40726706E0242677E8B96B0FAD988F ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
21:04:24.0409 0x12f0  WudfPf - ok
21:04:24.0440 0x12f0  [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFRd          C:\Windows\System32\drivers\WUDFRd.sys
21:04:24.0456 0x12f0  WUDFRd - ok
21:04:24.0503 0x12f0  [ 51D28F7F1F888DDCF2C67DCF3B79A5D3, 74FF2936AFCEB9A36175D5B00EB91A5AD614B52BE3FB3FA9B994A025A484D2B7 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
21:04:24.0518 0x12f0  wudfsvc - ok
21:04:24.0534 0x12f0  [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFWpdFs       C:\Windows\System32\drivers\WUDFRd.sys
21:04:24.0550 0x12f0  WUDFWpdFs - ok
21:04:24.0565 0x12f0  [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFWpdMtp      C:\Windows\system32\DRIVERS\WUDFRd.sys
21:04:24.0581 0x12f0  WUDFWpdMtp - ok
21:04:24.0628 0x12f0  [ A0900F8F628B5AF6841414EB3CF11E50, 8A531F2472FF4B4D895D469D28C215C834ECADBEF539894B8F3F606079A86184 ] WwanSvc         C:\Windows\System32\wwansvc.dll
21:04:24.0659 0x12f0  WwanSvc - ok
21:04:24.0878 0x12f0  [ 8D809F4ECFE9E80723C49B427854068A, 4186B6C56BA70106A95D28371360C780F55FECA1A1C61966F091A07A390BA189 ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
21:04:25.0018 0x12f0  ZeroConfigService - ok
21:04:25.0034 0x12f0  ZTEusbmdm6k - ok
21:04:25.0034 0x12f0  ZTEusbnmea - ok
21:04:25.0050 0x12f0  ZTEusbser6k - ok
21:04:25.0050 0x12f0  ================ Scan global ===============================
21:04:25.0096 0x12f0  [ 3500AF0BA2EF095BF313EEB75D2366C6, C755E57B02BFA82151A182DF964349859575570EA5C3FBA81F747B8D2134A4D0 ] C:\Windows\system32\basesrv.dll
21:04:25.0143 0x12f0  [ EAB311B0A7A8EA0346F14F08D4BC8F46, 11168E4074679F8A69DA714C0ABD0C68BA49D171B379343F14783C9C563202CA ] C:\Windows\system32\winsrv.dll
21:04:25.0175 0x12f0  [ 3600ED7EA8AED849E20700551C0BD63B, 4A8C346C1646E80B58EF93F87F915A41E05CA2E993BB1C96955AE62A0669AF66 ] C:\Windows\system32\sxssrv.dll
21:04:25.0206 0x12f0  [ E0C7813A97CA7947FF5C18A8F3B61A45, 083BB4F3B20419C87DB656F1465E5F782ACDE76838CDE6207F26AAD035C69DE0 ] C:\Windows\system32\services.exe
21:04:25.0221 0x12f0  [ Global ] - ok
21:04:25.0221 0x12f0  ================ Scan MBR ==================================
21:04:25.0237 0x12f0  [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
21:04:25.0320 0x12f0  \Device\Harddisk0\DR0 - ok
21:04:25.0321 0x12f0  ================ Scan VBR ==================================
21:04:25.0339 0x12f0  [ F2E003C99B8194B9FA3DF886A83B2FF0 ] \Device\Harddisk0\DR0\Partition1
21:04:25.0339 0x12f0  \Device\Harddisk0\DR0\Partition1 - ok
21:04:25.0355 0x12f0  [ B3A236913CD429187E21F32E273BEC41 ] \Device\Harddisk0\DR0\Partition2
21:04:25.0355 0x12f0  \Device\Harddisk0\DR0\Partition2 - ok
21:04:25.0371 0x12f0  [ C3933BD45DDFCDFF1A283193843D62C3 ] \Device\Harddisk0\DR0\Partition3
21:04:25.0371 0x12f0  \Device\Harddisk0\DR0\Partition3 - ok
21:04:25.0386 0x12f0  [ 7BB1AD532FA7ADBC6F765FE7CEFBA23E ] \Device\Harddisk0\DR0\Partition4
21:04:25.0386 0x12f0  \Device\Harddisk0\DR0\Partition4 - ok
21:04:25.0417 0x12f0  [ C729F97E3A77A24C34C5292F74C6B549 ] \Device\Harddisk0\DR0\Partition5
21:04:25.0417 0x12f0  \Device\Harddisk0\DR0\Partition5 - ok
21:04:25.0417 0x12f0  ================ Scan generic autorun ======================
21:04:25.0480 0x12f0  [ 31AB035B05B898AF044D41B33FD2E2F0, 1A8E5F36960C8F13AD6243194FBF348CE915D03B421103147C6A78E207292830 ] c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe
21:04:25.0527 0x12f0  TSVU - ok
21:04:25.0745 0x12f0  [ 7EE68A122ED08E4AAD8DA551E34D2515, B3C9AB270AF595D3DBAFBF4A312B96CBF00C16F0A03CCC86BE56825CD1EB7143 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
21:04:25.0886 0x12f0  SDTray - ok
21:04:25.0980 0x12f0  [ C9B67BCB8E384064A8C2263740B0C437, F2609406A84F3A8E256DD250F84A774EF43F92C9F8B373E297A99ACF95B3CCE4 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
21:04:26.0027 0x12f0  SunJavaUpdateSched - ok
21:04:26.0074 0x12f0  [ 735969F52578193ABF4EAEC7B370E311, D62F12DF0C915C28AD2FAA62CE013E833D24122CE14EA4F2B7F608A23AE9C0A2 ] C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe
21:04:26.0089 0x12f0  AnyMP4 Free iPhone Data RecoveryAppService - ok
21:04:26.0152 0x12f0  [ F51BB12D8977D26C1A4CDA348770D9F1, DDA35CD8F8A6591B83821B5180D457740E0B820CCE000BC7FB1B78FB4AEAD3BA ] C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe
21:04:26.0199 0x12f0  SpybotPostWindows10UpgradeReInstall - detected UnsignedFile.Multi.Generic ( 1 )
21:04:26.0355 0x12f0  Detect skipped due to KSN trusted
21:04:26.0355 0x12f0  SpybotPostWindows10UpgradeReInstall - ok
21:04:26.0355 0x12f0  Waiting for KSN requests completion. In queue: 184
21:04:26.0558 0x1348  Object required for P2P: [ F264662C057A54AA2DE41B3C7551712F ] sppsvc
21:04:26.0808 0x1348  Object send P2P result: true
21:04:27.0380 0x12f0  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.8.207.0 ), 0x60100 ( disabled : updated )
21:04:27.0442 0x12f0  Win FW state via NFP2: enabled ( trusted )
21:04:27.0598 0x12f0  ============================================================
21:04:27.0598 0x12f0  Scan finished
21:04:27.0598 0x12f0  ============================================================
21:04:27.0598 0x1184  Detected object count: 3
21:04:27.0598 0x1184  Actual detected object count: 3
21:04:48.0919 0x1184  Apple_Cfg ( UnsignedFile.Multi.Generic ) - skipped by user
21:04:48.0919 0x1184  Apple_Cfg ( UnsignedFile.Multi.Generic ) - User select action: Skip 
21:04:48.0919 0x1184  WinSAPSvc ( UnsignedFile.Multi.Generic ) - skipped by user
21:04:48.0919 0x1184  WinSAPSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 
21:04:48.0919 0x1184  WinSnare ( UnsignedFile.Multi.Generic ) - skipped by user
21:04:48.0919 0x1184  WinSnare ( UnsignedFile.Multi.Generic ) - User select action: Skip
         
__________________


Alt 21.02.2017, 11:03   #3
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Ich wollte die Problembeschreibung noch kurz ein wenig ergänzen, denn ich weiß ja auch nicht wirklich was es genau ist:

Ab und an öffnen sich neue Tabs (aber eher selten). Hinzu kommt Werbung, trotz Adblock.
Wenn ich facebook.com aufrufe, erscheint eine weiße Seite mit vielen Codes. Erst wenn ich danach FB nochmal aufrufe kommt die Seite auch.
Ich habe davon mal einen Screenshot angehangen. Keine Ahnung, ob das hier erlaubt und hilfreich ist oder eher unerwünscht.
Wenn unerwünscht: Sorry! Dann entferne ich das direkt wieder.

Lieben Gruß und danke!
Marius



Edit: Bild getauscht
__________________

Geändert von badkarmainc (21.02.2017 um 12:02 Uhr)

Alt 21.02.2017, 11:59   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



- auf deiner Briefmarke von screenshot kann niemand etwas erkennen
- Logs von Malwarebytes fehlen
- Spybot ist überflüssig, bitte deinstallieren
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 21.02.2017, 12:09   #5
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Hi Cosinus,
Haha, sorry! Screenshot getauscht.

Anbei die Malware logs.
Es sind ein paar, da ich es ein paar mal habe laufen lassen.

Spybot wird direkt deinstalliert.

Ich danke dir.
MfG,
Marius

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 16.02.2017
Suchlaufzeit: 00:25
Protokolldatei: mbam1.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2017.02.15.08
Rootkit-Datenbank: v2017.02.15.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: M

Suchlauftyp: Benutzerdefinierter Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 602462
Abgelaufene Zeit: 10 Std., 5 Min., 26 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 4
Adware.Elex, HKLM\SOFTWARE\jhtrsq, In Quarantäne, [271dd4cf9c0c60d61513fdbf31cfac54], 
Adware.Elex, HKLM\SOFTWARE\WOW6432NODE\jhtrsq, In Quarantäne, [d66e8a192f792e080325c9f33bc57a86], 
Adware.Linkury, HKU\.DEFAULT\SOFTWARE\jhtrsq, In Quarantäne, [84c0dfc4b1f7ba7cb3cdb30898681de3], 
Adware.Elex, HKU\S-1-5-18\SOFTWARE\jhtrsq, In Quarantäne, [cd774c573d6b64d2dbf7704a21df5ca4], 

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 6
PUP.Optional.FileTour, C:\Users\M\Desktop\BMH\BMH2016_17v1.1Classic_Edition24.10.2016.exe, In Quarantäne, [d66e3c679a0e82b4a9e84d8826dacf31], 
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.searchengine.hp", "hxxp://www.trotux.com/?z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=hp");), Ersetzt,[86be742faff948ee5454d3660af67888]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (41);
user_pref("app.update.lastUpdateTime.search-engine-update-timer", 1487169510);
user_pref("app.update.lastUpdateTime.xpi-signature-verification", 1487185902);
user_pref("browser.cache.disk.cap), Ersetzt,[1f25277cb6f238fe8f1955e423dd4cb4]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (pdateTime.xpi-signature-verification", 1487185902);
user_pref("browser.cache.disk.capacity", 358400);
user_pref("browser.cache.disk.filesystem_reported", 1);
user_pref("browser.cache.disk.smart_siz), Ersetzt,[2f15dcc72f790b2b4563c27743bda55b]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (date.lastUpdateTime.search-engine-update-timer", 1487), Ersetzt,[6dd7d2d15a4e2e08fcac6fca29d724dc]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (orted", 1);
user_pref("browser.cache.disk.smart_size.first_run", false);
user_pref("browser.cache.frecency_experiment", 4);
user_pref("browser.download.importedFromSql), Ersetzt,[5be9ddc65652171f1296d36648b809f7]

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org


Scan, 16.02.2017 00:09, SYSTEM, NOTEBOOK, Manual, Start: 15.02.2017 23:32, Dauer: 33 Min. 34 Sek., Bedrohungssuchlauf, Abgeschlossen, 0 Malware-Erkennung, 6 Nicht-Malware-Erkennungen, 
Scan, 16.02.2017 11:06, SYSTEM, NOTEBOOK, Manual, Start: 16.02.2017 00:25, Dauer: 10 Std. 5 Min. 26 Sek., Benutzerdefinierter Suchlauf, Abgeschlossen, 4 Malware-Erkennung, 6 Nicht-Malware-Erkennungen, 

(end)
         
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 15.02.2017
Suchlaufzeit: 22:44
Protokolldatei: mbam4.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2017.02.15.08
Rootkit-Datenbank: v2017.02.15.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: M

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 337410
Abgelaufene Zeit: 35 Min., 38 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 1
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\PGNet.exe, 3780, Löschen bei Neustart, [62e25e45515711251c738d56fe03758b]

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 13
PUP.Optional.Wajam, HKLM\SOFTWARE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, In Quarantäne, [b0945b485b4d4ee8aa201a882fd3e11f], 
PUP.Optional.Wajam, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, In Quarantäne, [be868f142187a78fd5f53e64ae542bd5], 
PUP.Optional.Wajam, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, In Quarantäne, [cf75ced51791aa8cd2f8782a1fe38d73], 
PUP.Optional.AppTrailers, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\AppTrailers, In Quarantäne, [dd67f2b1d4d4da5c0bed7303be427c84], 
Adware.Elex, HKLM\SOFTWARE\jhtrsq, In Quarantäne, [053f396a288012242ff99e1ee61a17e9], 
Adware.Elex, HKLM\SOFTWARE\WOW6432NODE\jhtrsq, In Quarantäne, [c183f8ab0b9dba7c87a15b6179877f81], 
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2A31-48E1-B4BB-3B42174BEA0F, Löschen bei Neustart, [ed577231c6e2171f310379e5936d926e], 
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\E24B7131-D039-43CB-9E6F-AD4BE601EC1F, Löschen bei Neustart, [c97b1f84a50310263301095538c841bf], 
Adware.Sasquor.SPL, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\PRINT\PROVIDERS\7LDP4N9K, In Quarantäne, [8cb8742fefb9152136dc0284817f7b85], 
Adware.Linkury, HKU\.DEFAULT\SOFTWARE\jhtrsq, In Quarantäne, [cf75c7dcabfd30068000f9c27d83768a], 
Adware.Elex, HKU\S-1-5-18\SOFTWARE\jhtrsq, In Quarantäne, [d470881b297f4aec8f43249690707789], 
PUP.Optional.OneSystemCare, HKU\S-1-5-21-235318688-4269726762-198329688-1001\SOFTWARE\One System Care, In Quarantäne, [152fa201f4b4b086917c9282c739f907], 
PUP.Optional.AppTrailers, HKU\S-1-5-21-235318688-4269726762-198329688-1001\SOFTWARE\APPDATALOW\SOFTWARE\AppTrailers, In Quarantäne, [ad975b482088b87e3f43c192f40c31cf], 

Registrierungswerte: 5
PUP.Optional.GoldClick, HKU\S-1-5-21-235318688-4269726762-198329688-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\MainService.exe, In Quarantäne, [58ec3c67268269cd6c23edf61ee3fa06]
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2a31-48e1-b4bb-3b42174bea0f|Description, One System Care battery save scheme., Löschen bei Neustart, [ed577231c6e2171f310379e5936d926e]
PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\e24b7131-d039-43cb-9e6f-ad4be601ec1f|Description, One System Care game scheme., Löschen bei Neustart, [c97b1f84a50310263301095538c841bf]
Adware.Sasquor.SPL, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\PRINT\PROVIDERS\7ldp4n9k|Name, C:\Program Files (x86)\Cerigharijeied Monitor\local64spl.dll, In Quarantäne, [8cb8742fefb9152136dc0284817f7b85]
PUP.Optional.AppTrailers, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\AppTrailers.exe su, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96]

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 16
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppTrailers, In Quarantäne, [e85ce6bdcbdd54e22c2b74bf51afe51b], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate, Löschen bei Neustart, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\ocx, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\index-dir, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\GPUCache, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Local Storage, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
Adware.Elex.Generic, C:\Program Files (x86)\Cerigharijeied Monitor, Löschen bei Neustart, [7aca8b18525644f2db69793242be0bf5], 
PUP.Optional.FakeFFProfile, C:\Users\M\AppData\Roaming\Mozilla\Firefox\naweriweentcofise, In Quarantäne, [66dee6bd8820e05624ef0caf1ee2a957], 
PUP.Optional.FakeFFProfile, C:\Users\M\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles, In Quarantäne, [66dee6bd8820e05624ef0caf1ee2a957], 
PUP.Optional.FakeFFProfile, C:\Users\M\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\9079h1at.default-1481549202673, In Quarantäne, [66dee6bd8820e05624ef0caf1ee2a957], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\447beb81-0057-1, In Quarantäne, [86bebee5f4b494a211c1339a06fc7f81], 
PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\447beb81-21a5-0, In Quarantäne, [54f0099a396f3df9e0f22f9ed72beb15], 

Dateien: 203
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\PGNet.exe, In Quarantäne, [62e25e45515711251c738d56fe03758b], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\MainService.exe, In Quarantäne, [58ec3c67268269cd6c23edf61ee3fa06], 
Adware.Elex, C:\Program Files (x86)\Cerigharijeied Monitor\local64spl.dll, Löschen bei Neustart, [b88c23804e5a23133a0fbf33728e2bd5], 
Adware.OtherSearch, C:\Program Files (x86)\Ex1iV4c7ul\updengine.exe, In Quarantäne, [ce7642612a7e7cba8069ee06ba46a15f], 
PUP.Optional.FileTour, C:\$RECYCLE.BIN\S-1-5-21-235318688-4269726762-198329688-1001\$RVSQ8GR.zip, In Quarantäne, [1331f2b1bbedaf876130efe6a35daf51], 
Adware.OptimizerEliteMax, C:\Users\M\AppData\Local\Temp\~nsuA.tmp\Un_A.exe, In Quarantäne, [7bc9a201f4b4d85e8dd1809157a95ba5], 
Adware.OptimizerEliteMax, C:\Users\M\AppData\Local\Temp\9C1465E9-896F-4200-AB8E-9D8B059AD351\onesystemcare.exe, In Quarantäne, [4ff563405850a4925c025fb2ab55b54b], 
Adware.OtherSearch, C:\Users\M\AppData\Local\Temp\6F8AC461-C727-4BDF-9297-F28135C3B559\setupos_4435.exe, In Quarantäne, [b68eefb4604863d301e843b127d9d927], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\Temp\2832E150-0E43-42A6-805E-12D1E3316A51\AppTrailers.9.1.10amt.exe, In Quarantäne, [073d8320beea55e130c820566b952fd1], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\Uninstall.exe, In Quarantäne, [dd67f2b1d4d4da5c0bed7303be427c84], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\Cloud.exe, Löschen bei Neustart, [b68efca76345a88eb5f16a8da0617e82], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\PGChk.exe, Löschen bei Neustart, [3410ecb7a5032a0c8708608322dfaf51], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\PGCommon.dll, Löschen bei Neustart, [83c1b1f225831026365931b2a8598977], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\PGHelp.exe, In Quarantäne, [e460f2b13078261069264c979170748c], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\PGLog.exe, In Quarantäne, [c183f0b34d5b4bebcec1c91a00012cd4], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\PGUpd.exe, In Quarantäne, [ea5a71326e3aeb4ba0ef05dec43d53ad], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\ProxyGate.exe, In Quarantäne, [f94b584be5c3f2441d729a49aa5750b0], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\Socket.exe, In Quarantäne, [4df7188bfeaaa591f6996d76ab5644bc], 
PUP.Optional.GoldClick, C:\Users\M\AppData\Roaming\ProxyGate\TrafficMonitor.exe, In Quarantäne, [3a0a3172d0d847ef2d628360798805fb], 
Adware.Elex.SHHKRST, C:\Users\M\AppData\Roaming\Thujghprikuk\Mervichjomus.dll7ld, Löschen bei Neustart, [82c2aff4c0e87fb708b728b802fe718f], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppTrailers\AppTrailers.lnk, In Quarantäne, [e85ce6bdcbdd54e22c2b74bf51afe51b], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppTrailers\Uninstall.lnk, In Quarantäne, [e85ce6bdcbdd54e22c2b74bf51afe51b], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\dns.dat, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\conf.dat, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\Config.ini, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\dbghelp.dll, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\list.dat, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\msvbvm60.dll, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\Skin.dll, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\TrafficMonitor.ini, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.ProxyGate, C:\Users\M\AppData\Roaming\ProxyGate\ocx\mscomctl.ocx, In Quarantäne, [ea5a82213d6bd16525d8b783e31d3ec2], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Web Data, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\cookies, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\cookies-journal, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Web Data-journal, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\014a6e36cd7a2672_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\02781cf283bad338_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\02cdb733b079655d_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\08bc571418449ead_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\0ed73590870cfbd2_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\0ed7399215f555d7_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\0fc3db66b9cbe75d_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\13bc7fe2ce10c502_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\1b72c2d37a2af109_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\1dff67c9badf383d_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\1e20774a42d716f3_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\2009bcf78a35d470_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\5ede7465ad814101_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\66928cc3398bdbc9_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\66e510668b4796e9_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\690236e4ca6ee8d1_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\6a049d05dc31f2bf_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\6fc4a9ca4705c533_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\711f9f610e35a8b6_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\7589f80f2ddeab29_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\7d3cfe5499733980_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\7d8cebaadfd53fbf_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\8326a92c0f293bc4_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\83a226c1379f7a18_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\c0676a458818319d_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\c3329b5e71fb9773_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\c487316b1c7eb401_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\c8bff37e9d993e8c_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\c94b3024dfacfceb_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\c9efb04ec241100a_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\cb0dfcc6c7914e3c_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\cd87b6402756547b_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\d19a15ac54bfa3ba_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\d652598e0bff0a74_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\dc7c883ebdb4ce43_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\dd1fa8967c9eedf1_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\e42bcf862c9a2ba1_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\886edbdb0dbe5c47_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\8d9b27c428a8f6a3_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\8f60e69a4afd6f60_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\90739661538ff8cf_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\95ff98c7e9c1b8a3_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\98be65afa5c12f43_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\a1f309cd5a3eb6fa_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\a2719229322771c8_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\a718cbb69bd3e0dc_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\b3986aa6d1a5b1ca_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\b3edef432256edd5_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\b4a9fae96af3d9f5_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\bd48447363dfb226_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\be189d201694bf89_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\2200c41c444447b0_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\234986793e71f265_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\26968e7a0c71776d_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\26d30f525022e864_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\2819c5233c1f77b4_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\28239d6109086916_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\2ac381ccd53e2ce0_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\2b11e2e523e5d524_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\2da6596685c17f79_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\3082972055161e5d_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\34d622f47f721e3a_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\f4beaede20fc0699_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\f552ab47376f113e_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\f74a8c1655500d73_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\fbef9ceaf336383d_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\fddd11ea475c5135_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\index, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\87d1756029a26ce9_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\bf6f7a13953dbf3e_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\ec30fb4a4dfde26a_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\3a977894dc0fcd39_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\442182c02ee0a243_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\4d75eab78299f375_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\4ed7b320ac278191_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\5125b9f58b582f46_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\57856881eb7720ed_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\593d0e1547012291_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Cache\index-dir\the-real-index, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\GPUCache\data_0, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\GPUCache\data_1, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\GPUCache\data_2, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\GPUCache\data_3, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\GPUCache\index, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Local Storage\file__0.localstorage, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Local Storage\file__0.localstorage-journal, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Local Storage\http_www.imdb.com_0.localstorage, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Local\AppTrailers\Local Storage\http_www.imdb.com_0.localstorage-journal, In Quarantäne, [2a1a0e95a206dd591fd1d6795fa13dc3], 
Adware.Elex.Generic, C:\Program Files (x86)\Cerigharijeied Monitor\local64spl.dll.ini, In Quarantäne, [7aca8b18525644f2db69793242be0bf5], 
Trojan.Agent, C:\Windows\76d5fa8fd3020718f7133f7301d20d13.exe, In Quarantäne, [390be0c3a503c96d8097cb4f42c18d73], 
PUP.Optional.Amonetize.Gen, C:\ProgramData\447beb81-0057-1\BITCB7C.tmp, In Quarantäne, [3a0ad9caf0b8290dd84e6c4eb25111ef], 
PUP.Optional.Amonetize.Gen, C:\ProgramData\447beb81-21a5-0\BITF0E7.tmp, In Quarantäne, [63e122813c6c082e1b0be1d912f11be5], 
PUP.Optional.FakeFFProfile, C:\Users\M\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\9079h1at.default-1481549202673\prefs.js, In Quarantäne, [66dee6bd8820e05624ef0caf1ee2a957], 
PUP.Optional.FakeFFProfile, C:\Users\M\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\9079h1at.default-1481549202673\profiles.ini, In Quarantäne, [66dee6bd8820e05624ef0caf1ee2a957], 
PUP.Optional.FakeFFProfile, C:\Users\M\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\9079h1at.default-1481549202673\search.json.mozlz4, In Quarantäne, [66dee6bd8820e05624ef0caf1ee2a957], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\AppTrailers.exe, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\AutoUpdater.Config, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\ffmpegsumo.dll, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\icudtl.dat, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\nw.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\storage.json, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\hr.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\am.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ar.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\bg.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\bn.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ca.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\cs.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\da.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\de.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\el.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\en-GB.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\en-US.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\es-419.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\es.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\et.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\fa.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\fi.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\fil.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\fr.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\gu.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\hi.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\hu.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\id.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\it.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\iw.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ja.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\kn.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ko.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\lt.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\lv.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ml.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\mr.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ms.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\nl.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\no.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\pl.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\pt-BR.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\pt-PT.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ro.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ru.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\sk.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\sl.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\sr.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\sv.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\sw.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\ta.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\te.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\th.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\tr.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\uk.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\vi.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\zh-CN.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.AppTrailers, C:\Users\M\AppData\Roaming\AppTrailers\locales\zh-TW.pak, In Quarantäne, [75cf366d8226181e7ef8c02ff9076a96], 
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trotux.com/?z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=hp");), Ersetzt,[ae96683b91172c0acb62b771b054926e]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\prefs.js, Gut: (), Schlecht: (e);
user_pref("browser.cache.frecency_experiment", 4);
user_pref("browser.download.importedFromSqlite", true);
user_pref("browser.download.lastDir", "C:\\Users\\M\\Desktop")), Ersetzt,[152f8023d9cff244131a59cff90b12ee]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\prefs.js, Gut: (), Schlecht: (cation is running,
 * the changes will be overwritten when the application exits.
 *
 * To make a manual change to preferences, you can visit the URL about:config
 */

user_pref("accessibility.), Ersetzt,[69dbf2b19018de586ac3b474f410b749]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\prefs.js, Gut: (), Schlecht: (e to preferences, you can visit the URL about:config
 */

user_pref("accessibility.typeaheadfind", true);
user_pref("accessibility.typeaheadfind.flashBar", 0);
user_pref("app.update.auto", false)), Ersetzt,[350f5a496d3bf640082505236b9910f0]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\prefs.js, Gut: (), Schlecht: (("app.update.lastUpdateTime.background-update-timer", 1487187390);
user_pref("app.update.lastUpdateTime.blocklist-background-update-timer", 1487185781);
user_pref("app.), Ersetzt,[7ec692112b7d55e169c436f2d1339967]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\searchplugins\7ldp4n9k.xml, In Quarantäne, [a59f61425c4c979fba69ab7db45051af], 
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trotux.com/?z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=hp");), Ersetzt,[0c38861d446430065553d564629ef709]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (er.cache.disk.hashstats_reported", 1);
user_pref("brows), Ersetzt,[7dc7940f3c6cb97dcbddca6f5ba5f20e]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (s file.
 *
 * If you make changes to this file while the application is running,
 * the changes will be overwritten when the application exits.
 *
 * To make a manual chan), Ersetzt,[8eb64261faae6dc9e1c7043535cbe818]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (on is running,
 * the changes will be overwritten when the application exits.
 *
 * To make a manual change to preferences, you can visit the URL about:config
 */

user_pref("accessibility.type), Ersetzt,[a1a35053c1e7ed492781e25716ea5ea2]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: ( preferences, you can visit the URL about:config
 */

user_pref("accessibility.typeaheadfind", true);
user_pref("accessibility.typeaheadfind.flashBar", 0);
user_pref("app.update.auto", false);
u), Ersetzt,[b88c8e157a2e82b44a5e85b4e51b3ec2]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (changes will be overwritten when the application exit), Ersetzt,[cb79861dbaeef046a305ac8d966a0ff1]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\prefs.js, Gut: (), Schlecht: (shBar", 0);
user_pref("app.update.auto", false);
user_pref("app.update.enabled", false);
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 148718566), Ersetzt,[46fea4ffe8c068ceb4f4c5747789a55b]
PUP.Optional.Trotux, C:\Users\M\AppData\Roaming\Profiles\Tuwergepeb.default\searchplugins\7ldp4n9k.xml, In Quarantäne, [f450cfd41a8e78be482ca565fb0537c9], 

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org


Update, 15.02.2017 08:44, SYSTEM, NOTEBOOK, Manual, Remediation Database, 2017.2.14.1, 2017.2.14.2, 
Update, 15.02.2017 08:44, SYSTEM, NOTEBOOK, Manual, IP Database, 2017.2.13.6, 2017.2.14.6, 
Update, 15.02.2017 08:44, SYSTEM, NOTEBOOK, Manual, Domain Database, 2017.2.14.9, 2017.2.15.1, 
Update, 15.02.2017 08:44, SYSTEM, NOTEBOOK, Manual, Malware Database, 2017.2.14.5, 2017.2.15.2, 
Protection, 15.02.2017 08:44, SYSTEM, NOTEBOOK, Protection, Refresh, Starting, 
Protection, 15.02.2017 08:52, SYSTEM, NOTEBOOK, Protection, Refresh, Success, 
Scan, 15.02.2017 19:56, SYSTEM, NOTEBOOK, Manual, Start: 15.02.2017 08:44, Dauer: 11 Std. 11 Min. 17 Sek., Benutzerdefinierter Suchlauf, Abgeschlossen, 0 Malware-Erkennung, 0 Nicht-Malware-Erkennungen, 
Update, 15.02.2017 22:43, SYSTEM, NOTEBOOK, Manual, Rootkit Database, 2017.2.11.1, 2017.2.15.1, 
Update, 15.02.2017 22:43, SYSTEM, NOTEBOOK, Manual, Remediation Database, 2017.2.14.2, 2017.2.15.2, 
Update, 15.02.2017 22:43, SYSTEM, NOTEBOOK, Manual, IP Database, 2017.2.14.6, 2017.2.15.2, 
Update, 15.02.2017 22:43, SYSTEM, NOTEBOOK, Manual, Domain Database, 2017.2.15.1, 2017.2.15.10, 
Update, 15.02.2017 22:43, SYSTEM, NOTEBOOK, Manual, Malware Database, 2017.2.15.2, 2017.2.15.8, 
Protection, 15.02.2017 22:43, SYSTEM, NOTEBOOK, Protection, Refresh, Starting, 
Protection, 15.02.2017 22:49, SYSTEM, NOTEBOOK, Protection, Refresh, Success, 
Scan, 15.02.2017 23:20, SYSTEM, NOTEBOOK, Manual, Start: 15.02.2017 22:44, Dauer: 35 Min. 38 Sek., Bedrohungssuchlauf, Abgeschlossen, 15 Malware-Erkennung, 223 Nicht-Malware-Erkennungen, 
Update, 15.02.2017 23:32, SYSTEM, NOTEBOOK, Manual, IP Database, 2017.2.15.2, 2017.2.15.3, 
Protection, 15.02.2017 23:32, SYSTEM, NOTEBOOK, Protection, Refresh, Starting, 
Protection, 15.02.2017 23:32, SYSTEM, NOTEBOOK, Protection, Refresh, Success, 

(end)
         
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlaufdatum: 15.02.2017
Suchlaufzeit: 08:44
Protokolldatei: mbam6.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2017.02.15.02
Rootkit-Datenbank: v2017.02.11.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: M

Suchlauftyp: Benutzerdefinierter Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 613321
Abgelaufene Zeit: 11 Std., 11 Min., 17 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)
         


Alt 21.02.2017, 12:21   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

__________________
--> Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe

Alt 21.02.2017, 12:44   #7
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Hi,
Beides erledigt.

Anbei die Logs:

Code:
ATTFilter
# AdwCleaner v6.043 - Bericht erstellt am 21/02/2017 um 12:33:17
# Aktualisiert am 27/01/2017 von Malwarebytes
# Datenbank : 2017-02-20.3 [Server]
# Betriebssystem : Windows 8.1  (X64)
# Benutzername : M - NOTEBOOK
# Gestartet von : C:\Users\M\Desktop\AdwCleaner_6.043.exe
# Modus: Löschen
# Unterstützung : https://www.malwarebytes.com/support



***** [ Dienste ] *****

[-] Dienst gelöscht: FirefoxU
[-] Dienst gelöscht: WinSAPSvc
[-] Dienst gelöscht: ed2kidle
[-] Dienst gelöscht: WinSnare


***** [ Ordner ] *****

[-] Ordner gelöscht: C:\Program Files (x86)\WinSnare(4.1.0)
[-] Ordner gelöscht: C:\Users\M\AppData\RoaMing\WinSAPSvc
[#] Ordner mit Neustart gelöscht: C:\Users\M\AppData\RoaMing\winsapsvc
[-] Ordner gelöscht: C:\Users\M\AppData\RoaMing\WinSnare
[-] Ordner gelöscht: C:\Program Files (x86)\Up Pro
[-] Ordner gelöscht: C:\Program Files (x86)\Firefox
[#] Ordner mit Neustart gelöscht: C:\Users\M\AppData\Roaming\WinSnare


***** [ Dateien ] *****

[-] Datei gelöscht: C:\Users\Public\Documents\temp.dat
[-] Datei gelöscht: C:\Users\Public\Documents\report.dat


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Verknüpfungen ] *****



***** [ Aufgabenplanung ] *****

[-] Aufgabe gelöscht: PNlf14iPF6


***** [ Registrierungsdatenbank ] *****

[-] Schlüssel gelöscht: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Sample.BrowserHandler
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Sample.BrowserHandler.1
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample.1
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Sample.BrowserHandler
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Sample.BrowserHandler.1
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample.1
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{D42C3A49-ABAF-464B-BBCE-991C3DD395E8}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{BF8946CD-EEBE-436B-8282-B19A021C9EFE}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\TypeLib\{38DD0B4A-E4E0-4A57-99EE-DCCB185B4728}
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
[-] Schlüssel gelöscht: HKU\.DEFAULT\Software\jhtrsq
[#] Schlüssel mit Neustart gelöscht: HKU\S-1-5-18\Software\jhtrsq
[-] Schlüssel gelöscht: HKLM\SOFTWARE\ScreenShot
[-] Schlüssel gelöscht: HKLM\SOFTWARE\amule-custom
[-] Schlüssel gelöscht: HKLM\SOFTWARE\jhtrsq
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B6DCCCD3-520D-4485-B642-FCC136CE12C3}
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\jhtrsq
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\InterSect Alliance
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Installer\Features\3DCCCD6BD02558446B24CF1C63EC213C
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Installer\Features\3DCCCD6BD02558446B24CF1C63EC213C
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\watch4.de
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.watch4.de
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\watch4.de
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.watch4.de
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]


***** [ Browser ] *****

[-] [C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData] [startup_urls] Gelöscht: hxxp://www.trotux.com/?z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=hp
[-] [C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData] [homepage] Gelöscht: hxxp://www.trotux.com/?z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=hp


*************************

:: "Tracing" Schlüssel gelöscht
:: Winsock Einstellungen zurückgesetzt
:: Proxy Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [6372 Bytes] - [21/02/2017 12:33:17]
C:\AdwCleaner\AdwCleaner[S0].txt - [6061 Bytes] - [21/02/2017 12:31:58]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [6518 Bytes] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 8.1 x64 
Ran by M (Administrator) on 21.02.2017 at 12:39:31,05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 2 

Failed to delete: C:\ProgramData\pdfforge (Folder) 
Successfully deleted: C:\Windows\wininit.ini (File) 



Registry: 2 

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B4D5D8A2-D50E-4C0D-BEAC-2CB6CA3D0951} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} (Registry Value) 




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.02.2017 at 12:42:01,79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

Alt 21.02.2017, 13:29   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Wir haben leider noch ne ältere Anleitung vom adwCleaner, bitte nochmal ausführen und so einstellen:

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 21.02.2017, 13:38   #9
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Ok, Prefatch fehlte mir. :-)

Code:
ATTFilter
# AdwCleaner v6.043 - Bericht erstellt am 21/02/2017 um 13:32:24
# Aktualisiert am 27/01/2017 von Malwarebytes
# Datenbank : 2017-02-20.3 [Lokal]
# Betriebssystem : Windows 8.1  (X64)
# Benutzername : M - NOTEBOOK
# Gestartet von : C:\Users\M\Desktop\AdwCleaner_6.043.exe
# Modus: Löschen
# Unterstützung : https://www.malwarebytes.com/support



***** [ Dienste ] *****



***** [ Ordner ] *****



***** [ Dateien ] *****

[-] Datei gelöscht: C:\Users\Public\Documents\temp.dat


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Verknüpfungen ] *****



***** [ Aufgabenplanung ] *****



***** [ Registrierungsdatenbank ] *****



***** [ Browser ] *****



*************************

:: "Tracing" Schlüssel gelöscht
:: Winsock Einstellungen zurückgesetzt
:: "Prefetch" Dateien gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [6657 Bytes] - [21/02/2017 12:33:17]
C:\AdwCleaner\AdwCleaner[C2].txt - [1076 Bytes] - [21/02/2017 13:32:24]
C:\AdwCleaner\AdwCleaner[S0].txt - [6061 Bytes] - [21/02/2017 12:31:58]
C:\AdwCleaner\AdwCleaner[S1].txt - [1486 Bytes] - [21/02/2017 13:31:47]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1295 Bytes] ##########
         

Alt 21.02.2017, 13:50   #10
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 21.02.2017, 13:57   #11
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Da ist er:

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 19-02-2017
durchgeführt von M (Administrator) auf NOTEBOOK (21-02-2017 13:51:54)
Gestartet von C:\Users\M\Desktop
Geladene Profile: M (Verfügbare Profile: M)
Platform: Windows 8.1 (Update) (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1")
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidMonitorSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Don HO don.h@free.fr) C:\Program Files (x86)\notepad2\notepad2.exe
(pdfforge GmbH) C:\Program Files\PDF Architect 4\creator-ws.exe
(© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\System Setting\TssSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TDUSrv64.exe
() C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [] => [X]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672664 2014-06-30] (Realtek Semiconductor)
HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296008 2013-10-22] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-10-09] (TOSHIBA Corporation)
HKLM\...\Run: [ThpSrv] => C:\Windows\system32\thpsrv /logon
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [354144 2013-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [179288 2014-04-17] (TOSHIBA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [517536 2014-04-07] (TOSHIBA)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595480 2016-03-20] (Oracle Corporation)
HKLM-x32\...\Run: [AnyMP4 Free iPhone Data RecoveryAppService] => C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe [88128 2016-10-28] ()
HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\MountPoints2: {6fd17b76-c396-11e5-8296-303a64aa1620} - "E:\AutoRun.exe" 
ShellExecuteHooks: Kein Name - {586292BE-F1AE-11E6-81CC-64006A5CFC23} - C:\Users\M\AppData\Roaming\Thujghprikuk\Mervichjomus.dll -> Keine Datei
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{01A3239A-66E6-4A37-95D3-D88991033A6A}: [DhcpNameServer] 192.168.1.251 8.8.8.8
Tcpip\..\Interfaces\{76A32D41-DACA-45F5-872C-C9D20FEE27CB}: [DhcpNameServer] 192.168.2.1
ManualProxies: 

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-235318688-4269726762-198329688-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-235318688-4269726762-198329688-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation)
BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-08-05] (pdfforge GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-04-04] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-05-14] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-04] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT

FireFox:
========
FF ProfilePath: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673 [2017-02-21]
FF Homepage: Mozilla\Firefox\Profiles\9079h1at.default-1481549202673 -> hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
FF Extension: (Adblock Plus) - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-12]
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\features\{302110b3-b1bf-4951-82d4-8122016fa5b1}\disableSHA1rollout@mozilla.org.xpi [2017-02-17]
FF SearchPlugin: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\searchplugins\startpageing123.xml [2017-02-21]
FF ProfilePath: C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673 [2017-02-21]
FF Homepage: Firefox\Firefox\Profiles\9079h1at.default-1481549202673 -> about:home
FF Extension: (SimilarWeb) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\@DA3566E2-F709-11E5-8E87-A604BC8E7F8B.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (FF Adr) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (Deutsch (DE) Language Pack) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\langpack-de@firefox.mozilla.org.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (Adblock Plus) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-12]
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\features\{302110b3-b1bf-4951-82d4-8122016fa5b1}\disableSHA1rollout@mozilla.org.xpi [2017-02-17]
FF SearchPlugin: C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\searchplugins\searchinme.xml [2017-02-17]
FF Extension: (UITBAutoInstaller) - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{edd7fc99-d65c-4979-85c2-ddeed30c50c7} [2016-11-18] [ist nicht signiert]
FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension
FF Extension: (PDF Architect 4 Creator) - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension [2016-09-19] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-15] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-15] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-25] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: PDF Architect 4 -> C:\Program Files (x86)\PDF Architect 4\np-previewer.dll [2016-08-05] (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-235318688-4269726762-198329688-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2017-02-15]

Chrome: 
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxps://www.google.com/
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}&z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=sp
CHR DefaultSearchKeyword: ChromeDefaultData -> trotux
CHR Profile: C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-15] <==== ACHTUNG
CHR Extension: (Google Präsentationen) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-07]
CHR Extension: (Google Docs) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-07]
CHR Extension: (Google Drive) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-07]
CHR Extension: (YouTube) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-07]
CHR Extension: (Google Tabellen) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-07]
CHR Extension: (Google Docs Offline) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-07]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-07]
CHR Extension: (Google Mail) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-07]
StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 ApHidMonitorService; C:\Program Files\Apoint2K\HidMonitorSvc.exe [87384 2014-07-12] (Alps Electric Co., Ltd.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 Apple_Cfg; C:\ProgramData\Apple\Apple Application Support\Support.dll [111104 2017-02-17] () [Datei ist nicht signiert]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042032 2016-12-13] (Microsoft Corporation)
R3 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [21840 2014-06-11] ()
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [315352 2014-06-17] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-12-09] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-09] (Intel Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-05-30] ()
R2 Ntp2NetSvc; C:\Program Files (x86)\notepad2\notepad2.exe [2340864 2017-02-16] (Don HO don.h@free.fr) [Datei ist nicht signiert]
S2 Ntp2UpSvc; C:\Program Files (x86)\Common Files\ntp2UpSvc\notepad2.exe [2340864 2017-02-16] (Don HO don.h@free.fr) [Datei ist nicht signiert]
S3 PDF Architect 4; C:\Program Files\PDF Architect 4\ws.exe [2438880 2016-08-05] (pdfforge GmbH)
S3 PDF Architect 4 CrashHandler; C:\Program Files\PDF Architect 4\crash-handler-ws.exe [1038048 2016-08-05] (pdfforge GmbH)
R2 PDF Architect 4 Creator; C:\Program Files\PDF Architect 4\creator-ws.exe [851168 2016-08-05] (pdfforge GmbH)
R2 PDF Architect 4 Manager; C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe [972056 2016-05-18] (© pdfforge GmbH.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116088 2013-12-24] (Toshiba Europe GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe [437392 2016-10-10] (Wondershare)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\Dr.Fone for iOS\DriverInstall.exe [97792 2016-11-30] (Wondershare) [Datei ist nicht signiert]
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-05-30] (Intel® Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [191944 2014-05-09] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-02-21] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-09] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3446240 2014-06-18] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [27136 2014-03-24] (Windows (R) Win 7 DDK provider)
S1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-09-08] (Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 ZTEusbmdm6k; \SystemRoot\system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; \SystemRoot\system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; \SystemRoot\system32\DRIVERS\ZTEusbser6k.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-02-21 13:51 - 2017-02-21 13:51 - 00000000 ____D C:\Users\M\Desktop\FRST-OlderVersion
2017-02-21 13:35 - 2017-02-21 13:35 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-02-21 12:42 - 2017-02-21 12:42 - 00000921 _____ C:\Users\M\Desktop\JRT.txt
2017-02-21 12:38 - 2017-02-21 12:38 - 01663040 _____ (Malwarebytes) C:\Users\M\Desktop\JRT.exe
2017-02-21 12:36 - 2017-02-21 12:36 - 00006660 _____ C:\Users\M\Desktop\AdwCleaner[C0].txt
2017-02-21 12:28 - 2017-02-21 13:32 - 00000000 ____D C:\AdwCleaner
2017-02-21 12:27 - 2017-02-21 12:27 - 04015056 _____ C:\Users\M\Desktop\AdwCleaner_6.043.exe
2017-02-21 12:07 - 2017-02-21 12:07 - 00001211 _____ C:\Users\M\Desktop\mbam5.txt
2017-02-21 12:06 - 2017-02-21 12:06 - 00001908 _____ C:\Users\M\Desktop\mbam4.txt
2017-02-21 12:05 - 2017-02-21 12:05 - 00036716 _____ C:\Users\M\Desktop\mbam3.txt
2017-02-21 12:04 - 2017-02-21 12:04 - 00003226 _____ C:\Users\M\Desktop\mbam1.txt
2017-02-21 12:04 - 2017-02-21 12:04 - 00000449 _____ C:\Users\M\Desktop\mbam2.txt
2017-02-20 13:42 - 2017-02-20 13:42 - 00000000 ____D C:\Program Files (x86)\Standuck
2017-02-17 21:05 - 2017-02-17 21:04 - 00235836 _____ C:\Users\M\Desktop\TDSSKiller.3.1.0.12_17.02.2017_21.02.29_log.txt
2017-02-17 21:02 - 2017-02-17 21:06 - 00235924 _____ C:\TDSSKiller.3.1.0.12_17.02.2017_21.02.29_log.txt
2017-02-17 21:02 - 2017-02-17 21:02 - 04747704 _____ (AO Kaspersky Lab) C:\Users\M\Desktop\tdsskiller.exe
2017-02-17 20:58 - 2017-02-17 20:58 - 00034795 _____ C:\Users\M\Desktop\Addition.txt
2017-02-17 20:57 - 2017-02-21 13:53 - 00026828 _____ C:\Users\M\Desktop\FRST.txt
2017-02-17 20:56 - 2017-02-21 13:51 - 02422784 _____ (Farbar) C:\Users\M\Desktop\FRST64.exe
2017-02-17 19:42 - 2017-02-17 19:42 - 00000000 ____D C:\Users\M\AppData\Local\Firefox
2017-02-17 19:41 - 2017-02-20 13:42 - 00000219 _____ C:\Users\Public\Desktop\Google Chrome.url
2017-02-17 19:41 - 2017-02-17 19:41 - 00000000 ____D C:\Users\M\AppData\Roaming\Firefox
2017-02-17 19:41 - 2017-02-17 19:41 - 00000000 ____D C:\Users\M\AppData\Local\Standuck
2017-02-16 12:20 - 2017-02-16 12:20 - 00000000 ____D C:\Users\M\AppData\Local\DOSBox
2017-02-16 12:14 - 2017-02-21 12:14 - 00000000 ____D C:\Program Files (x86)\BikaQRssReader
2017-02-16 12:14 - 2017-02-16 12:14 - 00003218 _____ C:\Windows\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-02-16 12:14 - 2017-02-16 12:14 - 00000000 ____D C:\Program Files (x86)\notepad2
2017-02-16 12:13 - 2017-02-20 12:13 - 00000000 ____D C:\Program Files (x86)\7ldp4n9k
2017-02-15 23:27 - 2017-02-21 12:33 - 00000008 __RSH C:\Users\M\ntuser.pol
2017-02-15 22:35 - 2017-02-15 22:35 - 00003080 _____ C:\Windows\System32\Tasks\{19F6666D-E5AA-4781-BD88-047860B4F25B}
2017-02-15 22:32 - 2017-02-15 22:32 - 00003084 _____ C:\Windows\System32\Tasks\{CA17C8C7-3267-4637-8D2D-7ABA72B5B2D0}
2017-02-15 22:17 - 2017-02-21 12:33 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-02-15 22:15 - 2017-02-15 23:20 - 00000000 ____D C:\Program Files (x86)\Ex1iV4c7ul
2017-02-15 22:14 - 2017-02-15 22:34 - 00000000 ____D C:\Windows\system32\SSL
2017-02-15 22:13 - 2017-02-20 13:38 - 00000000 ____D C:\Program Files (x86)\Gherkadomijly
2017-02-15 22:13 - 2017-02-15 23:25 - 00000000 ____D C:\Users\M\AppData\Roaming\Thujghprikuk
2017-02-15 22:13 - 2017-02-15 22:15 - 00000000 ____D C:\Users\M\AppData\Local\Ewudom
2017-02-15 22:13 - 2017-02-15 22:13 - 00006018 _____ C:\Windows\System32\Tasks\Cerigharijeied Monitor
2017-02-09 19:55 - 2017-02-14 12:54 - 00000000 ____D C:\Users\M\Desktop\Praktikum
2017-02-06 12:48 - 2017-02-20 01:05 - 00000000 ____D C:\Users\M\Desktop\shm neu
2017-01-23 21:53 - 2017-01-23 21:55 - 00000000 ____D C:\Users\M\Desktop\Märklin CS 2 Update 4 1 2

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-02-21 13:51 - 2016-01-05 21:19 - 00000000 ____D C:\FRST
2017-02-21 13:36 - 2015-02-23 20:25 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-02-21 13:35 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-21 13:12 - 2015-03-20 16:02 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-02-21 12:59 - 2015-02-23 19:36 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-235318688-4269726762-198329688-1001
2017-02-21 12:49 - 2015-02-23 19:31 - 00000000 ____D C:\Users\M\AppData\Local\Google
2017-02-21 12:33 - 2015-02-23 19:28 - 00000000 ____D C:\Users\M
2017-02-21 12:30 - 2016-11-18 12:07 - 00000000 ____D C:\Users\M\AppData\LocalLow\Mozilla
2017-02-21 12:21 - 2016-01-06 00:18 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-02-21 12:12 - 2016-01-30 19:54 - 00005156 _____ C:\Users\M\Desktop\aktuellste erledigungen.odt
2017-02-21 12:11 - 2016-01-06 00:19 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-02-21 10:24 - 2016-10-07 11:08 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-21 10:24 - 2015-02-23 20:17 - 00002334 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-02-21 10:24 - 2015-02-23 19:29 - 00001785 _____ C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-02-21 10:17 - 2014-05-06 05:41 - 00765582 _____ C:\Windows\system32\perfh007.dat
2017-02-21 10:17 - 2014-05-06 05:41 - 00159366 _____ C:\Windows\system32\perfc007.dat
2017-02-21 10:17 - 2014-03-18 10:47 - 01776918 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-21 10:17 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf
2017-02-21 09:33 - 2015-12-08 21:49 - 00000000 ____D C:\Users\M\Desktop\Vertrag
2017-02-21 01:56 - 2015-02-25 00:55 - 00000000 ____D C:\Users\M\AppData\Roaming\Skype
2017-02-17 22:00 - 2015-04-12 18:56 - 00045056 _____ C:\Users\M\Desktop\konzertarchiv.xls
2017-02-16 11:08 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\L2Schemas
2017-02-16 11:07 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-02-15 23:25 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\Cursors
2017-02-15 22:11 - 2015-08-07 20:41 - 00000000 ____D C:\Program Files (x86)\WinAce
2017-02-15 09:12 - 2015-03-20 16:02 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-02-15 09:12 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-02-15 09:12 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-02-12 20:36 - 2016-04-12 20:36 - 00000000 ____D C:\Users\M\Knuddels-Stapp
2017-02-10 11:56 - 2015-12-24 21:40 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-02-10 11:56 - 2014-09-02 02:00 - 00000000 ____D C:\ProgramData\Skype
2017-02-01 12:41 - 2016-12-25 03:51 - 00000000 ____D C:\Users\M\Desktop\6a040bc1f0ba7e2e714a342db23d5905b6382f93-20161212-214503
2017-02-01 00:07 - 2016-11-18 00:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-02-01 00:07 - 2015-02-23 20:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-30 17:18 - 2016-03-07 09:58 - 00011829 _____ C:\Users\M\Desktop\Notenvergleichsrechner_neuePO__Schwerpunkt.xlsx
2017-01-30 16:06 - 2016-10-17 14:36 - 00000000 ____D C:\Users\M\Desktop\Uni

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-04-22 18:20 - 2015-04-22 18:20 - 0002533 _____ () C:\Users\M\AppData\Local\recently-used.xbel
2014-09-02 01:22 - 2014-09-02 01:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Einige Dateien in TEMP:
====================
2016-01-26 15:53 - 2007-03-03 20:19 - 0069632 ____R (Huawei Technologies Co., Ltd.) C:\Users\M\AppData\Local\Temp\DataCard_Setup.exe
2016-01-26 15:53 - 2007-01-08 20:08 - 0006144 ____R () C:\Users\M\AppData\Local\Temp\ResetDevice.exe

==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-02-17 09:53

==================== Ende von FRST.txt ============================
         
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 19-02-2017
durchgeführt von M (21-02-2017 13:54:24)
Gestartet von C:\Users\M\Desktop
Windows 8.1 (Update) (X64) (2015-02-23 18:28:35)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-235318688-4269726762-198329688-500 - Administrator - Disabled)
Gast (S-1-5-21-235318688-4269726762-198329688-501 - Limited - Disabled)
M (S-1-5-21-235318688-4269726762-198329688-1001 - Administrator - Enabled) => C:\Users\M

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.106.303.109 - ALPS ELECTRIC CO., LTD.)
AnyMP4 Free iPhone Data Recovery 7.3.28 (HKLM-x32\...\{2F81F350-B3A3-4f2a-A670-5BC3358AC1F6}_is1) (Version: 7.3.28 - AnyMP4 Studio)
Apple Application Support (32-Bit) (HKLM-x32\...\{D079CAAD-0C31-47A2-9AF5-A82F9CD9B221}) (Version: 5.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
DTS Sound (HKLM-x32\...\{1A938032-98EE-4C0F-9EAB-B3B5B64E28F8}) (Version: 1.01.8500 - DTS, Inc.)
Evernote v. 5.4 (HKLM-x32\...\{59071464-DAEE-11E3-9080-00163E98E7D0}) (Version: 5.4.0.3698 - Evernote Corp.)
Free Image Convert and Resize version 2.1.31.415 (HKLM-x32\...\Free Image Convert and Resize_is1) (Version: 2.1.31.415 - DVDVideoSoft Ltd.)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3643 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.0.1001 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) 4.0 (HKLM-x32\...\{001A29E3-D8DD-46C0-A7F9-B33E3DFA9338}) (Version: 17.0.1419.02 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{85b9d34f-7397-4e39-8600-07942ef6ca04}) (Version: 17.0.5 - Intel Corporation)
iTunes (HKLM\...\{81C96689-EA5B-4B7D-A04F-16326EC51BC2}) (Version: 12.5.4.42 - Apple Inc.)
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
Knuddels Standalone App (HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\Knuddels App ) (Version: "2015.12.6.0" - "Knuddels App")
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Manager (x32 Version: 4.1.4.27792 - 2015 pdfforge GmbH. All rights reserved) Hidden
Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4893.1002 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 51.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 51.0.1 (x86 de)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 51.0.1.6234 - Mozilla)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.34.26215 - pdfforge GmbH)
PDF Architect 4 Create Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDF Architect 4 Edit Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDF Architect 4 View Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.3.2 - pdfforge GmbH)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.315.0 - Tracker Software Products Ltd)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.31.423.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7285 - Realtek Semiconductor Corp.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
SecureW2 EAP Suite 1.1.3 for Windows (HKLM-x32\...\SecureW2 EAP Suite) (Version:  - )
Skype™ 7.32 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
Symbaloo (HKLM-x32\...\Symbaloo) (Version: 1.0.0 - Symbaloo Launcher by Toshiba Europe GmbH)
The Last Express (HKLM-x32\...\The Last Express) (Version: 1.0 - DotEmu)
TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.01.01 - Toshiba Corporation)
TOSHIBA Desktop Assist (HKLM\...\{C4CDCEF0-0A7A-4425-887C-33E39533D758}) (Version: 1.03.06.6403 - Toshiba Corporation)
TOSHIBA Display Utility (HKLM\...\{B9A67DC9-EAD3-4B87-B733-F2BA28F0D68E}) (Version: 1.2.4.0 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{94D2A899-0C34-4420-880E-AE337E635AB0}) (Version: 2.5.2.6401 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{1844CFE2-EBA3-490A-8A5E-9BFC646342FD}) (Version: 1.1.5.6402 - Toshiba Corporation)
TOSHIBA HDD Protection (HKLM\...\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.6.02.6403 - Toshiba Corporation)
TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.20 - TOSHIBA)
TOSHIBA Password Utility (HKLM\...\{CD4B9E2C-4295-4920-82F2-C87113822E32}) (Version: 3.03.04.02 - Toshiba Corporation)
TOSHIBA PC Health Monitor (HKLM\...\{A0D34C74-70AC-45E4-9735-A11DA95A5810}) (Version: 4.00.00.6402 - Toshiba Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.2.01.56006006 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{0DFA8761-7735-4DE8-A0EB-2286578DCFC6}) (Version: 2.6.14 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{E3FCDCBE-0A13-4F73-95C1-000A51CF1C8C}) (Version: 2.6.16.0 - Toshiba Corporation)
TOSHIBA Start Screen Option (HKLM\...\{06B71035-F19F-4F76-9875-FFCCD4FC3F83}) (Version: 1.00.05.6401 - Toshiba Corporation)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0036 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{4D57ED72-6B01-40BD-9CA9-012B8FC09CEB}) (Version: 2.0.5.32002 - Toshiba Corporation)
Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.5.1 - Toshiba Europe GmbH)
TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 6.2.4.5  - Toshiba Corporation)
WEB.DE MailCheck für Mozilla Firefox (HKLM-x32\...\1&1 Mail & Media GmbH Toolbar FF) (Version: 3.0.1.1739 - 1&1 Mail & Media GmbH)
WinAce Archiver (HKLM-x32\...\WinAce Archiver) (Version: 2.69 - e-merge GmbH)
WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
Wondershare Dr.Fone für iOS(Build 7.6.3.3) (HKLM-x32\...\{A26F8BBD-EC10-4bdc-8AD8-F146825A8A63}_is1) (Version: 7.6.3.3 - Wondershare Software Co.,Ltd.)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-235318688-4269726762-198329688-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\M\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {02EE2730-4C68-4CEE-9B12-E0834AAD9165} - System32\Tasks\Cerigharijeied Monitor => C:\Program Files (x86)\Gherkadomijly\prlisp.exe [2017-02-15] (Glarysoft Ltd)
Task: {1963AB86-3CCF-4921-A86E-0C95FDFC2C41} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2014-03-12] (TOSHIBA Corporation)
Task: {23A4E842-AE98-4C0B-8BD2-7BAF8F38E306} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {244CF0E9-1DC6-4B7D-A2DC-0EE33652C114} - System32\Tasks\dts_apo_service_task => C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_task.exe [2014-06-04] ()
Task: {474488AF-0A50-4378-B8CC-355200CAEF43} - System32\Tasks\{19F6666D-E5AA-4781-BD88-047860B4F25B} => pcalua.exe -a C:\Windows\76d5fa8fd3020718f7133f7301d20d13.exe
Task: {4F2206ED-6C81-45EC-99C7-C8D654E24A86} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-15] (Adobe Systems Incorporated)
Task: {A16E52D6-1AE2-47DE-A6B8-F659339F2216} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation)
Task: {AE0AB1BD-14CC-4495-B555-DF2F6C20A8EB} - System32\Tasks\{CA17C8C7-3267-4637-8D2D-7ABA72B5B2D0} => pcalua.exe -a "C:\Program Files (x86)\Ex1iV4c7ul\uninstall.exe"
Task: {B3129F6F-2266-4F3B-B5C6-2B1625CE58E2} - \Viqoght -> Keine Datei <==== ACHTUNG
Task: {C278E144-B7D0-4012-99F0-1BF832EA664D} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-12-24] (Toshiba Europe GmbH)
Task: {C5B33B85-8E06-43BC-B7BE-6DCD42477D3A} - System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel => C:\Program Files (x86)\BikaQRssReader\BikaQ.exe 
Task: {EE7CF08E-63FD-4CF2-91E1-3CF1FAE0F75B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation)
Task: {F6BD4D82-50B1-4C1C-857B-D6982B174360} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2014-04-03] (TOSHIBA Corporation)
Task: {F71F83E2-0465-4B27-93E1-6245D356AB57} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {F72DE3DC-C245-4A38-82A3-4AC879811071} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

Shortcut: C:\Users\M\Desktop\The Last Express Spielen (MS-DOS).lnk -> C:\Program Files (x86)\DotEmu\The Last Express\LastExpress.bat ()
Shortcut: C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DotEmu\The Last Express\The Last Express Spielen (MS-DOS).lnk -> C:\Program Files (x86)\DotEmu\The Last Express\LastExpress.bat ()

ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-07-15 09:17 - 2015-07-15 09:17 - 00022528 _____ () C:\Windows\System32\ssz2clm.dll
2016-09-01 17:12 - 2016-09-01 17:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-11-17 01:28 - 2016-11-17 01:28 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-25 00:17 - 2016-05-24 08:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2012-07-19 02:38 - 2012-07-19 02:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
2017-01-18 22:16 - 2016-10-28 01:56 - 00088128 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe
2014-06-11 23:06 - 2014-06-11 23:06 - 00021840 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2016-12-19 09:12 - 2016-12-19 09:12 - 01459712 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\ea494708300f305a0bfdb9484f99e357\Windows.UI.ni.dll
2016-12-19 09:12 - 2016-12-19 09:12 - 00521216 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Data\f68d203e69c1916668d932e1718f7b08\Windows.Data.ni.dll
2013-08-22 08:19 - 2013-08-22 07:54 - 00030208 _____ () C:\Windows\system32\WinMetadata\Windows.Foundation.winmd
2017-02-17 19:41 - 2017-02-17 07:20 - 00111104 _____ () c:\programdata\apple\apple application support\support.dll
2017-01-18 22:16 - 2015-11-16 10:10 - 00887808 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\Framework.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00013824 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\Utility.dll
2017-01-18 22:16 - 2015-06-24 05:53 - 02825216 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\IosDevice.dll
2017-01-18 22:16 - 2011-03-24 08:42 - 00334848 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtXml4.dll
2017-01-18 22:16 - 2011-03-24 08:56 - 07981056 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtGui4.dll
2017-01-18 22:16 - 2011-03-24 08:43 - 00934912 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtNetwork4.dll
2017-01-18 22:16 - 2011-03-24 08:42 - 02145792 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtCore4.dll
2017-01-18 22:16 - 2011-03-24 10:25 - 09843200 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtWebKit4.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00987136 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\libxml2.dll
2017-01-18 22:16 - 2011-03-24 09:06 - 00232960 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\phonon4.dll
2017-01-18 22:16 - 2011-03-24 09:06 - 02530816 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtXmlPatterns4.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00077824 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\zlib1.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00562072 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\SQLite3.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00025600 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qgif4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00027648 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qico4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00119808 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qjpeg4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00220672 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qmng4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00278528 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qtiff4.dll
2014-09-02 01:17 - 2013-12-09 23:26 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2017-02-20 13:42 - 2017-02-01 10:01 - 01870168 _____ () C:\Program Files (x86)\Standuck\Application\libglesv2.dll
2017-02-20 13:42 - 2017-02-01 10:01 - 00085848 _____ () C:\Program Files (x86)\Standuck\Application\libegl.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\amazon.de -> hxxps://amazon.de

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-235318688-4269726762-198329688-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Toshiba\standard.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{1AE20044-6F71-4787-B4F7-22D2C65F91D0}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{587D8541-F16D-4387-BC22-3B5001E958EF}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{0438D64D-1EE6-4219-A1E4-8F23A895627E}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{8890D3FA-A9D8-418A-9429-63F487CD7DF1}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{8F2A2D7E-8CB0-489A-92AC-EBCFF33CBFDE}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{8D0F9C4D-6C8D-4EA3-8EDD-594A919DFA18}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{0C6E0F95-E835-403C-B85B-D7F1D88E6194}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{A83F76AC-1574-4364-97CD-9DCF891C23FD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D1CBE926-0360-4C39-A7BB-D7F3FFEF0D99}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{63B0833A-DF61-4913-87D2-5C518357417B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{65FDEC65-2BDE-4249-B1D1-F927B1E55532}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{08FB6F16-DF51-457A-A5EA-B762C5D23C91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2C016DCA-D3CC-4EBB-A4A3-A8547F02E607}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{17E3355E-11F7-43C5-886E-44E3F2A9B8E8}] => (Allow) C:\Users\M\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [TCP Query User{1FEFDD73-2C91-4B7C-A0EC-2472218F259B}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{E4FB2BCE-031B-4943-8C30-6DB4D30FD37D}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{44DD637B-C478-4539-A783-31CD086B1199}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{728FCBDC-657D-4F11-A114-C8ECC059149E}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{C30C1B93-724C-4AB5-B803-72BED103BD9B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7FFBF84E-F820-43AA-9347-B25F5F562295}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A9375983-A0F8-43DE-B79F-B104D561C7A9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D622E66C-CBA9-4E2A-BDEF-C410CC75B8B9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A818F6FA-BACB-4911-AB9C-4D6AFF1250BD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{ED96F61E-CD4A-483B-83C3-59AA512122E8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D656335D-447D-4874-93DE-B2ACBF23C34B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{60542E9D-B3C4-46E5-8CBD-E17C468DF3A7}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LINE.exe
FirewallRules: [{3FFFBBF9-E5FB-4320-8C3B-DE58D40E45C2}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LINE.exe
FirewallRules: [{27CD1FC5-585B-4694-ACFB-6370F2BF1FD7}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LineUpdater.exe
FirewallRules: [{8DE37CC8-203E-4E72-A244-0E8B451E59F4}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LineUpdater.exe
FirewallRules: [{3F176F4F-A34E-4F02-9B48-7E47BE659802}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2ADFB605-0A1A-40C6-9613-A99910E000DC}] => (Allow) C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
FirewallRules: [{9E6CDF58-2665-4413-B1E4-7AE1768C4931}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe
FirewallRules: [{0CC126A6-6EA2-4B9E-80D4-DBA156A276A3}] => (Allow) C:\Program Files (x86)\Standuck\Application\chrome.exe

==================== Wiederherstellungspunkte =========================

29-01-2017 18:52:11 Geplanter Prüfpunkt
07-02-2017 22:32:12 Geplanter Prüfpunkt
17-02-2017 10:09:42 Geplanter Prüfpunkt
21-02-2017 12:11:56 Removed WinSnare
21-02-2017 12:13:32 Removed amuleC
21-02-2017 12:39:36 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: TOSHIBA Web Camera - HD
Description: USB-Videogerät
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (02/21/2017 12:14:16 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: notebook)
Description: Die Anwendung oder der Dienst "ed2k idle service" konnte nicht neu gestartet werden.

Error: (02/21/2017 10:09:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1218

Error: (02/21/2017 10:09:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1218

Error: (02/21/2017 10:09:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/21/2017 01:57:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8516

Error: (02/21/2017 01:57:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8516

Error: (02/21/2017 01:57:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/20/2017 03:28:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1312

Error: (02/20/2017 03:28:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1312

Error: (02/20/2017 03:28:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


Systemfehler:
=============
Error: (02/21/2017 01:35:29 PM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI4

Error: (02/21/2017 01:35:07 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll

Error: (02/21/2017 01:35:07 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll

Error: (02/21/2017 01:35:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "TMachInfo" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "TPCH Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Dynamic Application Loader Host Interface Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) ME Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "DTS APO Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "iPod-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i3-4005U CPU @ 1.70GHz
Prozentuale Nutzung des RAM: 37%
Installierter physikalischer RAM: 4013.33 MB
Verfügbarer physikalischer RAM: 2501.36 MB
Summe virtueller Speicher: 5421.33 MB
Verfügbarer virtueller Speicher: 3721.03 MB

==================== Laufwerke ================================

Drive c: (TI31360000B) (Fixed) (Total:454.94 GB) (Free:397.09 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Ende von Addition.txt ============================
         

Alt 21.02.2017, 14:09   #12
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\MountPoints2: {6fd17b76-c396-11e5-8296-303a64aa1620} - "E:\AutoRun.exe" 
ShellExecuteHooks: Kein Name - {586292BE-F1AE-11E6-81CC-64006A5CFC23} - C:\Users\M\AppData\Roaming\Thujghprikuk\Mervichjomus.dll -> Keine Datei
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-235318688-4269726762-198329688-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-235318688-4269726762-198329688-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
FF Homepage: Mozilla\Firefox\Profiles\9079h1at.default-1481549202673 -> http://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
FF SearchPlugin: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\searchplugins\startpageing123.xml [2017-02-21]
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
CHR DefaultSearchURL: ChromeDefaultData -> http://www.trotux.com/search/?q={searchTerms}&z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=sp
CHR DefaultSearchKeyword: ChromeDefaultData -> trotux
CHR Profile: C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-15] <==== ACHTUNG
StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
BootExecute: autocheck autochk * sdnclean64.exe
Task: {B3129F6F-2266-4F3B-B5C6-2B1625CE58E2} - \Viqoght -> Keine Datei <==== ACHTUNG
C:\Program Files (x86)\7ldp4n9k
C:\Program Files (x86)\Ex1iV4c7ul
C:\Program Files (x86)\Gherkadomijly
C:\Users\M\AppData\Local\Ewudom
C:\Windows\System32\Tasks\Cerigharijeied Monitor
C:\Program Files (x86)\Spybot - Search & Destroy 2
C:\ProgramData\Spybot - Search & Destroy
C:\Users\M\AppData\Roaming\Thujghprikuk
C:\Program Files\Common Files\AV\Spybot - Search and Destroy
cmd: type "C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles.ini"
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> http://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 21.02.2017, 15:29   #13
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Da ist der Fixlog:

Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 19-02-2017
durchgeführt von M (21-02-2017 15:18:10) Run:1
Gestartet von C:\Users\M\Desktop
Geladene Profile: M (Verfügbare Profile: M)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\MountPoints2: {6fd17b76-c396-11e5-8296-303a64aa1620} - "E:\AutoRun.exe" 
ShellExecuteHooks: Kein Name - {586292BE-F1AE-11E6-81CC-64006A5CFC23} - C:\Users\M\AppData\Roaming\Thujghprikuk\Mervichjomus.dll -> Keine Datei
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-235318688-4269726762-198329688-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-235318688-4269726762-198329688-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
FF Homepage: Mozilla\Firefox\Profiles\9079h1at.default-1481549202673 -> hxxp://www.startpageing123.com/?type=hp&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
FF SearchPlugin: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\searchplugins\startpageing123.xml [2017-02-21]
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}&z=a9f363f1d4acd5717a1541egdzeb6mbg6t9c5o4o4c&from=isr&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT&type=sp
CHR DefaultSearchKeyword: ChromeDefaultData -> trotux
CHR Profile: C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-15] <==== ACHTUNG
StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
BootExecute: autocheck autochk * sdnclean64.exe
Task: {B3129F6F-2266-4F3B-B5C6-2B1625CE58E2} - \Viqoght -> Keine Datei <==== ACHTUNG
C:\Program Files (x86)\7ldp4n9k
C:\Program Files (x86)\Ex1iV4c7ul
C:\Program Files (x86)\Gherkadomijly
C:\Users\M\AppData\Local\Ewudom
C:\Windows\System32\Tasks\Cerigharijeied Monitor
C:\Program Files (x86)\Spybot - Search & Destroy 2
C:\ProgramData\Spybot - Search & Destroy
C:\Users\M\AppData\Roaming\Thujghprikuk
C:\Program Files\Common Files\AV\Spybot - Search and Destroy
cmd: type "C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles.ini"
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.) -> hxxp://www.startpageing123.com/?type=sc&ts=1487669076&z=1025a29047b308bb6a381eag2z2b3mdq0qdtbecm9z&from=che0812&uid=TOSHIBAXMQ01ABF050_841TC0YXTXX841TC0YXT
emptytemp:
         
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotPostWindows10UpgradeReInstall => Wert erfolgreich entfernt
HKU\S-1-5-21-235318688-4269726762-198329688-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6fd17b76-c396-11e5-8296-303a64aa1620} => Schlüssel erfolgreich entfernt
HKCR\CLSID\{6fd17b76-c396-11e5-8296-303a64aa1620} => Schlüssel nicht gefunden. 
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{586292BE-F1AE-11E6-81CC-64006A5CFC23} => Wert erfolgreich entfernt
HKCR\CLSID\{586292BE-F1AE-11E6-81CC-64006A5CFC23} => Schlüssel nicht gefunden. 
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wert erfolgreich wiederhergestellt
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wert erfolgreich wiederhergestellt
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wert erfolgreich wiederhergestellt
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wert erfolgreich wiederhergestellt
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wert erfolgreich wiederhergestellt
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wert erfolgreich wiederhergestellt
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wert erfolgreich wiederhergestellt
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wert erfolgreich wiederhergestellt
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wert erfolgreich wiederhergestellt
HKU\S-1-5-21-235318688-4269726762-198329688-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wert erfolgreich wiederhergestellt
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wert erfolgreich wiederhergestellt
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Schlüssel erfolgreich entfernt
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Schlüssel nicht gefunden. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wert erfolgreich wiederhergestellt
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Schlüssel erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Schlüssel nicht gefunden. 
HKU\S-1-5-21-235318688-4269726762-198329688-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wert erfolgreich entfernt
HKU\S-1-5-21-235318688-4269726762-198329688-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Schlüssel erfolgreich entfernt
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Schlüssel nicht gefunden. 
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Wert erfolgreich wiederhergestellt
Firefox "homepage" erfolgreich entfernt
C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\searchplugins\startpageing123.xml => erfolgreich verschoben
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Wert erfolgreich wiederhergestellt
Chrome DefaultSearchURL => erfolgreich entfernt
Chrome DefaultSearchKeyword => erfolgreich entfernt
C:\Users\M\AppData\Local\Google\Chrome\User Data\ChromeDefaultData => erfolgreich verschoben
HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Wert erfolgreich wiederhergestellt
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Wert erfolgreich wiederhergestellt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B3129F6F-2266-4F3B-B5C6-2B1625CE58E2} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3129F6F-2266-4F3B-B5C6-2B1625CE58E2} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Viqoght => Schlüssel erfolgreich entfernt
C:\Program Files (x86)\7ldp4n9k => erfolgreich verschoben
C:\Program Files (x86)\Ex1iV4c7ul => erfolgreich verschoben
C:\Program Files (x86)\Gherkadomijly => erfolgreich verschoben
C:\Users\M\AppData\Local\Ewudom => erfolgreich verschoben
C:\Windows\System32\Tasks\Cerigharijeied Monitor => erfolgreich verschoben
C:\Program Files (x86)\Spybot - Search & Destroy 2 => erfolgreich verschoben
C:\ProgramData\Spybot - Search & Destroy => erfolgreich verschoben
C:\Users\M\AppData\Roaming\Thujghprikuk => erfolgreich verschoben
C:\Program Files\Common Files\AV\Spybot - Search and Destroy => erfolgreich verschoben

========= type "C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles.ini" =========

[General]
StartWithLastProfile=1

[Profile0]
Name=default-1481549202673
IsRelative=1
Path=Profiles/9079h1at.default-1481549202673


========= Ende von CMD: =========

C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Verknüpfung Eigenschaft erfolgreich entfernt.
C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Verknüpfung Eigenschaft erfolgreich entfernt.
C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Verknüpfung Eigenschaft erfolgreich entfernt.
C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => Verknüpfung Eigenschaft erfolgreich entfernt.
C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => Verknüpfung Eigenschaft erfolgreich entfernt.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Verknüpfung Eigenschaft erfolgreich entfernt.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 172957115 B
Java, Flash, Steam htmlcache => 84623 B
Windows/system/drivers => 16573380 B
Edge => 0 B
Chrome => 0 B
Firefox => 391810511 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 18394273 B
LocalService => 0 B
NetworkService => 599548 B
M => 155503832 B

RecycleBin => 0 B
EmptyTemp: => 728.9 MB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 15:20:16 ====
         
Vielen Dank!!
Hast mich gerettet. :-)

Alt 21.02.2017, 15:29   #14
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 21.02.2017, 17:10   #15
badkarmainc
 
Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Standard

Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe



Da sind die ganz frischen:

Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 19-02-2017
durchgeführt von M (Administrator) auf NOTEBOOK (21-02-2017 16:07:36)
Gestartet von C:\Users\M\Desktop
Geladene Profile: M (Verfügbare Profile: M)
Platform: Windows 8.1 (Update) (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1")
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidMonitorSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Don HO don.h@free.fr) C:\Program Files (x86)\notepad2\notepad2.exe
(pdfforge GmbH) C:\Program Files\PDF Architect 4\creator-ws.exe
(© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\System Setting\TssSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TDUSrv64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standuck\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672664 2014-06-30] (Realtek Semiconductor)
HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296008 2013-10-22] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-10-09] (TOSHIBA Corporation)
HKLM\...\Run: [ThpSrv] => C:\Windows\system32\thpsrv /logon
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [354144 2013-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [179288 2014-04-17] (TOSHIBA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [517536 2014-04-07] (TOSHIBA)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595480 2016-03-20] (Oracle Corporation)
HKLM-x32\...\Run: [AnyMP4 Free iPhone Data RecoveryAppService] => C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe [88128 2016-10-28] ()
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{01A3239A-66E6-4A37-95D3-D88991033A6A}: [DhcpNameServer] 192.168.1.251 8.8.8.8
Tcpip\..\Interfaces\{76A32D41-DACA-45F5-872C-C9D20FEE27CB}: [DhcpNameServer] 192.168.2.1
ManualProxies: 

Internet Explorer:
==================
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation)
BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-08-05] (pdfforge GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-04-04] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-05-14] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-04] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673 [2017-02-21]
FF Extension: (Adblock Plus) - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-12]
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\9079h1at.default-1481549202673\features\{302110b3-b1bf-4951-82d4-8122016fa5b1}\disableSHA1rollout@mozilla.org.xpi [2017-02-17]
FF ProfilePath: C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673 [2017-02-21]
FF Homepage: Firefox\Firefox\Profiles\9079h1at.default-1481549202673 -> about:home
FF Extension: (SimilarWeb) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\@DA3566E2-F709-11E5-8E87-A604BC8E7F8B.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (FF Adr) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (Deutsch (DE) Language Pack) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\langpack-de@firefox.mozilla.org.xpi [2017-02-17] [ist nicht signiert]
FF Extension: (Adblock Plus) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-12]
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\features\{302110b3-b1bf-4951-82d4-8122016fa5b1}\disableSHA1rollout@mozilla.org.xpi [2017-02-17]
FF SearchPlugin: C:\Users\M\AppData\Roaming\Firefox\Firefox\Profiles\9079h1at.default-1481549202673\searchplugins\searchinme.xml [2017-02-17]
FF Extension: (UITBAutoInstaller) - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{edd7fc99-d65c-4979-85c2-ddeed30c50c7} [2016-11-18] [ist nicht signiert]
FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension
FF Extension: (PDF Architect 4 Creator) - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension [2016-09-19] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-15] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-15] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-25] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: PDF Architect 4 -> C:\Program Files (x86)\PDF Architect 4\np-previewer.dll [2016-08-05] (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-235318688-4269726762-198329688-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2015-09-08] (Tracker Software Products (Canada) Ltd.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2017-02-15]

Chrome: 
=======
CHR DefaultProfile: ChromeDefaultData

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 ApHidMonitorService; C:\Program Files\Apoint2K\HidMonitorSvc.exe [87384 2014-07-12] (Alps Electric Co., Ltd.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 Apple_Cfg; C:\ProgramData\Apple\Apple Application Support\Support.dll [111104 2017-02-17] () [Datei ist nicht signiert]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042032 2016-12-13] (Microsoft Corporation)
R3 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [21840 2014-06-11] ()
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [315352 2014-06-17] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-12-09] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-09] (Intel Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-05-30] ()
R2 Ntp2NetSvc; C:\Program Files (x86)\notepad2\notepad2.exe [2340864 2017-02-16] (Don HO don.h@free.fr) [Datei ist nicht signiert]
S2 Ntp2UpSvc; C:\Program Files (x86)\Common Files\ntp2UpSvc\notepad2.exe [2340864 2017-02-16] (Don HO don.h@free.fr) [Datei ist nicht signiert]
S3 PDF Architect 4; C:\Program Files\PDF Architect 4\ws.exe [2438880 2016-08-05] (pdfforge GmbH)
S3 PDF Architect 4 CrashHandler; C:\Program Files\PDF Architect 4\crash-handler-ws.exe [1038048 2016-08-05] (pdfforge GmbH)
R2 PDF Architect 4 Creator; C:\Program Files\PDF Architect 4\creator-ws.exe [851168 2016-08-05] (pdfforge GmbH)
R2 PDF Architect 4 Manager; C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe [972056 2016-05-18] (© pdfforge GmbH.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116088 2013-12-24] (Toshiba Europe GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe [437392 2016-10-10] (Wondershare)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\Dr.Fone for iOS\DriverInstall.exe [97792 2016-11-30] (Wondershare) [Datei ist nicht signiert]
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-05-30] (Intel® Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [191944 2014-05-09] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-02-21] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-09] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3446240 2014-06-18] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [27136 2014-03-24] (Windows (R) Win 7 DDK provider)
S1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-09-08] (Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 ZTEusbmdm6k; \SystemRoot\system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; \SystemRoot\system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; \SystemRoot\system32\DRIVERS\ZTEusbser6k.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-02-21 15:18 - 2017-02-21 15:20 - 00015792 _____ C:\Users\M\Desktop\Fixlog.txt
2017-02-21 13:51 - 2017-02-21 13:51 - 00000000 ____D C:\Users\M\Desktop\FRST-OlderVersion
2017-02-21 13:35 - 2017-02-21 15:26 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-02-21 12:42 - 2017-02-21 12:42 - 00000921 _____ C:\Users\M\Desktop\JRT.txt
2017-02-21 12:38 - 2017-02-21 12:38 - 01663040 _____ (Malwarebytes) C:\Users\M\Desktop\JRT.exe
2017-02-21 12:36 - 2017-02-21 12:36 - 00006660 _____ C:\Users\M\Desktop\AdwCleaner[C0].txt
2017-02-21 12:28 - 2017-02-21 13:32 - 00000000 ____D C:\AdwCleaner
2017-02-21 12:27 - 2017-02-21 12:27 - 04015056 _____ C:\Users\M\Desktop\AdwCleaner_6.043.exe
2017-02-21 12:07 - 2017-02-21 12:07 - 00001211 _____ C:\Users\M\Desktop\mbam5.txt
2017-02-21 12:06 - 2017-02-21 12:06 - 00001908 _____ C:\Users\M\Desktop\mbam4.txt
2017-02-21 12:05 - 2017-02-21 12:05 - 00036716 _____ C:\Users\M\Desktop\mbam3.txt
2017-02-21 12:04 - 2017-02-21 12:04 - 00003226 _____ C:\Users\M\Desktop\mbam1.txt
2017-02-21 12:04 - 2017-02-21 12:04 - 00000449 _____ C:\Users\M\Desktop\mbam2.txt
2017-02-20 13:42 - 2017-02-20 13:42 - 00000000 ____D C:\Program Files (x86)\Standuck
2017-02-17 21:05 - 2017-02-17 21:04 - 00235836 _____ C:\Users\M\Desktop\TDSSKiller.3.1.0.12_17.02.2017_21.02.29_log.txt
2017-02-17 21:02 - 2017-02-17 21:06 - 00235924 _____ C:\TDSSKiller.3.1.0.12_17.02.2017_21.02.29_log.txt
2017-02-17 21:02 - 2017-02-17 21:02 - 04747704 _____ (AO Kaspersky Lab) C:\Users\M\Desktop\tdsskiller.exe
2017-02-17 20:58 - 2017-02-21 13:55 - 00033247 _____ C:\Users\M\Desktop\Addition.txt
2017-02-17 20:57 - 2017-02-21 16:08 - 00019184 _____ C:\Users\M\Desktop\FRST.txt
2017-02-17 20:56 - 2017-02-21 13:51 - 02422784 _____ (Farbar) C:\Users\M\Desktop\FRST64.exe
2017-02-17 19:42 - 2017-02-17 19:42 - 00000000 ____D C:\Users\M\AppData\Local\Firefox
2017-02-17 19:41 - 2017-02-20 13:42 - 00000219 _____ C:\Users\Public\Desktop\Google Chrome.url
2017-02-17 19:41 - 2017-02-17 19:41 - 00000000 ____D C:\Users\M\AppData\Roaming\Firefox
2017-02-17 19:41 - 2017-02-17 19:41 - 00000000 ____D C:\Users\M\AppData\Local\Standuck
2017-02-16 12:20 - 2017-02-16 12:20 - 00000000 ____D C:\Users\M\AppData\Local\DOSBox
2017-02-16 12:14 - 2017-02-21 12:14 - 00000000 ____D C:\Program Files (x86)\BikaQRssReader
2017-02-16 12:14 - 2017-02-16 12:14 - 00003218 _____ C:\Windows\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-02-16 12:14 - 2017-02-16 12:14 - 00000000 ____D C:\Program Files (x86)\notepad2
2017-02-15 23:27 - 2017-02-21 12:33 - 00000008 __RSH C:\Users\M\ntuser.pol
2017-02-15 22:35 - 2017-02-15 22:35 - 00003080 _____ C:\Windows\System32\Tasks\{19F6666D-E5AA-4781-BD88-047860B4F25B}
2017-02-15 22:32 - 2017-02-15 22:32 - 00003084 _____ C:\Windows\System32\Tasks\{CA17C8C7-3267-4637-8D2D-7ABA72B5B2D0}
2017-02-15 22:17 - 2017-02-21 12:33 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-02-15 22:14 - 2017-02-15 22:34 - 00000000 ____D C:\Windows\system32\SSL
2017-02-09 19:55 - 2017-02-14 12:54 - 00000000 ____D C:\Users\M\Desktop\Praktikum
2017-02-06 12:48 - 2017-02-20 01:05 - 00000000 ____D C:\Users\M\Desktop\shm neu
2017-01-23 21:53 - 2017-01-23 21:55 - 00000000 ____D C:\Users\M\Desktop\Märklin CS 2 Update 4 1 2

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-02-21 16:07 - 2016-01-05 21:19 - 00000000 ____D C:\FRST
2017-02-21 15:36 - 2015-02-23 19:36 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-235318688-4269726762-198329688-1001
2017-02-21 15:26 - 2015-02-23 20:25 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-02-21 15:26 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-21 15:18 - 2016-10-07 11:08 - 00002134 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-21 15:18 - 2016-01-06 00:24 - 00000000 ____D C:\Program Files\Common Files\AV
2017-02-21 15:18 - 2015-02-23 19:29 - 00001185 _____ C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-02-21 15:16 - 2014-05-06 05:41 - 00765582 _____ C:\Windows\system32\perfh007.dat
2017-02-21 15:16 - 2014-05-06 05:41 - 00159366 _____ C:\Windows\system32\perfc007.dat
2017-02-21 15:16 - 2014-03-18 10:47 - 01776918 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-21 15:16 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf
2017-02-21 14:12 - 2015-03-20 16:02 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-02-21 12:49 - 2015-02-23 19:31 - 00000000 ____D C:\Users\M\AppData\Local\Google
2017-02-21 12:33 - 2015-02-23 19:28 - 00000000 ____D C:\Users\M
2017-02-21 12:30 - 2016-11-18 12:07 - 00000000 ____D C:\Users\M\AppData\LocalLow\Mozilla
2017-02-21 12:12 - 2016-01-30 19:54 - 00005156 _____ C:\Users\M\Desktop\aktuellste erledigungen.odt
2017-02-21 10:24 - 2015-02-23 20:17 - 00002334 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-02-21 09:33 - 2015-12-08 21:49 - 00000000 ____D C:\Users\M\Desktop\Vertrag
2017-02-21 01:56 - 2015-02-25 00:55 - 00000000 ____D C:\Users\M\AppData\Roaming\Skype
2017-02-17 22:00 - 2015-04-12 18:56 - 00045056 _____ C:\Users\M\Desktop\konzertarchiv.xls
2017-02-16 11:08 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\L2Schemas
2017-02-16 11:07 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-02-15 23:25 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\Cursors
2017-02-15 22:11 - 2015-08-07 20:41 - 00000000 ____D C:\Program Files (x86)\WinAce
2017-02-15 09:12 - 2015-03-20 16:02 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-02-15 09:12 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-02-15 09:12 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-02-12 20:36 - 2016-04-12 20:36 - 00000000 ____D C:\Users\M\Knuddels-Stapp
2017-02-10 11:56 - 2015-12-24 21:40 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-02-10 11:56 - 2014-09-02 02:00 - 00000000 ____D C:\ProgramData\Skype
2017-02-01 12:41 - 2016-12-25 03:51 - 00000000 ____D C:\Users\M\Desktop\6a040bc1f0ba7e2e714a342db23d5905b6382f93-20161212-214503
2017-02-01 00:07 - 2016-11-18 00:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-02-01 00:07 - 2015-02-23 20:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-30 17:18 - 2016-03-07 09:58 - 00011829 _____ C:\Users\M\Desktop\Notenvergleichsrechner_neuePO__Schwerpunkt.xlsx
2017-01-30 16:06 - 2016-10-17 14:36 - 00000000 ____D C:\Users\M\Desktop\Uni

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-04-22 18:20 - 2015-04-22 18:20 - 0002533 _____ () C:\Users\M\AppData\Local\recently-used.xbel
2014-09-02 01:22 - 2014-09-02 01:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-02-17 09:53

==================== Ende von FRST.txt ============================
         
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 19-02-2017
durchgeführt von M (21-02-2017 16:08:39)
Gestartet von C:\Users\M\Desktop
Windows 8.1 (Update) (X64) (2015-02-23 18:28:35)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-235318688-4269726762-198329688-500 - Administrator - Disabled)
Gast (S-1-5-21-235318688-4269726762-198329688-501 - Limited - Disabled)
M (S-1-5-21-235318688-4269726762-198329688-1001 - Administrator - Enabled) => C:\Users\M

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.106.303.109 - ALPS ELECTRIC CO., LTD.)
AnyMP4 Free iPhone Data Recovery 7.3.28 (HKLM-x32\...\{2F81F350-B3A3-4f2a-A670-5BC3358AC1F6}_is1) (Version: 7.3.28 - AnyMP4 Studio)
Apple Application Support (32-Bit) (HKLM-x32\...\{D079CAAD-0C31-47A2-9AF5-A82F9CD9B221}) (Version: 5.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
DTS Sound (HKLM-x32\...\{1A938032-98EE-4C0F-9EAB-B3B5B64E28F8}) (Version: 1.01.8500 - DTS, Inc.)
Evernote v. 5.4 (HKLM-x32\...\{59071464-DAEE-11E3-9080-00163E98E7D0}) (Version: 5.4.0.3698 - Evernote Corp.)
Free Image Convert and Resize version 2.1.31.415 (HKLM-x32\...\Free Image Convert and Resize_is1) (Version: 2.1.31.415 - DVDVideoSoft Ltd.)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3643 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.0.1001 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) 4.0 (HKLM-x32\...\{001A29E3-D8DD-46C0-A7F9-B33E3DFA9338}) (Version: 17.0.1419.02 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{85b9d34f-7397-4e39-8600-07942ef6ca04}) (Version: 17.0.5 - Intel Corporation)
iTunes (HKLM\...\{81C96689-EA5B-4B7D-A04F-16326EC51BC2}) (Version: 12.5.4.42 - Apple Inc.)
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
Knuddels Standalone App (HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\Knuddels App ) (Version: "2015.12.6.0" - "Knuddels App")
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Manager (x32 Version: 4.1.4.27792 - 2015 pdfforge GmbH. All rights reserved) Hidden
Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4893.1002 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 51.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 51.0.1 (x86 de)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 51.0.1.6234 - Mozilla)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4893.1002 - Microsoft Corporation) Hidden
PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.34.26215 - pdfforge GmbH)
PDF Architect 4 Create Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDF Architect 4 Edit Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDF Architect 4 View Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.3.2 - pdfforge GmbH)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.315.0 - Tracker Software Products Ltd)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.31.423.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7285 - Realtek Semiconductor Corp.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
SecureW2 EAP Suite 1.1.3 for Windows (HKLM-x32\...\SecureW2 EAP Suite) (Version:  - )
Skype™ 7.32 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
Symbaloo (HKLM-x32\...\Symbaloo) (Version: 1.0.0 - Symbaloo Launcher by Toshiba Europe GmbH)
The Last Express (HKLM-x32\...\The Last Express) (Version: 1.0 - DotEmu)
TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.01.01 - Toshiba Corporation)
TOSHIBA Desktop Assist (HKLM\...\{C4CDCEF0-0A7A-4425-887C-33E39533D758}) (Version: 1.03.06.6403 - Toshiba Corporation)
TOSHIBA Display Utility (HKLM\...\{B9A67DC9-EAD3-4B87-B733-F2BA28F0D68E}) (Version: 1.2.4.0 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{94D2A899-0C34-4420-880E-AE337E635AB0}) (Version: 2.5.2.6401 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{1844CFE2-EBA3-490A-8A5E-9BFC646342FD}) (Version: 1.1.5.6402 - Toshiba Corporation)
TOSHIBA HDD Protection (HKLM\...\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.6.02.6403 - Toshiba Corporation)
TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.20 - TOSHIBA)
TOSHIBA Password Utility (HKLM\...\{CD4B9E2C-4295-4920-82F2-C87113822E32}) (Version: 3.03.04.02 - Toshiba Corporation)
TOSHIBA PC Health Monitor (HKLM\...\{A0D34C74-70AC-45E4-9735-A11DA95A5810}) (Version: 4.00.00.6402 - Toshiba Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.2.01.56006006 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{0DFA8761-7735-4DE8-A0EB-2286578DCFC6}) (Version: 2.6.14 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{E3FCDCBE-0A13-4F73-95C1-000A51CF1C8C}) (Version: 2.6.16.0 - Toshiba Corporation)
TOSHIBA Start Screen Option (HKLM\...\{06B71035-F19F-4F76-9875-FFCCD4FC3F83}) (Version: 1.00.05.6401 - Toshiba Corporation)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0036 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{4D57ED72-6B01-40BD-9CA9-012B8FC09CEB}) (Version: 2.0.5.32002 - Toshiba Corporation)
Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.5.1 - Toshiba Europe GmbH)
TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 6.2.4.5  - Toshiba Corporation)
WEB.DE MailCheck für Mozilla Firefox (HKLM-x32\...\1&1 Mail & Media GmbH Toolbar FF) (Version: 3.0.1.1739 - 1&1 Mail & Media GmbH)
WinAce Archiver (HKLM-x32\...\WinAce Archiver) (Version: 2.69 - e-merge GmbH)
WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
Wondershare Dr.Fone für iOS(Build 7.6.3.3) (HKLM-x32\...\{A26F8BBD-EC10-4bdc-8AD8-F146825A8A63}_is1) (Version: 7.6.3.3 - Wondershare Software Co.,Ltd.)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-235318688-4269726762-198329688-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\M\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {02EE2730-4C68-4CEE-9B12-E0834AAD9165} - \Cerigharijeied Monitor -> Keine Datei <==== ACHTUNG
Task: {1963AB86-3CCF-4921-A86E-0C95FDFC2C41} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2014-03-12] (TOSHIBA Corporation)
Task: {23A4E842-AE98-4C0B-8BD2-7BAF8F38E306} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {244CF0E9-1DC6-4B7D-A2DC-0EE33652C114} - System32\Tasks\dts_apo_service_task => C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_task.exe [2014-06-04] ()
Task: {474488AF-0A50-4378-B8CC-355200CAEF43} - System32\Tasks\{19F6666D-E5AA-4781-BD88-047860B4F25B} => pcalua.exe -a C:\Windows\76d5fa8fd3020718f7133f7301d20d13.exe
Task: {4F2206ED-6C81-45EC-99C7-C8D654E24A86} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-15] (Adobe Systems Incorporated)
Task: {A16E52D6-1AE2-47DE-A6B8-F659339F2216} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation)
Task: {AE0AB1BD-14CC-4495-B555-DF2F6C20A8EB} - System32\Tasks\{CA17C8C7-3267-4637-8D2D-7ABA72B5B2D0} => pcalua.exe -a "C:\Program Files (x86)\Ex1iV4c7ul\uninstall.exe"
Task: {C278E144-B7D0-4012-99F0-1BF832EA664D} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-12-24] (Toshiba Europe GmbH)
Task: {C5B33B85-8E06-43BC-B7BE-6DCD42477D3A} - System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel => C:\Program Files (x86)\BikaQRssReader\BikaQ.exe 
Task: {EE7CF08E-63FD-4CF2-91E1-3CF1FAE0F75B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation)
Task: {F6BD4D82-50B1-4C1C-857B-D6982B174360} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2014-04-03] (TOSHIBA Corporation)
Task: {F71F83E2-0465-4B27-93E1-6245D356AB57} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {F72DE3DC-C245-4A38-82A3-4AC879811071} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

Shortcut: C:\Users\M\Desktop\The Last Express Spielen (MS-DOS).lnk -> C:\Program Files (x86)\DotEmu\The Last Express\LastExpress.bat ()
Shortcut: C:\Users\M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DotEmu\The Last Express\The Last Express Spielen (MS-DOS).lnk -> C:\Program Files (x86)\DotEmu\The Last Express\LastExpress.bat ()
Shortcut: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\M\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Standuck\Application\chrome.exe (Google Inc.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-07-15 09:17 - 2015-07-15 09:17 - 00022528 _____ () C:\Windows\System32\ssz2clm.dll
2016-09-01 17:12 - 2016-09-01 17:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-11-17 01:28 - 2016-11-17 01:28 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-25 00:17 - 2016-05-24 08:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2012-07-19 02:38 - 2012-07-19 02:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
2017-01-18 22:16 - 2016-10-28 01:56 - 00088128 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\AppService.exe
2014-06-11 23:06 - 2014-06-11 23:06 - 00021840 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2016-12-19 09:12 - 2016-12-19 09:12 - 01459712 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\ea494708300f305a0bfdb9484f99e357\Windows.UI.ni.dll
2016-12-19 09:12 - 2016-12-19 09:12 - 00521216 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Data\f68d203e69c1916668d932e1718f7b08\Windows.Data.ni.dll
2013-08-22 08:19 - 2013-08-22 07:54 - 00030208 _____ () C:\Windows\system32\WinMetadata\Windows.Foundation.winmd
2017-02-17 19:41 - 2017-02-17 07:20 - 00111104 _____ () c:\programdata\apple\apple application support\support.dll
2017-01-18 22:16 - 2015-11-16 10:10 - 00887808 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\Framework.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00013824 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\Utility.dll
2017-01-18 22:16 - 2015-06-24 05:53 - 02825216 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\IosDevice.dll
2017-01-18 22:16 - 2011-03-24 08:42 - 00334848 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtXml4.dll
2017-01-18 22:16 - 2011-03-24 08:56 - 07981056 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtGui4.dll
2017-01-18 22:16 - 2011-03-24 08:43 - 00934912 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtNetwork4.dll
2017-01-18 22:16 - 2011-03-24 08:42 - 02145792 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtCore4.dll
2017-01-18 22:16 - 2011-03-24 10:25 - 09843200 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtWebKit4.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00987136 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\libxml2.dll
2017-01-18 22:16 - 2011-03-24 09:06 - 00232960 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\phonon4.dll
2017-01-18 22:16 - 2011-03-24 09:06 - 02530816 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\QtXmlPatterns4.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00077824 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\zlib1.dll
2017-01-18 22:16 - 2015-11-24 06:18 - 00562072 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\SQLite3.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00025600 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qgif4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00027648 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qico4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00119808 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qjpeg4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00220672 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qmng4.dll
2017-01-18 22:16 - 2011-03-24 10:37 - 00278528 _____ () C:\Program Files (x86)\AnyMP4 Studio\AnyMP4 Free iPhone Data Recovery\imageformats\qtiff4.dll
2017-02-20 13:42 - 2017-02-01 10:01 - 01870168 _____ () C:\Program Files (x86)\Standuck\Application\libglesv2.dll
2017-02-20 13:42 - 2017-02-01 10:01 - 00085848 _____ () C:\Program Files (x86)\Standuck\Application\libegl.dll
2014-09-02 01:17 - 2013-12-09 23:26 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-235318688-4269726762-198329688-1001\...\amazon.de -> hxxps://amazon.de

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-235318688-4269726762-198329688-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Toshiba\standard.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{1AE20044-6F71-4787-B4F7-22D2C65F91D0}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{587D8541-F16D-4387-BC22-3B5001E958EF}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{0438D64D-1EE6-4219-A1E4-8F23A895627E}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{8890D3FA-A9D8-418A-9429-63F487CD7DF1}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{8F2A2D7E-8CB0-489A-92AC-EBCFF33CBFDE}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{8D0F9C4D-6C8D-4EA3-8EDD-594A919DFA18}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{0C6E0F95-E835-403C-B85B-D7F1D88E6194}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{A83F76AC-1574-4364-97CD-9DCF891C23FD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D1CBE926-0360-4C39-A7BB-D7F3FFEF0D99}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{63B0833A-DF61-4913-87D2-5C518357417B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{65FDEC65-2BDE-4249-B1D1-F927B1E55532}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{08FB6F16-DF51-457A-A5EA-B762C5D23C91}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2C016DCA-D3CC-4EBB-A4A3-A8547F02E607}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{17E3355E-11F7-43C5-886E-44E3F2A9B8E8}] => (Allow) C:\Users\M\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [TCP Query User{1FEFDD73-2C91-4B7C-A0EC-2472218F259B}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{E4FB2BCE-031B-4943-8C30-6DB4D30FD37D}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{44DD637B-C478-4539-A783-31CD086B1199}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{728FCBDC-657D-4F11-A114-C8ECC059149E}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{C30C1B93-724C-4AB5-B803-72BED103BD9B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7FFBF84E-F820-43AA-9347-B25F5F562295}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A9375983-A0F8-43DE-B79F-B104D561C7A9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D622E66C-CBA9-4E2A-BDEF-C410CC75B8B9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A818F6FA-BACB-4911-AB9C-4D6AFF1250BD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{ED96F61E-CD4A-483B-83C3-59AA512122E8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D656335D-447D-4874-93DE-B2ACBF23C34B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{60542E9D-B3C4-46E5-8CBD-E17C468DF3A7}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LINE.exe
FirewallRules: [{3FFFBBF9-E5FB-4320-8C3B-DE58D40E45C2}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LINE.exe
FirewallRules: [{27CD1FC5-585B-4694-ACFB-6370F2BF1FD7}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LineUpdater.exe
FirewallRules: [{8DE37CC8-203E-4E72-A244-0E8B451E59F4}] => (Allow) C:\Users\M\AppData\Local\LINE\bin\4.11.2.1298\LineUpdater.exe
FirewallRules: [{3F176F4F-A34E-4F02-9B48-7E47BE659802}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2ADFB605-0A1A-40C6-9613-A99910E000DC}] => (Allow) C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
FirewallRules: [{9E6CDF58-2665-4413-B1E4-7AE1768C4931}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe
FirewallRules: [{0CC126A6-6EA2-4B9E-80D4-DBA156A276A3}] => (Allow) C:\Program Files (x86)\Standuck\Application\chrome.exe

==================== Wiederherstellungspunkte =========================

29-01-2017 18:52:11 Geplanter Prüfpunkt
07-02-2017 22:32:12 Geplanter Prüfpunkt
17-02-2017 10:09:42 Geplanter Prüfpunkt
21-02-2017 12:11:56 Removed WinSnare
21-02-2017 12:13:32 Removed amuleC
21-02-2017 12:39:36 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: TOSHIBA Web Camera - HD
Description: USB-Videogerät
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (02/21/2017 12:14:16 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: notebook)
Description: Die Anwendung oder der Dienst "ed2k idle service" konnte nicht neu gestartet werden.

Error: (02/21/2017 10:09:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1218

Error: (02/21/2017 10:09:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1218

Error: (02/21/2017 10:09:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/21/2017 01:57:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8516

Error: (02/21/2017 01:57:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8516

Error: (02/21/2017 01:57:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/20/2017 03:28:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1312

Error: (02/20/2017 03:28:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1312

Error: (02/20/2017 03:28:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


Systemfehler:
=============
Error: (02/21/2017 03:25:41 PM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI4

Error: (02/21/2017 01:35:29 PM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI4

Error: (02/21/2017 01:35:07 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll

Error: (02/21/2017 01:35:07 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll

Error: (02/21/2017 01:35:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "TMachInfo" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "TPCH Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Dynamic Application Loader Host Interface Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) ME Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/21/2017 01:32:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "DTS APO Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i3-4005U CPU @ 1.70GHz
Prozentuale Nutzung des RAM: 37%
Installierter physikalischer RAM: 4013.33 MB
Verfügbarer physikalischer RAM: 2492.29 MB
Summe virtueller Speicher: 5421.33 MB
Verfügbarer virtueller Speicher: 3649.48 MB

==================== Laufwerke ================================

Drive c: (TI31360000B) (Fixed) (Total:454.94 GB) (Free:397.8 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Ende von Addition.txt ============================
         
Ich wollte mal kurz ergänzen:
Seitdem eben ja Firefox eliminiert wurde, gehe ich derzeit über Google Chrome rein. (sonst nicht)
Dort kommt seit gerade totrux als Startseite.
Da ich den Namen hier beim querlesen mal aufgeschnappt habe, dachte ich mir, es wäre sicher gut das zu erwähnen.

Danke!

Antwort

Themen zu Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe
bildschirm, bonjour, browser, browser langsam, cpu, defender, desktop, explorer, firefox, flash player, homepage, hängen, langsam, malware, mozilla, popup, prozesse, realtek, registry, scan, schwarzes bild, services.exe, software, system, totrux, udp, usb, windows, winsnare



Ähnliche Themen: Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe


  1. Extrem langsam gewordener Rechner,verbunden mit Browser-PopUp bei Start des Rechners?
    Log-Analyse und Auswertung - 17.10.2015 (3)
  2. Browser extrem langsam, stürtzt manchmal kurz ab, Rechner lahm
    Log-Analyse und Auswertung - 24.04.2015 (15)
  3. Rechner vollig langsam ,Browser Firefox öffnet ständig Werbung
    Plagegeister aller Art und deren Bekämpfung - 30.10.2014 (11)
  4. Rechner langsam und Browser seltsam
    Log-Analyse und Auswertung - 04.01.2014 (8)
  5. Infizierter Rechner / Browser laden langsam
    Log-Analyse und Auswertung - 30.07.2013 (9)
  6. Rechner vermutl. infiziert. Tastatureingaben sind anders als ich sie eingebe.
    Log-Analyse und Auswertung - 09.07.2011 (7)
  7. Trojaner auf dem Rechner?! Brauche dringend Hilfe!
    Plagegeister aller Art und deren Bekämpfung - 25.08.2010 (82)
  8. Rechner Extrem Langsam, auch nach Adaware Test, brauche dringend logfile Auswertung!
    Log-Analyse und Auswertung - 10.03.2010 (4)
  9. Tojaner auf dem Rechner, brauche dringend Hilfe !!!
    Plagegeister aller Art und deren Bekämpfung - 08.02.2010 (12)
  10. Rechner / Browser startet langsam. Spyware?
    Log-Analyse und Auswertung - 27.03.2009 (11)
  11. Rechner hat sich bis vor kurzem immer von selbst neugestartet, jetzt: Browser langsam
    Plagegeister aller Art und deren Bekämpfung - 26.09.2008 (1)
  12. Trojaner / Viren auf dem Rechner? - Brauche Hilfe!
    Mülltonne - 04.09.2008 (0)
  13. rechner sehr langsam nach wurmattacke - brauche hilfe bitte
    Log-Analyse und Auswertung - 18.01.2008 (1)
  14. Brauche dringend Hilfe...Rechner is zu langsam und hängst sich ständig auf......
    Log-Analyse und Auswertung - 24.01.2007 (1)
  15. Brauche Hilfe beim Problem mit TIB Browser
    Log-Analyse und Auswertung - 31.03.2005 (1)
  16. Hilfe Rechner voll Spyware!! Brauche dringend HILFE!!!
    Log-Analyse und Auswertung - 03.03.2005 (1)
  17. Browser-HIJACK - Brauche dringend Hilfe
    Log-Analyse und Auswertung - 16.01.2005 (7)

Zum Thema Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe - Hi zusammen, Irgendwie spinnt mein Laptop, seitdem ich mir ein Spiel (Freeware) runterladen wollte. Mir ist schon aufgefallen, dass da viel Malware mitkam, ich habe dann versucht das zu beheben: - Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe...
Archiv
Du betrachtest: Rechner langsam, Browser superlangsam, vermutl Trotux, brauche Hilfe auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.