Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Windows 7: Trojanerfund durch Microsoft Security,extrem langsamer PC, Deaktivierung der Firewall (https://www.trojaner-board.de/160497-windows-7-trojanerfund-microsoft-security-extrem-langsamer-pc-deaktivierung-firewall.html)

Anchovi 07.11.2014 15:51

Windows 7: Trojanerfund durch Microsoft Security,extrem langsamer PC, Deaktivierung der Firewall
 
Hallo liebes Hilfeteam,

ich habe mit meinem Windows 7-PC folgendes Problem:

- Extrem langsam, Lüfter entsprechend laut
- Microsoft Security Essentials schlägt an, lässt sich nicht mehr richtig starten und dokumentiert Viren/Trojanerbefall
- Die systeminterne Windows-Firewall lässt sich nicht mehr starten, es ist lediglich ein rotes Kreuz zu erkennen
-Gelegentlich "ploppt" eine Download/Installationsaufforderung ("installer_adobe_Flash_player_German.exe" vom Herausgeber: "download2v.freesoftstore.com") auf, die ich selbstverständlich immer weggeklickt habe, aber hartnäckig immer wieder aufploppt.

Logfiles:

1. defogger: keine logfile ausgegeben

2. FRST

Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-11-2014
Ran by Hendrik (administrator) on HENDRIK-PC on 06-11-2014 18:31:15
Running from C:\Users\Hendrik\DOWNLOADS
Loaded Profile: Hendrik (Available profiles: Hendrik & DefaultAppPool)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
() C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
() C:\Program Files (x86)\Join Air\UIExec.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-09] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2255360 2011-06-10] (ASUS)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UIExec] => C:\Program Files (x86)\Join Air\UIExec.exe [132608 2009-08-31] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [Wiuhyfreyquwh] => "C:\Users\Hendrik\AppData\Roaming\Urmytiyf\ywwego.exe"
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\MountPoints2: {988fa727-f2ae-11e1-aed6-ac7289631a0e} - F:\LaunchU3.exe -a
HKU\S-1-5-18\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideSCAHealth] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Plugin HKCU: @torrentstream.net/tsplugin,version=1.0.6 -> C:\Users\Hendrik\AppData\Roaming\TorrentStream\player\npts.dll (The Torrent Stream and VideoLAN and Delft University of Technology)
FF Plugin ProgramFiles/Appdata: C:\Users\Hendrik\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018\Extensions\gmailnoads@mywebber.com.xpi [2014-10-11]
FF Extension: Adblock Plus - C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-11]
FF HKCU\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\Hendrik\AppData\Roaming\TorrentStream\extensions\firefox\magicplayer@torrentstream.org
FF Extension: TS Magic Player - C:\Users\Hendrik\AppData\Roaming\TorrentStream\extensions\firefox\magicplayer@torrentstream.org [2014-04-26]

Chrome:
=======
CHR HomePage: Default -> chrome://newtab
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.671\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll ()
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Users\Hendrik\AppData\Roaming\Mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.670.1) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U67) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Torrent Stream P2P Multimedia Plug-in) - C:\Users\Hendrik\AppData\Roaming\TorrentStream\player\npts.dll (The Torrent Stream and VideoLAN and Delft University of Technology)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll No File
CHR Profile: C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-16]
CHR Extension: (Google Drive) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-16]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04]
CHR Extension: (YouTube) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-16]
CHR Extension: (Google-Suche) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-16]
CHR Extension: (Google Wallet) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-16]
CHR Extension: (TS Magic Player) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ochbjojkpcmlfeagbaahkofepalngihg [2014-04-26]
CHR Extension: (Google Mail) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-16]
CHR HKCU\...\Chrome\Extension: [ochbjojkpcmlfeagbaahkofepalngihg] - C:\Users\Hendrik\AppData\Roaming\TorrentStream\extensions\chrome\magicplayer.crx [2014-04-26]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-11] (Seiko Epson Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com)
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [241664 2009-08-31] () [File not signed]
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S2 lxdu_device; C:\Windows\system32\lxducoms.exe -service [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 assd; C:\Windows\System32\Drivers\assd.sys [27264 2010-04-28] (ASUS Corporation)
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-11] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2013-12-08] (Windows (R) Win 7 DDK provider)
S2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam64.sys [1071032 2012-04-15] (Windows (R) Win 7 DDK provider)
S1 brdzkxcp; \??\C:\Windows\system32\drivers\brdzkxcp.sys [X]
S1 gucgznbc; \??\C:\Windows\system32\drivers\gucgznbc.sys [X]
S1 inqltdso; \??\C:\Windows\system32\drivers\inqltdso.sys [X]
S1 laaolckg; \??\C:\Windows\system32\drivers\laaolckg.sys [X]
S1 lxukkwfx; \??\C:\Windows\system32\drivers\lxukkwfx.sys [X]
S1 vngoazpn; \??\C:\Windows\system32\drivers\vngoazpn.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-06 18:31 - 2014-11-06 18:32 - 00025055 _____ () C:\Users\Hendrik\Downloads\FRST.txt
2014-11-06 18:30 - 2014-11-06 18:31 - 00000000 ____D () C:\FRST
2014-11-06 18:30 - 2014-11-06 18:30 - 02114560 _____ (Farbar) C:\Users\Hendrik\Downloads\FRST64.exe
2014-11-06 18:28 - 2014-11-06 18:29 - 00000476 _____ () C:\Users\Hendrik\Downloads\defogger_disable.log
2014-11-06 18:28 - 2014-11-06 18:28 - 00000000 _____ () C:\Users\Hendrik\defogger_reenable
2014-11-06 18:27 - 2014-11-06 18:27 - 00050477 _____ () C:\Users\Hendrik\Downloads\Defogger.exe
2014-11-06 18:25 - 2014-11-06 18:26 - 00002265 _____ () C:\Users\Hendrik\Desktop\mbam.txt
2014-11-06 16:25 - 2014-11-06 18:20 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-06 16:19 - 2014-11-06 16:19 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-06 16:19 - 2014-11-06 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-06 16:18 - 2014-11-06 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-06 16:18 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-06 16:18 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-06 16:18 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-06 16:16 - 2014-11-06 16:17 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025(2).exe
2014-11-06 16:00 - 2014-11-06 16:00 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025(1).exe
2014-11-06 15:43 - 2014-11-06 15:43 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-06 12:02 - 2014-11-06 12:06 - 121435896 _____ (Microsoft Corporation) C:\Users\Hendrik\Downloads\msert(2).exe
2014-11-05 17:18 - 2014-11-05 17:18 - 01125200 _____ () C:\Users\Hendrik\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe
2014-11-05 16:42 - 2014-11-05 16:42 - 00896504 _____ (Microsoft Corporation) C:\Users\Hendrik\Downloads\mssstool64.exe
2014-11-04 22:47 - 2014-11-05 15:52 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Urmytiyf
2014-11-04 21:50 - 2014-11-06 13:44 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-11-04 17:44 - 2014-11-06 15:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2014-11-04 17:44 - 2014-11-06 15:30 - 00000000 ____D () C:\Program Files\Wondershare
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ___HD () C:\Program Files (x86)\Dr.Fone_Temp
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Wondershare
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ____D () C:\ProgramData\Wondershare
2014-11-04 17:43 - 2014-11-04 17:43 - 00000000 ____D () C:\Users\Public\Documents\Wondershare
2014-11-04 17:16 - 2014-11-04 17:16 - 00000000 ____D () C:\Users\Hendrik\Desktop\Media
2014-11-04 17:07 - 2014-11-05 16:09 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Reincubate
2014-11-04 10:42 - 2014-11-04 10:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\WindSolutions
2014-11-04 10:42 - 2014-11-04 10:46 - 00000000 ____D () C:\ProgramData\WindSolutions
2014-11-04 00:08 - 2014-11-04 00:08 - 00000000 ____D () C:\Users\Hendrik\.android
2014-11-03 23:53 - 2014-11-04 00:05 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-11-02 00:42 - 2014-11-02 00:43 - 107254738 _____ () C:\Users\Hendrik\Documents\clip0918.avi
2014-11-01 12:32 - 2014-11-01 12:32 - 04078544 _____ (iMobie Inc. ) C:\Users\Hendrik\Downloads\phonerescue-setup.exe
2014-10-30 22:34 - 2014-10-30 22:36 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (21)
2014-10-29 15:01 - 2014-10-29 15:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-10-29 14:06 - 2014-10-29 14:06 - 00002192 _____ () C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2014-10-29 14:05 - 2014-10-29 14:05 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2014-10-27 17:43 - 2014-10-27 17:43 - 00002170 _____ () C:\Users\Hendrik\.recently-used.xbel
2014-10-27 00:15 - 2014-10-27 00:16 - 118253116 _____ () C:\Users\Hendrik\Documents\clip0917.avi
2014-10-26 23:50 - 2014-10-26 23:52 - 195895978 _____ () C:\Users\Hendrik\Documents\clip0916.avi
2014-10-25 23:09 - 2014-10-25 23:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2014-10-24 23:21 - 2014-10-24 23:21 - 25336014 _____ () C:\Users\Hendrik\Documents\clip0915.avi
2014-10-24 23:13 - 2014-10-24 23:13 - 06658282 _____ () C:\Users\Hendrik\Documents\clip0914.avi
2014-10-21 15:36 - 2014-10-21 15:36 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-21 15:36 - 2014-10-21 15:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\Program Files\iTunes
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-21 15:35 - 2014-10-21 15:35 - 00000000 ____D () C:\Program Files\iPod
2014-10-21 13:47 - 2014-10-21 13:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\pdfforge
2014-10-20 11:42 - 2014-10-20 11:42 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Oracle
2014-10-20 11:24 - 2014-10-20 11:23 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-10-20 11:23 - 2014-10-20 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-20 00:40 - 2014-10-20 01:10 - 2638644386 _____ () C:\Users\Hendrik\Documents\clip0913.avi
2014-10-19 18:19 - 2014-10-19 18:19 - 00613203 _____ () C:\Users\Hendrik\Downloads\Plain Cloud_1.0(1).zip
2014-10-19 17:50 - 2014-10-19 17:50 - 00613203 _____ () C:\Users\Hendrik\Downloads\Plain Cloud_1.0.zip
2014-10-19 17:18 - 2014-10-19 17:18 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Python
2014-10-19 17:18 - 2014-10-19 17:18 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\ActiveState
2014-10-19 15:38 - 2014-11-04 23:21 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Apple Inc
2014-10-15 21:36 - 2014-10-15 21:36 - 00144627 _____ () C:\Users\Hendrik\Downloads\NB SB.aac
2014-10-15 10:55 - 2014-10-15 10:55 - 00000000 ____H () C:\Users\Hendrik\Desktop\~WRL0254.tmp
2014-10-15 10:53 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 10:53 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-15 10:53 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2014-10-15 10:53 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 10:52 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-10-15 10:52 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-10-15 10:52 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-10-15 10:52 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-15 10:52 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-10-15 10:52 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-15 10:52 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-15 10:52 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2014-10-15 10:52 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-10-15 10:52 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-15 10:52 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-15 10:52 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-15 10:52 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-15 10:52 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-15 10:52 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-15 10:52 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-15 10:52 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2014-10-15 10:52 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2014-10-15 10:52 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-10-15 10:52 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-10-15 10:52 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-10-15 10:52 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-15 10:52 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-15 10:51 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-15 10:51 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-15 10:50 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-15 10:50 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 10:50 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-15 10:50 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-15 10:50 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-15 10:50 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-15 10:50 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 10:50 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 10:50 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 10:50 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 10:50 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-15 10:50 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 10:50 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 10:50 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 10:50 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 10:50 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 10:50 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 10:50 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 10:50 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 10:50 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 10:50 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 10:50 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-15 10:50 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 10:50 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 10:50 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 10:50 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-15 10:50 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 10:50 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 10:50 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-15 10:50 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 10:50 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-15 10:50 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 10:50 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-15 10:50 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-15 10:50 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-15 10:50 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-15 10:50 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-15 10:50 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-15 10:50 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 10:50 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 10:50 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 10:50 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 10:50 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 10:50 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-15 10:50 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-15 10:50 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-15 10:50 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 10:50 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-15 10:50 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 10:50 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-15 10:50 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-15 10:49 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-15 10:49 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-15 10:48 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 10:48 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-15 10:48 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 10:48 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 10:48 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-15 10:48 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-15 10:48 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-15 10:48 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 10:48 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-15 10:46 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 10:46 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-15 10:46 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 10:46 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-14 14:29 - 2014-10-14 14:38 - 00000000 ____D () C:\Users\Hendrik\Downloads\x
2014-10-11 10:42 - 2010-08-30 07:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-10-11 10:40 - 2014-10-11 10:43 - 00000000 ____D () C:\AdwCleaner

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-06 18:33 - 2013-01-28 17:23 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{40B698CB-62BD-4EE1-A271-0656D24B8F85}
2014-11-06 18:28 - 2012-02-20 09:58 - 00000000 ____D () C:\Users\Hendrik
2014-11-06 18:12 - 2013-10-16 10:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-06 17:57 - 2009-07-14 05:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 17:57 - 2009-07-14 05:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 17:50 - 2012-04-12 17:11 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-06 17:47 - 2013-12-08 21:30 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-11-06 17:47 - 2012-02-20 09:59 - 00000000 ___HD () C:\ASUS.DAT
2014-11-06 17:46 - 2012-04-12 17:11 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-06 17:44 - 2014-02-15 20:18 - 00165498 _____ () C:\Windows\PFRO.log
2014-11-06 17:44 - 2014-01-03 20:01 - 00040211 _____ () C:\Windows\setupact.log
2014-11-06 17:44 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-06 15:38 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-06 15:31 - 2014-08-15 17:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iMobie
2014-11-06 15:31 - 2014-08-15 16:39 - 00000000 ____D () C:\Program Files (x86)\iMobie
2014-11-06 13:48 - 2011-11-18 22:11 - 01957125 _____ () C:\Windows\WindowsUpdate.log
2014-11-05 15:55 - 2012-02-20 10:27 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Apple Computer
2014-11-04 17:58 - 2014-01-28 14:11 - 00000000 ____D () C:\Users\Hendrik\Desktop\sortieren
2014-11-04 17:07 - 2012-02-20 10:15 - 00000000 ____D () C:\Users\Hendrik\Desktop\Programme
2014-11-04 10:10 - 2013-03-18 12:04 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\uTorrent
2014-11-04 08:41 - 2011-11-18 22:28 - 00001839 _____ () C:\Windows\system32\ServiceFilter.ini
2014-11-03 20:16 - 2013-10-19 22:00 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\vlc
2014-11-03 14:08 - 2012-02-20 09:59 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-11-02 11:26 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-01 12:33 - 2014-08-15 16:39 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\iMobie
2014-11-01 12:33 - 2014-08-15 16:39 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\iMobie_Inc
2014-10-30 12:25 - 2012-04-27 08:56 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-29 15:13 - 2012-02-20 11:41 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Skype
2014-10-29 15:02 - 2012-02-20 11:41 - 00000000 ____D () C:\ProgramData\Skype
2014-10-29 15:01 - 2014-08-11 20:27 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-10-29 13:48 - 2014-08-20 17:26 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Adobe
2014-10-29 13:47 - 2013-10-16 10:01 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-29 13:47 - 2013-10-16 10:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-29 13:47 - 2013-10-16 10:01 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-27 17:46 - 2012-04-12 15:48 - 00000000 ____D () C:\Users\Hendrik\.gimp-2.6
2014-10-27 12:07 - 2011-02-19 10:08 - 00745910 _____ () C:\Windows\system32\perfh007.dat
2014-10-27 12:07 - 2011-02-19 10:08 - 00162816 _____ () C:\Windows\system32\perfc007.dat
2014-10-27 12:07 - 2009-07-14 06:13 - 01732678 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-25 23:11 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-25 23:09 - 2012-03-14 13:46 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-10-24 11:45 - 2012-04-12 17:11 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-24 11:45 - 2012-04-12 17:11 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-22 11:07 - 2014-06-10 18:44 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\7-PDFSplitMerge
2014-10-22 08:02 - 2012-11-20 10:20 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-10-22 07:59 - 2013-11-20 16:47 - 00000000 ____D () C:\ProgramData\MAGIX
2014-10-21 19:03 - 2012-02-20 10:27 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Apple Computer
2014-10-21 15:35 - 2014-09-10 23:19 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-20 11:24 - 2013-10-19 11:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-20 11:23 - 2012-02-22 16:25 - 00000000 ____D () C:\Program Files (x86)\Java
2014-10-20 10:54 - 2009-07-14 05:45 - 00518968 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-19 17:25 - 2012-02-20 09:59 - 00160264 _____ () C:\Users\Hendrik\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-19 15:56 - 2013-12-17 15:19 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\C24C21DE-B653-4E21-81BE-22AF552FB2ED.aplzod
2014-10-19 15:53 - 2012-03-17 13:25 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Microsoft Help
2014-10-17 17:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-10-16 00:16 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-15 22:29 - 2013-01-09 22:52 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-10-15 22:29 - 2012-02-22 13:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\DVDVideoSoft
2014-10-15 22:27 - 2012-02-22 13:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-10-15 17:33 - 2014-05-06 23:24 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-10-15 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-10-15 17:01 - 2012-03-17 13:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 16:47 - 2013-08-19 02:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 16:38 - 2012-10-20 09:57 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Windows Live
2014-10-15 16:19 - 2012-02-21 18:34 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-11 11:26 - 2011-04-09 19:54 - 00000000 ____D () C:\Windows\he
2014-10-11 10:55 - 2013-12-05 22:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-10 22:23 - 2014-04-22 15:27 - 00000000 ____D () C:\ProgramData\Origin

Some content of TEMP:
====================
C:\Users\Hendrik\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfi5xfy.dll
C:\Users\Hendrik\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Hendrik\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Hendrik\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Hendrik\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Hendrik\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Hendrik\AppData\Local\Temp\Quarantine.exe
C:\Users\Hendrik\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Hendrik\AppData\Local\Temp\vlc-2.1.5-win32.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-06 14:23

==================== End Of Log ============================

3. Addition

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-11-2014
Ran by Hendrik at 2014-11-06 18:34:03
Running from C:\Users\Hendrik\DOWNLOADS
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.34309 - BitTorrent Inc.)
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-PDF Split & Merge Version 2.1.0 (Build 128) (HKLM-x32\...\7-PDF Split & Merge_is1) (Version: 7-PDF Split & Merge - Version 2.1.0 (Build 128) - 7-PDF, Germany - Thorsten Hodes)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
ANNO 1503 GOLD (HKLM-x32\...\{DB833EF9-A198-49BE-970A-BD46F30BFBB4}) (Version: 1.05.00 - )
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo StartUp Tuner 2.00 (HKLM-x32\...\Ashampoo StartUp Tuner 2_is1) (Version: 2.0.0 - ashampoo GmbH & Co. KG)
ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.14 - ASUS)
ASUS FancyStart (HKLM-x32\...\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}) (Version: 1.1.1 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.22 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.0.6 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS)
ASUS Secure Delete (HKLM\...\{761C6783-D3BC-48AB-8E7C-61CE918A8436}) (Version: 1.00.0007 - ASUS)
ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0033 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.84.161 - eCareme Technologies, Inc.)
Asus_PSeries_Screensaver (HKLM-x32\...\Asus_PSeries_Screensaver) (Version: 1.0.0001 - ASUS)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.4.617 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS)
Audacity 2.0.4 (HKLM-x32\...\Audacity_is1) (Version: 2.0.4 - Audacity Team)
Audiodope 0.24 (HKLM-x32\...\Audiodope_is1) (Version:  - Audiodope Team)
AVI Splitter (HKLM-x32\...\AVI Splitter_is1) (Version:  - )
Benutzerhandbuch - Grundlagen EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Bog) (Version:  - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (x32 Version: 13.50.854.0 - Logitech) Hidden
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5067 - CDBurnerXP)
Cinergy T USB XE V6.11.23.01 (HKLM-x32\...\Cinergy T USB XE) (Version: 6.11.23.01 - )
Cinergy T-Stick V8.08.18.01 (HKLM-x32\...\Cinergy T-Stick) (Version: 8.08.18.01 - )
ClipGrab 3.4.7 (HKLM-x32\...\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version:  - Philipp Schmieder Medien)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.)
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.6.1622 - CyberLink Corp.)
CyberLink PowerRecover (Version: 5.6.1622 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Debut Video Capture Software (HKLM-x32\...\Debut) (Version:  - NCH Software)
Diercke Globus Online (HKLM-x32\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.29 - Dropbox, Inc.)
Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.1.1 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print 2 (HKLM-x32\...\{30E01116-5666-4807-8EF1-D80E9FF16717}) (Version: 2.3.2.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM-x32\...\{BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}) (Version: 3.01.0000 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON XP-302 303 305 306 Series Printer Uninstall (HKLM\...\EPSON XP-302 303 305 306 Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
ETDWare PS/2-X64 8.0.5.3_WHQL (HKLM\...\Elantech) (Version: 8.0.5.3 - ELAN Microelectronic Corp.)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.9 - ASUS)
Filedrop version 1.1.4 (HKLM-x32\...\{3A309583-1B4A-4C90-85EA-124EB8DB331A}_is1) (Version: 1.1.4 - Filedrop)
Folienviewer2 (HKLM-x32\...\Folienviewer2) (Version: 1.01 - Imagon GmbH)
FormatFactory 3.2.1.0 (HKLM-x32\...\FormatFactory) (Version: 3.2.1.0 - Free Time)
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
Free YouTube to iPod Converter version 3.10.37.1212 (HKLM-x32\...\Free YouTube to iPod Converter_is1) (Version: 3.10.37.1212 - DVDVideoSoft Ltd.)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
HyperCam 2 (HKLM\...\HyperCam 2) (Version: 2.25.01 - Hyperionics Technology LLC)
iCloud (HKLM\...\{6096C0CC-7E19-4355-87F0-627EC5AA146D}) (Version: 4.0.3.56 - Apple Inc.)
iExplorer 2.2.1.3 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant, LLC)
iFunbox (v2.7.2386.747), iFunbox DevTeam (HKLM-x32\...\iFunbox_is1) (Version: v2.7.2386.747 - )
Image Resizer for Windows (64 bit) (Version: 3.0.4442.6002 - Brice Lambson) Hidden
Image Resizer for Windows (HKLM-x32\...\{9dfff2f7-5cd7-4fd4-9b75-7d53b042d94b}) (Version: 3.0.4442.6002 - Brice Lambson)
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{A0E106D2-4815-4B7A-BAA7-7E21B530CFB4}) (Version: 1.1.0.0157 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{006B5C65-3938-4246-B182-994A7E415EDE}) (Version: 1.1.0.0537 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH)
Join Air (HKLM-x32\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.1 - ZTE Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.31 - Logitech Inc.)
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
ManyCam 3.0.80 (remove only) (HKLM-x32\...\ManyCam) (Version: 3.0.80 - ManyCam LLC)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 32.0.3 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0.3 (x86 de)) (Version: 32.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Netzwerkhandbuch EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Netg) (Version:  - )
Notebook Interactive Viewer (HKLM-x32\...\{24BA79B5-53F9-475C-9D49-EC4BDE8B09CF}) (Version: 9.5.126.5 - SMART Technologies Inc.)
Nuance PDF Reader (HKLM-x32\...\{B480904D-F73F-4673-B034-8A5F492C9184}) (Version: 6.00.0041 - Nuance Communications, Inc.)
Opera Stable 18.0.1284.63 (HKLM-x32\...\Opera 18.0.1284.63) (Version: 18.0.1284.63 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.0.11.77 - Electronic Arts, Inc.)
PC-WELT-TuneUpSuite 1.0 (HKLM-x32\...\{36B01464-5050-4492-BAA3-46E62551EEAB}_is1) (Version:  - IDG Magazine Media GmbH)
PDF Split And Merge Basic (HKLM\...\{C91B24F6-1629-11E2-B696-21676188709B}) (Version: 2.2.2 - Andrea Vacondio)
Politik transparent (HKLM-x32\...\{B8591E60-8A0E-43F9-A82D-7EAE368A8BBC}) (Version: 1.00.0000 - Bildungshaus Schulbuchverlage Westermann Schroedel Diesterweg Schöningh Winklers GmbH)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.8 - ASUS)
Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
Software Updater (HKLM-x32\...\{A3B308B9-BE96-4334-816F-3D82B19A7DE2}) (Version: 4.1.7 - SEIKO EPSON CORPORATION)
Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
SopCast 3.8.3 (HKLM-x32\...\SopCast) (Version: 3.8.3 - www.sopcast.com)
Splashtop Software Updater (HKLM-x32\...\Splashtop Software Updater) (Version: 1.5.6.14 - Splashtop Inc.)
Splashtop Streamer (HKLM-x32\...\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.4.0.1 - Splashtop Inc.)
Spotify (HKCU\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com)
StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version:  - )
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
syncables desktop SE (HKLM-x32\...\{341697D8-9923-445E-B42A-529E5A99CB7A}) (Version: 5.5.746.11492 - syncables)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.24482 - TeamViewer)
Torrent Stream 1.0.6 (HKCU\...\TorrentStream) (Version: 1.0.6 - Torrent Stream)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.1 - ASUS)
Wireless Console 3 (HKLM-x32\...\{8150221C-8F7E-4997-AD4E-AFDEE7F4B410}) (Version: 3.0.21 - ASUS)
Yahoo! Detect (HKLM-x32\...\YTdetect) (Version:  - )
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0DCC669E-305D-4490-A22A-DACF8ACDA332} - System32\Tasks\{2538AA23-41A8-46F9-A9B8-1600A487A194} => E:\Launch.exe
Task: {43C8FC67-FE7A-400D-B176-A7BA5670AAC8} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduamon.exe
Task: {4BD9B6A0-BF11-446B-8759-2ED56E4BF34D} - System32\Tasks\{86C211C5-1FA9-4FB3-AC24-7E9E7FB67409} => E:\Install.exe
Task: {4FEAFF65-7EAC-4AB6-B595-81CE32212A34} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-12] (Google Inc.)
Task: {5379F8D5-FD26-45BD-9BA2-807F743E5F9D} - \Security Center Update - 2964684536 No Task File <==== ATTENTION
Task: {5BCFBD93-1AF7-436D-A7B4-93DA8DB9ACE8} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS)
Task: {74A6AE27-5B37-403C-90E2-F82BD52EFD7C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {823355DA-B080-4C2E-8E9F-D7DF9F5AE4EF} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {845121B3-024E-43FD-9DDA-813E16664F90} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: {88A197AC-BAAA-491A-BB7B-74B5901A114B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-29] (Adobe Systems Incorporated)
Task: {A117D9B8-4DD6-41F5-8DF6-9B965A73444A} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-08-31] (ASUSTeK Computer Inc.)
Task: {B55C227F-8780-44C4-A6F6-D10F1B3D2A77} - System32\Tasks\ASUS Secure Delete => C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe [2011-01-24] ()
Task: {C1376A8C-6329-4AB1-A91F-09D10534B1E5} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS)
Task: {C5263A43-5637-4F45-A703-1D997E5E657A} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-05-30] (ASUS)
Task: {C86F9397-3A3B-42CA-8E8D-09C4EC4F269B} - System32\Tasks\{5E595A7B-3F2A-4C14-AE3D-C733F9915D0E} => E:\Launch.exe
Task: {DDEE7187-E174-496B-9B6A-6A10147BE6C6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-12] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2011-01-24 19:55 - 2011-01-24 19:55 - 00541696 _____ () C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
2014-03-11 15:29 - 2009-08-31 10:43 - 00241664 _____ () C:\Program Files (x86)\Join Air\AssistantServices.exe
2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-09-06 04:29 - 2011-05-24 01:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-03-11 15:29 - 2009-08-31 10:43 - 00132608 _____ () C:\Program Files (x86)\Join Air\UIExec.exe
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-08-31 15:33 - 2011-08-31 15:33 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
2011-05-30 22:48 - 2011-05-30 22:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2011-06-10 19:49 - 2011-06-10 19:49 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2014-09-25 08:48 - 2014-09-25 08:48 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:3E7393FC
AlternateDataStreams: C:\ProgramData\Temp:D20FFA63

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: EEventManager => "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Hendrik\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: UIExec => "C:\Program Files (x86)\Join Air\UIExec.exe"
MSCONFIG\startupreg: Wisdom-soft AutoScreenRecorder 3.1 Free => 0

========================= Accounts: ==========================

Administrator (S-1-5-21-1724138799-3868663929-1243099489-500 - Administrator - Disabled)
Gast (S-1-5-21-1724138799-3868663929-1243099489-501 - Limited - Disabled)
Hendrik (S-1-5-21-1724138799-3868663929-1243099489-1000 - Administrator - Enabled) => C:\Users\Hendrik
HomeGroupUser$ (S-1-5-21-1724138799-3868663929-1243099489-1002 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/06/2014 04:53:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: EXPLORER.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24
Ausnahmecode: 0xc0000022
Fehleroffset: 0x00000000000cd7e8
ID des fehlerhaften Prozesses: 0x214
Startzeit der fehlerhaften Anwendung: 0xEXPLORER.EXE0
Pfad der fehlerhaften Anwendung: EXPLORER.EXE1
Pfad des fehlerhaften Moduls: EXPLORER.EXE2
Berichtskennung: EXPLORER.EXE3

Error: (11/06/2014 03:37:56 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\WINDOWS\SYSTEM32\MSIEXEC.EXE /V; Beschreibung = Removed BlueStacks Notification Center; Fehler = 0x80042306).

Error: (11/06/2014 03:37:51 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 0000000000000064,0x0053c06c,00000000003F2D40,0,00000000003F1D30,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/06/2014 03:37:33 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 0000000000000190,0x0053c06c,00000000003F2D40,0,00000000003F1D30,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/06/2014 03:37:14 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 000000000000017C,0x0053c06c,00000000003F2D40,0,00000000003F1D30,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/06/2014 03:36:57 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 0000000000000190,0x0053c06c,00000000003F2D40,0,00000000003F1D30,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/06/2014 03:36:40 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 000000000000017C,0x0053c06c,00000000003F2D40,0,00000000003F1D30,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/06/2014 03:36:12 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\WINDOWS\SYSTEM32\MSIEXEC.EXE /V; Beschreibung = Removed BlueStacks Notification Center; Fehler = 0x80042306).

Error: (11/06/2014 03:36:07 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 00000000000000FC,0x0053c06c,00000000003F2D40,0,00000000003F1D30,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/06/2014 03:35:50 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 0000000000000140,0x0053c06c,00000000003F2540,0,00000000003F1530,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider


System errors:
=============
Error: (11/06/2014 05:49:34 PM) (Source: Microsoft Antimalware) (EventID: 1119) (User: )
Description: Beim Anwenden von Aktionen auf Schadsoftware und potenziell unerwünschte Software wurde von %Virus:DOS/Rovnix.gen!A60 ein schwerwiegender Fehler festgestellt.

Weitere Informationen finden Sie hier:
%Virus:DOS/Rovnix.gen!A603

        Name: Virus:DOS/Rovnix.gen!A

        ID: 2147686707

        Schweregrad: %Virus:DOS/Rovnix.gen!A600

        Kategorie: %Virus:DOS/Rovnix.gen!A602

        Pfad: 4.6.0305.02

        Ursprung der Erkennung: 4.6.0305.04

        Typ der Erkennung: 4.6.0305.08

        Quelle der Erkennung: %Virus:DOS/Rovnix.gen!A608

        Benutzer: {D2B051E0-345D-492E-8366-647F2922A7DE}9

        Prozessname: %Virus:DOS/Rovnix.gen!A609

        Aktion: {D2B051E0-345D-492E-8366-647F2922A7DE}1

        Aktionsstatus:  {D2B051E0-345D-492E-8366-647F2922A7DE}8

        Fehlercode: {D2B051E0-345D-492E-8366-647F2922A7DE}3

        Fehlerbeschreibung: {D2B051E0-345D-492E-8366-647F2922A7DE}4

        Signaturversion: 2014-11-06T16:47:13.150Z1

        Modulversion: 2014-11-06T16:47:13.150Z2

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.

Error: (11/06/2014 05:49:33 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk0\DR0 gefunden.


Microsoft Office Sessions:
=========================
Error: (08/26/2014 04:52:59 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6700.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1784 seconds with 960 seconds of active time.  This session ended with a crash.

Error: (04/06/2014 05:25:31 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (02/18/2014 07:27:55 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 64 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (05/16/2013 04:00:44 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1650 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (09/25/2012 03:45:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 904 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2013-02-26 10:55:36.047
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-26 10:55:35.965
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz
Percentage of memory in use: 83%
Total physical RAM: 4008.17 MB
Available physical RAM: 654.53 MB
Total Pagefile: 8016.34 MB
Available Pagefile: 3936 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:13.68 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:153.85 GB) (Free:22.95 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=119.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=153.9 GB) - (Type=07 NTFS)

==================== End Of Log ============================


Anchovi 07.11.2014 15:51

4. gmer

Code:

GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-11-06 18:55:33
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.01.0 298,09GB
Running: Gmer-19357.exe; Driver: C:\Users\Hendrik\AppData\Local\Temp\uxdiifob.sys


---- User code sections - GMER 2.1 ----

.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                                            0000000077861401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                                              0000000077861419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                                            0000000077861431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                                            000000007786144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll
.text  ...                                                                                                                                                                                              * 9
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                                                00000000778614dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                                        00000000778614f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                                                000000007786150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                                        0000000077861525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                                              000000007786153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                                                    0000000077861555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                                            000000007786156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                                              0000000077861585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                                                  000000007786159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                                              00000000778615b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                                            00000000778615cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                                        00000000778616b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll
.text  C:\Windows\AsScrPro.exe[3248] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                                        00000000778616bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!GetCursorPos                                                                                                                        000000007749ca44 5 bytes {CALL 0xffffffffffff35be}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!PeekMessageA                                                                                                                        00000000774a3a18 5 bytes {CALL 0xfffffffffffec5ea}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!GetMessageA                                                                                                                          00000000774a6110 5 bytes {CALL 0xfffffffffffe9ef2}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!PeekMessageW                                                                                                                        00000000774a8fd0 5 bytes {CALL 0xfffffffffffe7032}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!GetMessageW                                                                                                                          00000000774a9e74 5 bytes {CALL 0xfffffffffffe618e}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!GetMessagePos                                                                                                                        00000000774b84e0 5 bytes {CALL 0xfffffffffffd7b22}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!GetCursorInfo                                                                                                                        00000000774baef0 5 bytes {CALL 0xfffffffffffd5112}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!SetCursorPos                                                                                                                        00000000774d1f58 5 bytes {CALL 0xfffffffffffbe0aa}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxA                                                                                                                          00000000775012b8 5 bytes {CALL 0xfffffffffff8ed4a}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxW                                                                                                                          0000000077501314 2 bytes [E8, E9]
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxW + 3                                                                                                                      0000000077501317 2 bytes [F8, FF]
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxExA                                                                                                                        0000000077501370 2 bytes [E8, 8D]
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxExA + 3                                                                                                                    0000000077501373 2 bytes [F8, FF]
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxExW                                                                                                                        0000000077501394 2 bytes [E8, 69]
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxExW + 3                                                                                                                    0000000077501397 2 bytes [F8, FF]
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxIndirectA                                                                                                                  0000000077501668 5 bytes {CALL 0xfffffffffff8e99a}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\USER32.dll!MessageBoxIndirectW                                                                                                                  0000000077501874 5 bytes {CALL 0xfffffffffff8e78e}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\winmm.dll!PlaySoundW                                                                                                                            000007fef7c92144 5 bytes {CALL 0xffffffffffffdebe}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\winmm.dll!waveOutWrite                                                                                                                          000007fef7c93d40 5 bytes {CALL 0xffffffffffffc2c2}
.text  C:\WINDOWS\EXPLORER.EXE[9144] C:\Windows\system32\winmm.dll!PlaySound                                                                                                                            000007fef7cb2f10 5 bytes {CALL 0xfffffffffffdd0f2}

---- Threads - GMER 2.1 ----

Thread  C:\WINDOWS\EXPLORER.EXE [2292:3120]                                                                                                                                                              0000000001d02ec0
Thread  C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE [5140:5316]                                                                                                                            0000000076bd7587
Thread  C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE [5140:4468]                                                                                                                            0000000071097712
Thread  C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE [5140:5984]                                                                                                                            00000000778e2e65
Thread  C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE [5140:6832]                                                                                                                            00000000778e3e85
Thread  C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MSCORSVW.EXE [5140:9388]                                                                                                                            00000000778e3e85
Thread  C:\WINDOWS\EXPLORER.EXE [6956:4636]                                                                                                                                                              00000000000739a8
Thread  C:\WINDOWS\EXPLORER.EXE [6956:5556]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:2536]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:8580]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:5508]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:4184]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:5540]                                                                                                                                                              00000000000811d4
Thread  C:\WINDOWS\EXPLORER.EXE [6956:7912]                                                                                                                                                              00000000000811d4
Thread  C:\WINDOWS\EXPLORER.EXE [6956:6348]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:8616]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:9592]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:7652]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [6956:10088]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [1516:8148]                                                                                                                                                              00000000000f39a8
Thread  C:\WINDOWS\EXPLORER.EXE [1516:4368]                                                                                                                                                              00000000000fc0d0
Thread  C:\WINDOWS\EXPLORER.EXE [1516:9780]                                                                                                                                                              00000000000fc0d0
Thread  C:\WINDOWS\EXPLORER.EXE [1516:9204]                                                                                                                                                              00000000000fc0d0
Thread  C:\WINDOWS\EXPLORER.EXE [1516:7036]                                                                                                                                                              00000000000fc0d0
Thread  C:\WINDOWS\EXPLORER.EXE [1516:7476]                                                                                                                                                              00000000001011d4
Thread  C:\WINDOWS\EXPLORER.EXE [1516:8836]                                                                                                                                                              00000000000fc0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9372:3944]                                                                                                                                                              00000000000739a8
Thread  C:\WINDOWS\EXPLORER.EXE [9372:9352]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9372:1092]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9372:9184]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9372:8920]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9372:8468]                                                                                                                                                              00000000000811d4
Thread  C:\WINDOWS\EXPLORER.EXE [9372:9296]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9372:5796]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9372:4204]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9144:9520]                                                                                                                                                              00000000000739a8
Thread  C:\WINDOWS\EXPLORER.EXE [9144:8356]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9144:9828]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9144:9548]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9144:7220]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9144:1860]                                                                                                                                                              00000000000811d4
Thread  C:\WINDOWS\EXPLORER.EXE [9144:6616]                                                                                                                                                              000000000007c0d0
Thread  C:\WINDOWS\EXPLORER.EXE [9144:7744]                                                                                                                                                              000000000007c0d0

---- Registry - GMER 2.1 ----

Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e                                                                                                                     
Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\ac7289631a0e                                                                                                                     
Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\ac7289631a0e@881fa1c20730                                                                                                          0x0A 0xC5 0x6F 0x85 ...
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet)                                                                                                 
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\ac7289631a0e (not active ControlSet)                                                                                                 
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\ac7289631a0e@881fa1c20730                                                                                                              0x0A 0xC5 0x6F 0x85 ...
Reg    HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Hendrik\AppData\Local\Logitech\xae Webcam-Software\Logishrd\LU2.0\LogitechUpdate.exe  1

---- EOF - GMER 2.1 ----

5. Malwarebytes

Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 06.11.2014
Suchlauf-Zeit: 16:29:01
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.3.1025
Malware Datenbank: v2014.11.06.05
Rootkit Datenbank: v2014.11.01.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Hendrik

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 382719
Verstrichene Zeit: 1 Std, 11 Min, 20 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente erkannt)

Module: 0
(Keine schädliche Elemente erkannt)

Registrierungsschlüssel: 0
(Keine schädliche Elemente erkannt)

Registrierungswerte: 2
Trojan.Agent.MSDGen, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN|3975925605, C:\PROGRA~3\mslojpbc.exe, In Quarantäne, [c7c60335c4b8cd69c8486ec417eca25e]
Trojan.Agent.MSDGen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN|3975925605, C:\PROGRA~3\mslojpbc.exe, In Quarantäne, [c7c60335c4b8cd69c8486ec417eca25e]

Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)

Ordner: 0
(Keine schädliche Elemente erkannt)

Dateien: 5
Spyware.Passwords.ED, C:\ProgramData\Windows Genuine Advantage\{8089C5E3-7D9C-403A-AD48-D3DCE88B365C}\api-ms-win-system-crypt32-l1-1-0.dll, In Quarantäne, [632a1b1dc3b9fd39eeef537ef70a05fb],
Spyware.Passwords.ED, C:\ProgramData\Windows Genuine Advantage\{EDF91A0F-D196-4A0A-A418-6FFA02221287}\api-ms-win-system-vfnws-l1-1-0.dll, In Quarantäne, [d8b50b2d6319e452f6e7e3eecc35b14f],
Trojan.Agent, C:\Users\Hendrik\AppData\Local\Temp\UpdateFlashPlayer_d9e6c7ff.exe, In Quarantäne, [8d0098a0e7954bebe328e3fc45bcef11],
Trojan.Agent, C:\Users\Hendrik\AppData\Local\Temp\UpdateFlashPlayer_fbca044b.exe, In Quarantäne, [9df02711a9d352e4c2492fb04db44eb2],
Trojan.Agent.MSDGen, C:\ProgramData\mslojpbc.exe, In Quarantäne, [c7c60335c4b8cd69c8486ec417eca25e],

Physische Sektoren: 0
(Keine schädliche Elemente erkannt)


(end)


deeprybka 10.11.2014 19:16

:hallo:

Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...:abklatsch:
  • Bitte arbeite alle Schritte der Reihe nach ab.
  • Lese die Anleitungen sorgfältig durch bevor Du beginnst. Wenn es Probleme gibt oder Du etwas nicht verstehst, dann stoppe mit Deiner Ausführung und beschreibe mir das Problem.
  • Führe bitte nur Scans durch, zu denen Du von mir aufgefordert wurdest.
  • Bitte kein Crossposting (posten in mehreren Foren).
  • Installiere oder deinstalliere während der Bereinigung keine Software, außer Du wurdest dazu aufgefordert.
  • Speichere alle unsere Tools auf dem Desktop ab. Link: So ladet Ihr unsere Tools richtig
  • Poste die Logfiles direkt in Deinen Thread in Code-Tags.
  • Bedenke, dass wir hier alle während unserer Freizeit tätig sind, wenn du innerhalb von 24 Stunden nichts von mir liest, dann schreibe mir bitte eine PM.

Hinweis:
Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden.
Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert.
Adware & Co. können wir sehr gut entfernen.
Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean :daumenhoc bekommst.



Los geht's:
Keine sensiblen Logins mehr von diesem PC bis zum >clean<. Wenn Du online-Banking, paypal etc. mit diesem PC gemacht hast, dann würde ich die Passwörter von einem anderen (sauberen) PC, Handy ändern.

Schritt 1
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Anchovi 10.11.2014 21:25

Hallo Jürgen,vielen Dank für deine Hilfe! Ich habe gerade Combofix ausgeführt und nach Abschluss startet der Rechner neu. Der Hinweis im darauf folgenden Bildschirm "Bereite Logdatei vor" steht dort nun schon seit fast 20 Minuten,ohne dass sich etwas tut. Ist das normal oder könnte er daran liegen,dass Security Essentials trotz Deaktivierung nach Neustart des Rechners angesprungen und eine Bedrohung meldet?
Gruß Anchovi

deeprybka 10.11.2014 21:28

Brich das ganze ab und mach bitte einen Scan mit FRST:

Schritt 1

http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png

Bitte starte FRST erneut, und drücke auf Scan.
Bitte poste mir den Inhalt des Logs.

Anchovi 10.11.2014 21:54

Hi, hier der Inhalt des Logs.

Gruß Anchovi
FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-11-2014 01
Ran by Hendrik (administrator) on HENDRIK-PC on 10-11-2014 21:39:56
Running from C:\Users\Hendrik\Downloads
Loaded Profile: Hendrik (Available profiles: Hendrik & DefaultAppPool)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
() C:\Program Files (x86)\Join Air\UIExec.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Hendrik\Downloads\FRST64(1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-09] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2255360 2011-06-10] (ASUS)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UIExec] => C:\Program Files (x86)\Join Air\UIExec.exe [132608 2009-08-31] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [Wiuhyfreyquwh] => "C:\Users\Hendrik\AppData\Roaming\Urmytiyf\ywwego.exe"
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-18\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideSCAHealth] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Plugin HKU\S-1-5-21-1724138799-3868663929-1243099489-1000: @torrentstream.net/tsplugin,version=1.0.6 -> C:\Users\Hendrik\AppData\Roaming\TorrentStream\player\npts.dll (The Torrent Stream and VideoLAN and Delft University of Technology)
FF Plugin ProgramFiles/Appdata: C:\Users\Hendrik\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ddg.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018\Extensions\gmailnoads@mywebber.com.xpi [2014-10-11]
FF Extension: Adblock Plus - C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-11]

Chrome:
=======
CHR HomePage: Default -> chrome://newtab
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.671\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll ()
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Users\Hendrik\AppData\Roaming\Mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.670.1) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U67) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Torrent Stream P2P Multimedia Plug-in) - C:\Users\Hendrik\AppData\Roaming\TorrentStream\player\npts.dll (The Torrent Stream and VideoLAN and Delft University of Technology)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll No File
CHR Profile: C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-16]
CHR Extension: (Google Drive) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-16]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04]
CHR Extension: (YouTube) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-16]
CHR Extension: (Google-Suche) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-16]
CHR Extension: (Google Wallet) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-16]
CHR Extension: (TS Magic Player) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ochbjojkpcmlfeagbaahkofepalngihg [2014-04-26]
CHR Extension: (Google Mail) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-11] (Seiko Epson Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com)
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [241664 2009-08-31] () [File not signed]
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S2 lxdu_device; C:\Windows\system32\lxducoms.exe -service [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 assd; C:\Windows\System32\Drivers\assd.sys [27264 2010-04-28] (ASUS Corporation)
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-11] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2013-12-08] (Windows (R) Win 7 DDK provider)
S2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam64.sys [1071032 2012-04-15] (Windows (R) Win 7 DDK provider)
S1 brdzkxcp; \??\C:\Windows\system32\drivers\brdzkxcp.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S1 gucgznbc; \??\C:\Windows\system32\drivers\gucgznbc.sys [X]
S1 inqltdso; \??\C:\Windows\system32\drivers\inqltdso.sys [X]
S1 laaolckg; \??\C:\Windows\system32\drivers\laaolckg.sys [X]
S1 lxukkwfx; \??\C:\Windows\system32\drivers\lxukkwfx.sys [X]
S1 vngoazpn; \??\C:\Windows\system32\drivers\vngoazpn.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-10 21:33 - 2014-11-10 21:35 - 02116096 _____ (Farbar) C:\Users\Hendrik\Downloads\FRST64(1).exe
2014-11-10 20:13 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-11-10 20:13 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-11-10 20:13 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-11-10 20:12 - 2014-11-10 21:29 - 00000000 ____D () C:\ComboFix
2014-11-10 20:10 - 2014-11-10 20:12 - 00000000 ____D () C:\Qoobox
2014-11-10 20:06 - 2014-11-10 21:18 - 00000000 ____D () C:\Windows\erdnt
2014-11-10 19:57 - 2014-11-10 19:58 - 05598341 ____R (Swearware) C:\Users\Hendrik\Desktop\ComboFix.exe
2014-11-10 19:47 - 2014-11-10 19:47 - 00000000 ____D () C:\OETemp
2014-11-10 19:41 - 2014-11-10 19:41 - 05598341 _____ (Swearware) C:\Users\Hendrik\Downloads\ComboFix(1).exe
2014-11-10 19:40 - 2014-11-10 19:41 - 05598341 _____ (Swearware) C:\Users\Hendrik\Downloads\ComboFix.exe
2014-11-10 18:58 - 2014-11-10 19:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-08 14:45 - 2014-11-08 14:45 - 00003536 ____N () C:\bootsqm.dat
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Gyxyewlu
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Baexkir
2014-11-08 11:48 - 2014-11-08 11:48 - 00003834 _____ () C:\Windows\System32\Tasks\Security Center Update - 1783181859
2014-11-08 11:48 - 2014-11-08 11:48 - 00003830 _____ () C:\Windows\System32\Tasks\Security Center Update - 279616795
2014-11-08 11:48 - 2014-11-08 11:48 - 00003826 _____ () C:\Windows\System32\Tasks\Security Center Update - 3634134863
2014-11-08 11:47 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Vyyhxe
2014-11-08 11:21 - 2014-11-08 11:21 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (15)
2014-11-08 10:45 - 2014-11-08 10:50 - 710442486 _____ () C:\Users\Hendrik\Documents\clip0919.avi
2014-11-07 16:38 - 2014-11-10 19:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2014-11-06 21:29 - 2014-11-06 21:43 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (78)
2014-11-06 19:00 - 2014-11-10 19:51 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-11-06 18:59 - 2014-11-06 18:59 - 04583464 _____ (Avira Operations GmbH & Co. KG) C:\Users\Hendrik\Downloads\avira_de_av___ws.exe
2014-11-06 18:41 - 2014-11-06 18:41 - 00380416 _____ () C:\Users\Hendrik\Desktop\Gmer-19357.exe
2014-11-06 18:34 - 2014-11-06 18:36 - 00041719 _____ () C:\Users\Hendrik\Downloads\Addition.txt
2014-11-06 18:31 - 2014-11-10 21:39 - 00024522 _____ () C:\Users\Hendrik\Downloads\FRST.txt
2014-11-06 18:30 - 2014-11-10 21:40 - 00000000 ____D () C:\FRST
2014-11-06 18:30 - 2014-11-06 18:30 - 02114560 _____ (Farbar) C:\Users\Hendrik\Downloads\FRST64.exe
2014-11-06 18:28 - 2014-11-06 18:29 - 00000476 _____ () C:\Users\Hendrik\Downloads\defogger_disable.log
2014-11-06 18:28 - 2014-11-06 18:28 - 00000000 _____ () C:\Users\Hendrik\defogger_reenable
2014-11-06 18:27 - 2014-11-06 18:27 - 00050477 _____ () C:\Users\Hendrik\Downloads\Defogger.exe
2014-11-06 16:25 - 2014-11-06 18:20 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-06 16:19 - 2014-11-06 16:19 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-06 16:19 - 2014-11-06 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-06 16:18 - 2014-11-06 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-06 16:18 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-06 16:18 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-06 16:18 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-06 16:16 - 2014-11-06 16:17 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025(2).exe
2014-11-06 16:00 - 2014-11-06 16:00 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025(1).exe
2014-11-06 15:43 - 2014-11-06 15:43 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-06 12:02 - 2014-11-06 12:06 - 121435896 _____ (Microsoft Corporation) C:\Users\Hendrik\Downloads\msert(2).exe
2014-11-05 17:18 - 2014-11-05 17:18 - 01125200 _____ () C:\Users\Hendrik\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe
2014-11-05 16:42 - 2014-11-05 16:42 - 00896504 _____ (Microsoft Corporation) C:\Users\Hendrik\Downloads\mssstool64.exe
2014-11-04 22:47 - 2014-11-05 15:52 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Urmytiyf
2014-11-04 21:50 - 2014-11-06 13:44 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-11-04 17:44 - 2014-11-06 15:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2014-11-04 17:44 - 2014-11-06 15:30 - 00000000 ____D () C:\Program Files\Wondershare
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ___HD () C:\Program Files (x86)\Dr.Fone_Temp
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Wondershare
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ____D () C:\ProgramData\Wondershare
2014-11-04 17:43 - 2014-11-04 17:43 - 00000000 ____D () C:\Users\Public\Documents\Wondershare
2014-11-04 17:16 - 2014-11-04 17:16 - 00000000 ____D () C:\Users\Hendrik\Desktop\Media
2014-11-04 17:07 - 2014-11-05 16:09 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Reincubate
2014-11-04 10:42 - 2014-11-04 10:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\WindSolutions
2014-11-04 10:42 - 2014-11-04 10:46 - 00000000 ____D () C:\ProgramData\WindSolutions
2014-11-04 00:08 - 2014-11-04 00:08 - 00000000 ____D () C:\Users\Hendrik\.android
2014-11-03 23:53 - 2014-11-04 00:05 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-11-02 00:42 - 2014-11-02 00:43 - 107254738 _____ () C:\Users\Hendrik\Documents\clip0918.avi
2014-11-01 12:32 - 2014-11-01 12:32 - 04078544 _____ (iMobie Inc. ) C:\Users\Hendrik\Downloads\phonerescue-setup.exe
2014-10-30 22:34 - 2014-10-30 22:36 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (21)
2014-10-29 15:01 - 2014-10-29 15:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-10-29 14:06 - 2014-10-29 14:06 - 00002192 _____ () C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2014-10-29 14:05 - 2014-10-29 14:05 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2014-10-27 17:43 - 2014-10-27 17:43 - 00002170 _____ () C:\Users\Hendrik\.recently-used.xbel
2014-10-27 00:15 - 2014-10-27 00:16 - 118253116 _____ () C:\Users\Hendrik\Documents\clip0917.avi
2014-10-26 23:50 - 2014-10-26 23:52 - 195895978 _____ () C:\Users\Hendrik\Documents\clip0916.avi
2014-10-25 23:09 - 2014-10-25 23:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2014-10-24 23:21 - 2014-10-24 23:21 - 25336014 _____ () C:\Users\Hendrik\Documents\clip0915.avi
2014-10-24 23:13 - 2014-10-24 23:13 - 06658282 _____ () C:\Users\Hendrik\Documents\clip0914.avi
2014-10-21 15:36 - 2014-10-21 15:36 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-21 15:36 - 2014-10-21 15:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\Program Files\iTunes
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-21 15:35 - 2014-10-21 15:35 - 00000000 ____D () C:\Program Files\iPod
2014-10-21 13:47 - 2014-10-21 13:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\pdfforge
2014-10-20 11:42 - 2014-10-20 11:42 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Oracle
2014-10-20 11:24 - 2014-10-20 11:23 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-10-20 11:23 - 2014-10-20 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-20 00:40 - 2014-10-20 01:10 - 2638644386 _____ () C:\Users\Hendrik\Documents\clip0913.avi
2014-10-19 18:19 - 2014-10-19 18:19 - 00613203 _____ () C:\Users\Hendrik\Downloads\Plain Cloud_1.0(1).zip
2014-10-19 17:50 - 2014-10-19 17:50 - 00613203 _____ () C:\Users\Hendrik\Downloads\Plain Cloud_1.0.zip
2014-10-19 17:18 - 2014-10-19 17:18 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Python
2014-10-19 17:18 - 2014-10-19 17:18 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\ActiveState
2014-10-19 17:10 - 2014-10-19 18:05 - 00000000 ____D () C:\Users\Hendrik\Downloads\Whatsapp_Xtract_V2.2_2012-11-17
2014-10-19 15:38 - 2014-11-04 23:21 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Apple Inc
2014-10-15 21:36 - 2014-10-15 21:36 - 00144627 _____ () C:\Users\Hendrik\Downloads\NB SB.aac
2014-10-15 10:55 - 2014-10-15 10:55 - 00000000 ____H () C:\Users\Hendrik\Desktop\~WRL0254.tmp
2014-10-15 10:53 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 10:53 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-15 10:53 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2014-10-15 10:53 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 10:52 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-10-15 10:52 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-10-15 10:52 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-10-15 10:52 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-15 10:52 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-10-15 10:52 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-15 10:52 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-15 10:52 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2014-10-15 10:52 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-10-15 10:52 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-15 10:52 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-15 10:52 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-15 10:52 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-15 10:52 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-15 10:52 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-15 10:52 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-15 10:52 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2014-10-15 10:52 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2014-10-15 10:52 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-10-15 10:52 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-10-15 10:52 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-10-15 10:52 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-15 10:52 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-15 10:51 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-15 10:51 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-15 10:50 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-15 10:50 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 10:50 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-15 10:50 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-15 10:50 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-15 10:50 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-15 10:50 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 10:50 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 10:50 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 10:50 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 10:50 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-15 10:50 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 10:50 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 10:50 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 10:50 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 10:50 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 10:50 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 10:50 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 10:50 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 10:50 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 10:50 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 10:50 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-15 10:50 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 10:50 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 10:50 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 10:50 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-15 10:50 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 10:50 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 10:50 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-15 10:50 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 10:50 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-15 10:50 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 10:50 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-15 10:50 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-15 10:50 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-15 10:50 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-15 10:50 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-15 10:50 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-15 10:50 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 10:50 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 10:50 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 10:50 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 10:50 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 10:50 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-15 10:50 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-15 10:50 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-15 10:50 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 10:50 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-15 10:50 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 10:50 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-15 10:50 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-15 10:49 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-15 10:49 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-15 10:48 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 10:48 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-15 10:48 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 10:48 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 10:48 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-15 10:48 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-15 10:48 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-15 10:48 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 10:48 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-15 10:46 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 10:46 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-15 10:46 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 10:46 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-14 14:42 - 2014-10-14 14:42 - 00000000 ____D () C:\Users\Hendrik\Downloads\Snappening
2014-10-14 14:29 - 2014-10-14 14:38 - 00000000 ____D () C:\Users\Hendrik\Downloads\x
2014-10-11 10:42 - 2010-08-30 07:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-10-11 10:40 - 2014-10-11 10:43 - 00000000 ____D () C:\AdwCleaner

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-10 21:20 - 2009-07-14 05:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-10 21:20 - 2009-07-14 05:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-10 21:08 - 2013-10-16 10:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-10 21:05 - 2012-04-12 17:11 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-10 21:05 - 2012-02-20 09:59 - 00000000 ___HD () C:\ASUS.DAT
2014-11-10 21:05 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-11-10 21:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-10 21:03 - 2014-02-15 20:18 - 00299502 _____ () C:\Windows\PFRO.log
2014-11-10 21:03 - 2014-01-03 20:01 - 00040771 _____ () C:\Windows\setupact.log
2014-11-10 20:50 - 2012-04-12 17:11 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-10 20:44 - 2011-11-18 22:28 - 00000000 ____D () C:\ProgramData\Temp
2014-11-10 19:51 - 2012-05-02 16:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 19:49 - 2013-01-12 14:29 - 00000000 ____D () C:\ProgramData\Package Cache
2014-11-10 19:49 - 2011-11-18 22:11 - 02072675 _____ () C:\Windows\WindowsUpdate.log
2014-11-10 19:21 - 2013-01-28 17:23 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{40B698CB-62BD-4EE1-A271-0656D24B8F85}
2014-11-07 15:03 - 2013-12-08 21:30 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-11-06 21:56 - 2013-10-19 22:00 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\vlc
2014-11-06 20:11 - 2011-11-18 22:28 - 00001860 _____ () C:\Windows\system32\ServiceFilter.ini
2014-11-06 18:28 - 2012-02-20 09:58 - 00000000 ____D () C:\Users\Hendrik
2014-11-06 15:38 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-06 15:31 - 2014-08-15 17:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iMobie
2014-11-06 15:31 - 2014-08-15 16:39 - 00000000 ____D () C:\Program Files (x86)\iMobie
2014-11-05 15:55 - 2012-02-20 10:27 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Apple Computer
2014-11-04 17:58 - 2014-01-28 14:11 - 00000000 ____D () C:\Users\Hendrik\Desktop\sortieren
2014-11-04 17:07 - 2012-02-20 10:15 - 00000000 ____D () C:\Users\Hendrik\Desktop\Programme
2014-11-04 10:10 - 2013-03-18 12:04 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\uTorrent
2014-11-03 14:08 - 2012-02-20 09:59 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-11-02 11:26 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-01 12:33 - 2014-08-15 16:39 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\iMobie
2014-11-01 12:33 - 2014-08-15 16:39 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\iMobie_Inc
2014-10-30 12:25 - 2012-04-27 08:56 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-29 15:13 - 2012-02-20 11:41 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Skype
2014-10-29 15:02 - 2012-02-20 11:41 - 00000000 ____D () C:\ProgramData\Skype
2014-10-29 15:01 - 2014-08-11 20:27 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-10-29 13:48 - 2014-08-20 17:26 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Adobe
2014-10-29 13:47 - 2013-10-16 10:01 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-29 13:47 - 2013-10-16 10:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-29 13:47 - 2013-10-16 10:01 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-27 17:46 - 2012-04-12 15:48 - 00000000 ____D () C:\Users\Hendrik\.gimp-2.6
2014-10-27 12:07 - 2011-02-19 10:08 - 00745910 _____ () C:\Windows\system32\perfh007.dat
2014-10-27 12:07 - 2011-02-19 10:08 - 00162816 _____ () C:\Windows\system32\perfc007.dat
2014-10-27 12:07 - 2009-07-14 06:13 - 01732678 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-25 23:11 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-25 23:09 - 2012-03-14 13:46 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-10-24 11:45 - 2012-04-12 17:11 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-24 11:45 - 2012-04-12 17:11 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-22 11:07 - 2014-06-10 18:44 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\7-PDFSplitMerge
2014-10-22 08:02 - 2012-11-20 10:20 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-10-22 07:59 - 2013-11-20 16:47 - 00000000 ____D () C:\ProgramData\MAGIX
2014-10-21 19:03 - 2012-02-20 10:27 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Apple Computer
2014-10-21 15:35 - 2014-09-10 23:19 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-20 11:24 - 2013-10-19 11:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-20 11:23 - 2012-02-22 16:25 - 00000000 ____D () C:\Program Files (x86)\Java
2014-10-20 10:54 - 2009-07-14 05:45 - 00518968 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-19 17:25 - 2012-02-20 09:59 - 00160264 _____ () C:\Users\Hendrik\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-19 15:56 - 2013-12-17 15:19 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\C24C21DE-B653-4E21-81BE-22AF552FB2ED.aplzod
2014-10-19 15:53 - 2012-03-17 13:25 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Microsoft Help
2014-10-17 17:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-10-16 00:16 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-15 22:29 - 2013-01-09 22:52 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-10-15 22:29 - 2012-02-22 13:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\DVDVideoSoft
2014-10-15 22:27 - 2012-02-22 13:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-10-15 17:33 - 2014-05-06 23:24 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-10-15 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-10-15 17:01 - 2012-03-17 13:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 16:47 - 2013-08-19 02:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 16:38 - 2012-10-20 09:57 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Windows Live
2014-10-15 16:19 - 2012-02-21 18:34 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-11 11:26 - 2011-04-09 19:54 - 00000000 ____D () C:\Windows\he
2014-10-11 10:55 - 2013-12-05 22:04 - 00000000 ____D () C:\ProgramData\Malwarebytes

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-06 14:23

==================== End Of Log ============================

--- --- ---

deeprybka 10.11.2014 21:56

OK, jetzt bitte so weiter: (Bitte das Tool auf den Desktop downloaden oder kopieren!!!)

Schritt 1

http://deeprybka.trojaner-board.de/t...x/relogotb.png

Downloade Dir ESETRovnixCleaner auf Deinen Desktop:
  • Download
  • Starte das Tool mit Rechtsklick "als Administrator".
  • Wenn Malware gefunden wird drücke die "Y" Taste.
  • Der Entfernungsvorgang erfordert einen Neustart des PC und beginnt mit dem Drücken einer beliebigen Taste.
  • Bitte poste mir das Log welches vom Tool erstellt wurde in jedem Fall.
http://deeprybka.trojaner-board.de/tools/rovnix/re1.png
http://deeprybka.trojaner-board.de/tools/rovnix/re2.png

Anchovi 10.11.2014 22:08

[2014.11.10 21:58:48.161] - Begin
[2014.11.10 21:58:48.161] -
[2014.11.10 21:58:48.218] - ....................................
[2014.11.10 21:58:48.219] - ..::::::::::::::::::....................
[2014.11.10 21:58:48.221] - .::EEEEEE:::SSSSSS::..EEEEEE..TTTTTTTT.. Win32/Rovnix
[2014.11.10 21:58:48.223] - .::EE::::EE:SS:::::::.EE....EE....TT...... Version: 1.1.0.1
[2014.11.10 21:58:48.224] - .::EEEEEEEE::SSSSSS::.EEEEEEEE....TT...... Built: Oct 23 2014
[2014.11.10 21:58:48.225] - .::EE:::::::::::::SS:.EE..........TT......
[2014.11.10 21:58:48.226] - .::EEEEEE:::SSSSSS::..EEEEEE.....TT..... Copyright (c) ESET, spol. s r.o.
[2014.11.10 21:58:48.227] - ..::::::::::::::::::.................... 1992-2013. All rights reserved.
[2014.11.10 21:58:48.227] - ....................................
[2014.11.10 21:58:48.227] -
[2014.11.10 21:58:48.228] - --------------------------------------------------------------------------------
[2014.11.10 21:58:48.228] -
[2014.11.10 21:58:48.228] - INFO: OS: 6.1.7601 SP1
[2014.11.10 21:58:48.229] - INFO: Product Type: Workstation
[2014.11.10 21:58:48.229] - INFO: WoW64: True
[2014.11.10 21:58:48.229] - INFO: Machine guid: 96EA417C-D7F3-4D54-9922-184F997324B2
[2014.11.10 21:58:48.229] -
[2014.11.10 21:58:50.720] - INFO: Scanning for system infection...
[2014.11.10 21:58:50.720] - --------------------------------------------------------------------------------
[2014.11.10 21:58:50.720] -
[2014.11.10 21:58:51.129] - INFO: INF_PASI1 - 0x00000000...
[2014.11.10 21:58:51.129] - INFO: INF_PASI2 - 0x80000025...
[2014.11.10 21:58:51.129] -
[2014.11.10 21:58:51.129] - INFO: INF_PASI3 - 0x00000000...
[2014.11.10 21:58:51.129] - INFO: ESET Cleaner Service initialized successfully.
[2014.11.10 21:58:51.129] -
[2014.11.10 21:58:51.129] - --------------------------------------------------------------------------------
[2014.11.10 21:58:51.129] - INFO: Checking active infection...
[2014.11.10 21:58:51.129] -
[2014.11.10 21:58:51.129] - INFO: INF_PASGSH2 - 0x00000000...
[2014.11.10 21:58:51.129] - INFO: INF_PASGSH3 - 0x00000000...
[2014.11.10 21:58:51.129] - --------------------------------------------------------------------------------
[2014.11.10 21:58:51.129] - INFO: Checking inactive infection...
[2014.11.10 21:58:51.130] -
[2014.11.10 21:58:51.207] - INFO: CHECKING DISK NO - 0 | TYPE - 7 | SIZE - 0x2542EAAF(298GB)
[2014.11.10 21:58:51.252] - INFO: -> PARTITION NO - 0 | TYPE - 0x1C | BOOTABLE - False | STARTING LBA - 0x00000800 | SIZE - 0x03200000 (25GB)
[2014.11.10 21:58:51.252] - INFO: -> PARTITION NO - 1 | TYPE - 0x07 | BOOTABLE - True | STARTING LBA - 0x03200800 | SIZE - 0x0EE79000 (119GB)
[2014.11.10 21:58:51.252] - INFO: -> PARTITION NO - 2 | TYPE - 0x07 | BOOTABLE - False | STARTING LBA - 0x12079800 | SIZE - 0x133B4800 (153GB)
[2014.11.10 21:58:51.252] -
[2014.11.10 21:58:51.324] - INFO: 00000001: passed...
[2014.11.10 21:58:51.331] - INFO: 00000400: passed...
[2014.11.10 21:58:51.331] -
[2014.11.10 21:58:51.343] - INFO: [1] Detected Vbr modification by Rovnix.D!
[2014.11.10 21:58:51.343] - --------------------------------------------------------------------------------
[2014.11.10 21:58:51.343] - INFO: Win32/Rovnix found
[2014.11.10 21:58:54.917] - --------------------------------------------------------------------------------
[2014.11.10 21:58:54.917] - INFO: Cleaning infection...
[2014.11.10 21:58:54.917] -
[2014.11.10 21:58:54.919] - INFO: [3] Infection cleaned successfully!
[2014.11.10 21:58:54.919] -
[2014.11.10 21:58:54.919] - INFO: Cleaning status: 1
[2014.11.10 21:59:22.725] - End

deeprybka 10.11.2014 22:11

Prima! :daumenhoc

Jetzt bitte PC nochmal neu starten und Tool erneut ausführen. Auch wenn nichts gefunden wird, bitte Log posten. :)

Anchovi 10.11.2014 22:20

[2014.11.10 22:19:18.881] - Begin
[2014.11.10 22:19:18.882] -
[2014.11.10 22:19:18.970] - ....................................
[2014.11.10 22:19:18.971] - ..::::::::::::::::::....................
[2014.11.10 22:19:18.974] - .::EEEEEE:::SSSSSS::..EEEEEE..TTTTTTTT.. Win32/Rovnix
[2014.11.10 22:19:18.978] - .::EE::::EE:SS:::::::.EE....EE....TT...... Version: 1.1.0.1
[2014.11.10 22:19:18.981] - .::EEEEEEEE::SSSSSS::.EEEEEEEE....TT...... Built: Oct 23 2014
[2014.11.10 22:19:18.983] - .::EE:::::::::::::SS:.EE..........TT......
[2014.11.10 22:19:18.987] - .::EEEEEE:::SSSSSS::..EEEEEE.....TT..... Copyright (c) ESET, spol. s r.o.
[2014.11.10 22:19:18.988] - ..::::::::::::::::::.................... 1992-2013. All rights reserved.
[2014.11.10 22:19:18.989] - ....................................
[2014.11.10 22:19:18.989] -
[2014.11.10 22:19:18.990] - --------------------------------------------------------------------------------
[2014.11.10 22:19:18.990] -
[2014.11.10 22:19:18.992] - INFO: OS: 6.1.7601 SP1
[2014.11.10 22:19:18.993] - INFO: Product Type: Workstation
[2014.11.10 22:19:18.993] - INFO: WoW64: True
[2014.11.10 22:19:18.994] - INFO: Machine guid: 96EA417C-D7F3-4D54-9922-184F997324B2
[2014.11.10 22:19:18.995] -
[2014.11.10 22:19:19.026] - INFO: Scanning for system infection...
[2014.11.10 22:19:19.027] - --------------------------------------------------------------------------------
[2014.11.10 22:19:19.028] -
[2014.11.10 22:19:19.536] - INFO: INF_PASI1 - 0x00000000...
[2014.11.10 22:19:19.536] - INFO: INF_PASI2 - 0x80000025...
[2014.11.10 22:19:19.536] -
[2014.11.10 22:19:19.536] - INFO: INF_PASI3 - 0x00000000...
[2014.11.10 22:19:19.537] - INFO: ESET Cleaner Service initialized successfully.
[2014.11.10 22:19:19.537] -
[2014.11.10 22:19:19.537] - --------------------------------------------------------------------------------
[2014.11.10 22:19:19.537] - INFO: Checking active infection...
[2014.11.10 22:19:19.537] -
[2014.11.10 22:19:19.537] - INFO: INF_PASGSH2 - 0x00000000...
[2014.11.10 22:19:19.537] - INFO: INF_PASGSH3 - 0x00000000...
[2014.11.10 22:19:19.537] - --------------------------------------------------------------------------------
[2014.11.10 22:19:19.537] - INFO: Checking inactive infection...
[2014.11.10 22:19:19.537] -
[2014.11.10 22:19:19.622] - INFO: CHECKING DISK NO - 0 | TYPE - 7 | SIZE - 0x2542EAAF(298GB)
[2014.11.10 22:19:19.745] - INFO: -> PARTITION NO - 0 | TYPE - 0x1C | BOOTABLE - False | STARTING LBA - 0x00000800 | SIZE - 0x03200000 (25GB)
[2014.11.10 22:19:19.745] - INFO: -> PARTITION NO - 1 | TYPE - 0x07 | BOOTABLE - True | STARTING LBA - 0x03200800 | SIZE - 0x0EE79000 (119GB)
[2014.11.10 22:19:19.745] - INFO: -> PARTITION NO - 2 | TYPE - 0x07 | BOOTABLE - False | STARTING LBA - 0x12079800 | SIZE - 0x133B4800 (153GB)
[2014.11.10 22:19:19.745] -
[2014.11.10 22:19:19.905] - INFO: 00000001: passed...
[2014.11.10 22:19:20.091] - INFO: 00000400: passed...
[2014.11.10 22:19:20.091] -
[2014.11.10 22:19:20.125] - --------------------------------------------------------------------------------
[2014.11.10 22:19:20.125] - INFO: Win32/Rovnix not found
[2014.11.10 22:19:26.855] - End

deeprybka 10.11.2014 22:27

http://www.bleepingcomputer.com/foru...ault/rip_1.gif
Rovnix


Naja, freuen wir uns nicht zu früh...;)

Schritt 1

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Anchovi 10.11.2014 22:50

22:46:11.0626 0x0ed8 TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34
22:46:16.0056 0x0ed8 ============================================================
22:46:16.0056 0x0ed8 Current date / time: 2014/11/10 22:46:16.0056
22:46:16.0056 0x0ed8 SystemInfo:
22:46:16.0056 0x0ed8
22:46:16.0056 0x0ed8 OS Version: 6.1.7601 ServicePack: 1.0
22:46:16.0056 0x0ed8 Product type: Workstation
22:46:16.0056 0x0ed8 ComputerName: HENDRIK-PC
22:46:16.0057 0x0ed8 UserName: Hendrik
22:46:16.0057 0x0ed8 Windows directory: C:\Windows
22:46:16.0057 0x0ed8 System windows directory: C:\Windows
22:46:16.0057 0x0ed8 Running under WOW64
22:46:16.0057 0x0ed8 Processor architecture: Intel x64
22:46:16.0057 0x0ed8 Number of processors: 4
22:46:16.0057 0x0ed8 Page size: 0x1000
22:46:16.0057 0x0ed8 Boot type: Normal boot
22:46:16.0057 0x0ed8 ============================================================
22:46:16.0524 0x0ed8 KLMD registered as C:\Windows\system32\drivers\43166474.sys
22:46:17.0123 0x0ed8 System UUID: {8C36091E-9C46-3568-21BA-DE7E258EFA02}
22:46:18.0215 0x0ed8 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:46:18.0958 0x0ed8 ============================================================
22:46:18.0958 0x0ed8 \Device\Harddisk0\DR0:
22:46:18.0992 0x0ed8 MBR partitions:
22:46:18.0992 0x0ed8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3200800, BlocksNum 0xEE79000
22:46:18.0992 0x0ed8 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x12079800, BlocksNum 0x133B4800
22:46:18.0992 0x0ed8 ============================================================
22:46:19.0028 0x0ed8 C: <-> \Device\Harddisk0\DR0\Partition1
22:46:19.0141 0x0ed8 D: <-> \Device\Harddisk0\DR0\Partition2
22:46:19.0141 0x0ed8 ============================================================
22:46:19.0141 0x0ed8 Initialize success
22:46:19.0141 0x0ed8 ============================================================
22:47:17.0915 0x08f4 ============================================================
22:47:17.0915 0x08f4 Scan started
22:47:17.0915 0x08f4 Mode: Manual; SigCheck; TDLFS;
22:47:17.0915 0x08f4 ============================================================
22:47:17.0915 0x08f4 KSN ping started
22:47:20.0386 0x08f4 KSN ping finished: true
22:47:21.0705 0x08f4 ================ Scan system memory ========================
22:47:21.0705 0x08f4 System memory - ok
22:47:21.0707 0x08f4 ================ Scan services =============================
22:47:22.0286 0x08f4 [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
22:47:22.0431 0x08f4 1394ohci - ok
22:47:22.0481 0x08f4 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys
22:47:22.0502 0x08f4 ACPI - ok
22:47:22.0536 0x08f4 [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
22:47:22.0633 0x08f4 AcpiPmi - ok
22:47:22.0908 0x08f4 [ C5679E5186B2FC95BC76A8A9870D5456, 70AC61850B811A0A902532F098AE1D5DF4622455E56C78B89D4ABDBE4A061A48 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:47:22.0965 0x08f4 AdobeARMservice - ok
22:47:23.0556 0x08f4 [ 2637233632CCD1837A1A57A43CAF00A4, 848026C6C9B38FD9F70BC7B2306BF4F5DD395726D4FDD6A18B29354921191DC5 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:47:23.0586 0x08f4 AdobeFlashPlayerUpdateSvc - ok
22:47:23.0759 0x08f4 [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
22:47:23.0789 0x08f4 adp94xx - ok
22:47:23.0873 0x08f4 [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\drivers\adpahci.sys
22:47:23.0896 0x08f4 adpahci - ok
22:47:23.0907 0x08f4 [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
22:47:23.0923 0x08f4 adpu320 - ok
22:47:23.0985 0x08f4 [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:47:24.0176 0x08f4 AeLookupSvc - ok
22:47:24.0262 0x08f4 [ 6E79A119B0CE418FE44E0C824BF3F039, 7C7E8ED41EFCDB20C1A0C038BB6C53CDBE6709E3573C8A93B4059C0CD08759EB ] AFBAgent C:\Windows\system32\FBAgent.exe
22:47:24.0369 0x08f4 AFBAgent - ok
22:47:24.0485 0x08f4 [ FA886682CFC5D36718D3E436AACF10B9, F80AB4F91AA6B5C7ECCB000D8E1BC2CF776DC3D69B3D9EBC2558C19035A6B3AB ] AFD C:\Windows\system32\drivers\afd.sys
22:47:24.0598 0x08f4 AFD - ok
22:47:24.0652 0x08f4 [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys
22:47:24.0671 0x08f4 agp440 - ok
22:47:24.0701 0x08f4 [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe
22:47:24.0777 0x08f4 ALG - ok
22:47:24.0816 0x08f4 [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys
22:47:24.0829 0x08f4 aliide - ok
22:47:24.0860 0x08f4 [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys
22:47:24.0873 0x08f4 amdide - ok
22:47:24.0894 0x08f4 [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
22:47:24.0958 0x08f4 AmdK8 - ok
22:47:24.0964 0x08f4 [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
22:47:25.0015 0x08f4 AmdPPM - ok
22:47:25.0066 0x08f4 [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys
22:47:25.0084 0x08f4 amdsata - ok
22:47:25.0107 0x08f4 [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
22:47:25.0127 0x08f4 amdsbs - ok
22:47:25.0155 0x08f4 [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys
22:47:25.0169 0x08f4 amdxata - ok
22:47:25.0229 0x08f4 [ 9921E78BC29634235F4BF5809E7E8CDE, 194FFE228923D267A3CCDCF371BDAE6ECB72E4B559C0716FC3A6D6113C2A9B48 ] AMPPAL C:\Windows\system32\DRIVERS\AMPPAL.sys
22:47:25.0288 0x08f4 AMPPAL - ok
22:47:25.0323 0x08f4 [ 9921E78BC29634235F4BF5809E7E8CDE, 194FFE228923D267A3CCDCF371BDAE6ECB72E4B559C0716FC3A6D6113C2A9B48 ] AMPPALP C:\Windows\system32\DRIVERS\amppal.sys
22:47:25.0340 0x08f4 AMPPALP - ok
22:47:25.0809 0x08f4 [ 83A0E7BA4AE616D3654E700D9C5FF9DB, 4FE28E51C77C417CEB9F724CCFB9A9ABF521C599E6B2AFD5A822CBEAF2AD0E4E ] AMPPALR3 C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
22:47:25.0856 0x08f4 AMPPALR3 - ok
22:47:25.0952 0x08f4 [ 92A848F962DA91C631147D566414BB7E, 8F3161A7C1930610819DA3529635B1D28C27E37BE75B2552402C97C78CA33477 ] AmUStor C:\Windows\system32\drivers\AmUStor.SYS
22:47:25.0967 0x08f4 AmUStor - ok
22:47:26.0082 0x08f4 [ 59D01FA91962C9C1E9B4022B2D3B46DB, 3A111588538B77F010B5C900FB8425DDE55A08DBAC308CA7FB7BD9FCCCDEC69F ] AppHostSvc C:\Windows\system32\inetsrv\apphostsvc.dll
22:47:26.0147 0x08f4 AppHostSvc - ok
22:47:26.0201 0x08f4 [ 80B9412C4DE09147581FC935FB4C97AB, 0C9661F7B5EF7F9D61981790B7AB64E3375BD117962166619D0CC546A2D014D3 ] AppID C:\Windows\system32\drivers\appid.sys
22:47:26.0255 0x08f4 AppID - ok
22:47:26.0260 0x08f4 [ F71CA01C24FC3798A717B5A6F682F9AD, 8CF1C209E7BBBAD02D6D087293C0B681CDA3170AF119CA2916C2708D8801E749 ] AppIDSvc C:\Windows\System32\appidsvc.dll
22:47:26.0306 0x08f4 AppIDSvc - ok
22:47:26.0343 0x08f4 [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo C:\Windows\System32\appinfo.dll
22:47:26.0408 0x08f4 Appinfo - ok
22:47:26.0557 0x08f4 [ 650D03E40F93FAE323CB841F80368E5C, F67B97CFDCE2EE9294977725268EFDB0DD724BD16E7ED5BFCA45375AA8EBA5BB ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
22:47:26.0569 0x08f4 Apple Mobile Device - ok
22:47:26.0626 0x08f4 [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt C:\Windows\System32\appmgmts.dll
22:47:26.0684 0x08f4 AppMgmt - ok
22:47:26.0736 0x08f4 [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\drivers\arc.sys
22:47:26.0751 0x08f4 arc - ok
22:47:26.0782 0x08f4 [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\drivers\arcsas.sys
22:47:26.0802 0x08f4 arcsas - ok
22:47:26.0982 0x08f4 [ 18E5C2F937F9DEB8C282DF66A3761925, 30294C381F8C7DCB45EF9BCF572F410FF47630E12D5AA02259C6C80F07BEF495 ] ASLDRService C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
22:47:27.0008 0x08f4 ASLDRService - ok
22:47:27.0044 0x08f4 [ 4C016FD76ED5C05E84CA8CAB77993961, 025E7BE9FCEFD6A83F4471BBA0C11F1C11BD5047047D26626DA24EE9A419CDC4 ] ASMMAP64 C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
22:47:27.0052 0x08f4 ASMMAP64 - ok
22:47:27.0323 0x08f4 [ 9A262EDD17F8473B91B333D6B031A901, 05DFBD3A7D83FDE1D062EA719ACA9EC48CB7FD42D17DDD88B82E5D25469ADD23 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:47:27.0346 0x08f4 aspnet_state - ok
22:47:27.0431 0x08f4 [ 06F30358A657CBA22115C4368B4001F9, C0FF7F964E1E7AC8B17EBB4308F17CA7C9BC9ED92E8B300D20A3B0DE0DAF2CB9 ] assd C:\Windows\system32\drivers\assd.sys
22:47:27.0458 0x08f4 assd - ok
22:47:27.0505 0x08f4 [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:47:27.0561 0x08f4 AsyncMac - ok
22:47:27.0609 0x08f4 [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys
22:47:27.0620 0x08f4 atapi - ok
22:47:27.0709 0x08f4 [ 0ACC06FCF46F64ED4F11E57EE461C1F4, F2AB7198C7F7D36AB1D6D03C1FEFD929ED402002AC835B909FC14938BC0EE24B ] athr C:\Windows\system32\DRIVERS\athrx.sys
22:47:27.0927 0x08f4 athr - ok
22:47:27.0972 0x08f4 [ 7910158929571214A959D5A6D16DD9C0, 9B4F8A3AF9E09B2F772EEF1CB8F7EAB8A226068784837F375AE97B89B0B3A383 ] ATKGFNEXSrv C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
22:47:27.0992 0x08f4 ATKGFNEXSrv - ok
22:47:28.0021 0x08f4 [ AC31727F9946E9009480708E4D1B9986, D1D5DC2A377D37483E10BF5F96D670712718BC27C753E86ABBB6C0708992E7C9 ] ATKWMIACPIIO C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys
22:47:28.0036 0x08f4 ATKWMIACPIIO - ok
22:47:28.0135 0x08f4 [ 2C1B6A64294F2182DC4999F923873974, 6D611636D849631BB1F852DC03A98BBFEC4D797A2707CA63427E187F0725A796 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:47:28.0234 0x08f4 AudioEndpointBuilder - ok
22:47:28.0257 0x08f4 [ 2C1B6A64294F2182DC4999F923873974, 6D611636D849631BB1F852DC03A98BBFEC4D797A2707CA63427E187F0725A796 ] AudioSrv C:\Windows\System32\Audiosrv.dll
22:47:28.0288 0x08f4 AudioSrv - ok
22:47:28.0343 0x08f4 [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll
22:47:28.0452 0x08f4 AxInstSV - ok
22:47:28.0538 0x08f4 [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
22:47:28.0638 0x08f4 b06bdrv - ok
22:47:28.0718 0x08f4 [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
22:47:28.0798 0x08f4 b57nd60a - ok
22:47:28.0867 0x08f4 [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll
22:47:28.0903 0x08f4 BDESVC - ok
22:47:28.0924 0x08f4 [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys
22:47:29.0010 0x08f4 Beep - ok
22:47:29.0108 0x08f4 [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll
22:47:29.0214 0x08f4 BFE - ok
22:47:29.0264 0x08f4 [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\system32\qmgr.dll
22:47:29.0464 0x08f4 BITS - ok
22:47:29.0511 0x08f4 [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
22:47:29.0554 0x08f4 blbdrive - ok
22:47:29.0949 0x08f4 [ 55B0C8441DE7D91A819A39D0351154A2, EA39144C82DB7F48D12042ED12701932C9339DA9E9AF002B09FF5E8101BC6047 ] Bluetooth Device Monitor C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
22:47:29.0986 0x08f4 Bluetooth Device Monitor - ok
22:47:30.0338 0x08f4 [ 7E262330DF0C4BE4ECE853B59B9CBE4C, 11397833838266425CB400B5A0F4379E1F23822D1E7BFBC898F7ABD88CC8DA9A ] Bluetooth Media Service C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
22:47:30.0384 0x08f4 Bluetooth Media Service - ok
22:47:30.0450 0x08f4 [ 8BF4B9956E13871A88A3810074E2E110, CB76A83C02904675A28E6E3C29FA6FC3969C1012B6528FF0B0A55036E2E73AF7 ] Bluetooth OBEX Service C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
22:47:30.0497 0x08f4 Bluetooth OBEX Service - ok
22:47:30.0573 0x08f4 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
22:47:30.0599 0x08f4 Bonjour Service - ok
22:47:30.0647 0x08f4 [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:47:30.0678 0x08f4 bowser - ok
22:47:30.0707 0x08f4 brdzkxcp - ok
22:47:30.0743 0x08f4 [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
22:47:30.0851 0x08f4 BrFiltLo - ok
22:47:30.0860 0x08f4 [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
22:47:30.0900 0x08f4 BrFiltUp - ok
22:47:30.0974 0x08f4 [ 5C2F352A4E961D72518261257AAE204B, 9EE1001E1D46A414A7A86FE1DBBE232203E26F54D9EF43ED31ED8EACD4D09853 ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
22:47:31.0034 0x08f4 BridgeMP - ok
22:47:31.0139 0x08f4 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll
22:47:31.0200 0x08f4 Browser - ok
22:47:31.0215 0x08f4 [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys
22:47:31.0274 0x08f4 Brserid - ok
22:47:31.0280 0x08f4 [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
22:47:31.0316 0x08f4 BrSerWdm - ok
22:47:31.0337 0x08f4 [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
22:47:31.0352 0x08f4 BrUsbMdm - ok
22:47:31.0357 0x08f4 [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
22:47:31.0391 0x08f4 BrUsbSer - ok
22:47:31.0429 0x08f4 [ CF98190A94F62E405C8CB255018B2315, E1B2540023C4FE9FD588E4B6AE6347DFA565EB3898F21E5360882BF3E8B5E781 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
22:47:31.0486 0x08f4 BthEnum - ok
22:47:31.0525 0x08f4 [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
22:47:31.0565 0x08f4 BTHMODEM - ok
22:47:31.0589 0x08f4 [ 02DD601B708DD0667E1331FA8518E9FF, 7DE6CC4DBB621CD03B01D9CE6CF66EAFE31D39030A391562CD0E278E1D70ADE1 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
22:47:31.0638 0x08f4 BthPan - ok
22:47:31.0830 0x08f4 [ 738D0E9272F59EB7A1449C3EC118E6C4, FE3D32C2A5E4DC21376A0F89C0B2EE024ECF1A3FB99213CC9BBC986ADF7AF080 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
22:47:31.0908 0x08f4 BTHPORT - ok
22:47:31.0956 0x08f4 [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll
22:47:32.0017 0x08f4 bthserv - ok
22:47:32.0090 0x08f4 [ A5B3E8B2B78C7B3DA56A0DE490E6718C, 9AA06B18E55679358BE5BFA5D1F3FC1FD790FD74B48E4FFD6517C91734E009EF ] BTHSSecurityMgr C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
22:47:32.0103 0x08f4 BTHSSecurityMgr - ok
22:47:32.0130 0x08f4 [ F188B7394D81010767B6DF3178519A37, 576304E92FD94908F093A6AB5F4D328F25829BE32EC3CA0D29EBFDF5DE83539B ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
22:47:32.0167 0x08f4 BTHUSB - ok
22:47:32.0233 0x08f4 [ 0A6CD4C79C92EEC0FA60B1EEA2677B37, AE461DE7E0BA021A61FA61B6D5D9F0F1894BA47F9F840403D9C649665D8091FF ] btmaudio C:\Windows\system32\drivers\btmaud.sys
22:47:32.0255 0x08f4 btmaudio - ok
22:47:32.0314 0x08f4 [ 270FBA230E78E25726D065A924589A72, 9D68C51B0A5F969CE2700F6CD9D98DE224D9D67F43D599F07BDCEC020C890E79 ] btmaux C:\Windows\system32\DRIVERS\btmaux.sys
22:47:32.0371 0x08f4 btmaux - ok
22:47:32.0409 0x08f4 [ 0010A54571F525A97EED8C091E96EAA9, 6BA69BD0BEAFAF0385C53E2FEB3C7E19DA797C4C732F60600243F2B79B6CDC64 ] btmhsf C:\Windows\system32\DRIVERS\btmhsf.sys
22:47:32.0466 0x08f4 btmhsf - ok
22:47:32.0767 0x08f4 catchme - ok
22:47:32.0876 0x08f4 [ 555FA105C22B1616094EDAD1CBFB0551, 3DB8EB0F95589E8CC338AE033C314256296F0BF039B338CF023FE393CF80840C ] cbfs3 C:\Windows\system32\DRIVERS\cbfs3.sys
22:47:32.0923 0x08f4 cbfs3 - ok
22:47:32.0977 0x08f4 [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:47:33.0029 0x08f4 cdfs - ok
22:47:33.0134 0x08f4 [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
22:47:33.0166 0x08f4 cdrom - ok
22:47:33.0217 0x08f4 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll
22:47:33.0307 0x08f4 CertPropSvc - ok
22:47:33.0338 0x08f4 [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\drivers\circlass.sys
22:47:33.0375 0x08f4 circlass - ok
22:47:33.0495 0x08f4 [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS C:\Windows\system32\CLFS.sys
22:47:33.0530 0x08f4 CLFS - ok
22:47:33.0807 0x08f4 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:47:33.0838 0x08f4 clr_optimization_v2.0.50727_32 - ok
22:47:33.0871 0x08f4 [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:47:33.0891 0x08f4 clr_optimization_v2.0.50727_64 - ok
22:47:34.0065 0x08f4 [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:47:34.0090 0x08f4 clr_optimization_v4.0.30319_32 - ok
22:47:34.0183 0x08f4 [ 4AEDAB50F83580D0B4D6CF78191F92AA, D113C47013B018B45161911B96E93AF96A2F3B34FA47061BF6E7A71FBA03194A ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:47:34.0216 0x08f4 clr_optimization_v4.0.30319_64 - ok
22:47:34.0285 0x08f4 [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:47:34.0344 0x08f4 CmBatt - ok
22:47:34.0413 0x08f4 [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys
22:47:34.0442 0x08f4 cmdide - ok
22:47:34.0622 0x08f4 [ EBF28856F69CF094A902F884CF989706, AD6C9F0BC20AA49EEE5478DA0F856F0EA2B414B63208C5FFB03C9D7F5B59765F ] CNG C:\Windows\system32\Drivers\cng.sys
22:47:34.0690 0x08f4 CNG - ok
22:47:34.0726 0x08f4 [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
22:47:34.0737 0x08f4 Compbatt - ok
22:47:34.0779 0x08f4 [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
22:47:34.0815 0x08f4 CompositeBus - ok
22:47:34.0835 0x08f4 COMSysApp - ok
22:47:35.0157 0x08f4 [ 08F934092E0429BADF88E9F91DB0F61E, 6E9091C006FFFF261DC61C8E9A45219E47C351296E5355FC4B7242F30E1DDFE3 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
22:47:35.0251 0x08f4 cphs - ok
22:47:35.0276 0x08f4 [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
22:47:35.0288 0x08f4 crcdisk - ok
22:47:35.0352 0x08f4 [ 19D511CC455C19DE1ADF60E6C39C85B6, 2A05DD5EF3D0BEC2C9F4EA186E0E2D0F7BE0BF6A473D51194B09D33773AC7FAA ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:47:35.0422 0x08f4 CryptSvc - ok
22:47:35.0459 0x08f4 [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC C:\Windows\system32\drivers\csc.sys
22:47:35.0562 0x08f4 CSC - ok
22:47:35.0617 0x08f4 [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService C:\Windows\System32\cscsvc.dll
22:47:35.0679 0x08f4 CscService - ok
22:47:35.0749 0x08f4 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\Windows\system32\rpcss.dll
22:47:35.0818 0x08f4 DcomLaunch - ok
22:47:35.0872 0x08f4 [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll
22:47:35.0953 0x08f4 defragsvc - ok
22:47:35.0996 0x08f4 [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:47:36.0069 0x08f4 DfsC - ok
22:47:36.0109 0x08f4 [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll
22:47:36.0171 0x08f4 Dhcp - ok
22:47:36.0185 0x08f4 [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys
22:47:36.0220 0x08f4 discache - ok
22:47:36.0270 0x08f4 [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\Windows\system32\drivers\disk.sys
22:47:36.0283 0x08f4 Disk - ok
22:47:36.0297 0x08f4 [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys
22:47:36.0358 0x08f4 dmvsc - ok
22:47:36.0422 0x08f4 [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:47:36.0505 0x08f4 Dnscache - ok
22:47:36.0583 0x08f4 [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll
22:47:36.0629 0x08f4 dot3svc - ok
22:47:36.0681 0x08f4 [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll
22:47:36.0745 0x08f4 DPS - ok
22:47:36.0826 0x08f4 [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:47:36.0899 0x08f4 drmkaud - ok
22:47:37.0002 0x08f4 [ 87CE5C8965E101CCCED1F4675557E868, 077D98F0F130B2FC710208BA34016EF2B2506EE2BD71740B228145E34A3046F1 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:47:37.0060 0x08f4 DXGKrnl - ok
22:47:37.0093 0x08f4 [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll
22:47:37.0152 0x08f4 EapHost - ok
22:47:37.0460 0x08f4 [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\drivers\evbda.sys
22:47:37.0648 0x08f4 ebdrv - ok
22:47:37.0689 0x08f4 [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] EFS C:\Windows\System32\lsass.exe
22:47:37.0765 0x08f4 EFS - ok
22:47:37.0956 0x08f4 [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
22:47:38.0087 0x08f4 ehRecvr - ok
22:47:38.0117 0x08f4 [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe
22:47:38.0152 0x08f4 ehSched - ok
22:47:38.0340 0x08f4 [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\drivers\elxstor.sys
22:47:38.0382 0x08f4 elxstor - ok
22:47:38.0696 0x08f4 [ ABDD5AD016AFFD34AD40E944CE94BF59, 61089124CD8FEA31142CD4D3C47224A6310B9BE7B7FA974956D9EDDAD4381503 ] EpsonBidirectionalService C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
22:47:38.0732 0x08f4 EpsonBidirectionalService - detected UnsignedFile.Multi.Generic ( 1 )
22:47:41.0173 0x08f4 Detect skipped due to KSN trusted
22:47:41.0173 0x08f4 EpsonBidirectionalService - ok
22:47:41.0250 0x08f4 [ 20ECD0A490A121CB34F553FAD1DBBD39, 17C9DA33E78FBC7582B0AA53C611929B80FBBE1343B84A179D515B51C964D218 ] EpsonScanSvc C:\Windows\system32\EscSvc64.exe
22:47:41.0280 0x08f4 EpsonScanSvc - ok
22:47:41.0504 0x08f4 [ 194E8100D57FC13BEF88129BAAD07E46, 745D24ADD99ED182FCCA30C6B85167484B74D3EFD631AF92AA57AAD73F474631 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
22:47:41.0532 0x08f4 EPSON_PM_RPCV4_04 - ok
22:47:41.0553 0x08f4 [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys
22:47:41.0604 0x08f4 ErrDev - ok
22:47:41.0676 0x08f4 [ 871AB1BFA00ECA5DFDE99D6EECE1BFD4, 3C84D241B6275CA9A89685945DD7346B69C9D57E2859F34D98BF247B0309EB03 ] ETD C:\Windows\system32\DRIVERS\ETD.sys
22:47:41.0699 0x08f4 ETD - ok
22:47:41.0755 0x08f4 [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll
22:47:41.0845 0x08f4 EventSystem - ok
22:47:42.0435 0x08f4 [ 54FC81B0162478A72A93DBBEAFB35671, 1C0FA242E81105E2BB839ED32119DAF012FA4A3DB5D0E079350449CBB0CBF033 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
22:47:42.0492 0x08f4 EvtEng - ok
22:47:42.0591 0x08f4 [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys
22:47:42.0665 0x08f4 exfat - ok
22:47:42.0701 0x08f4 [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:47:42.0774 0x08f4 fastfat - ok
22:47:42.0905 0x08f4 [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe
22:47:43.0018 0x08f4 Fax - ok
22:47:43.0061 0x08f4 [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\drivers\fdc.sys
22:47:43.0084 0x08f4 fdc - ok
22:47:43.0181 0x08f4 [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll
22:47:43.0274 0x08f4 fdPHost - ok
22:47:43.0332 0x08f4 [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll
22:47:43.0389 0x08f4 FDResPub - ok
22:47:43.0425 0x08f4 [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:47:43.0438 0x08f4 FileInfo - ok
22:47:43.0457 0x08f4 [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:47:43.0524 0x08f4 Filetrace - ok
22:47:43.0585 0x08f4 [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
22:47:43.0597 0x08f4 flpydisk - ok
22:47:43.0645 0x08f4 [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:47:43.0664 0x08f4 FltMgr - ok
22:47:43.0779 0x08f4 [ C4C183E6551084039EC862DA1C945E3D, 0874A2ACDD24D64965AA9A76E9C818E216880AE4C9A2E07ED932EE404585CEE6 ] FontCache C:\Windows\system32\FntCache.dll
22:47:43.0914 0x08f4 FontCache - ok
22:47:43.0973 0x08f4 [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:47:43.0982 0x08f4 FontCache3.0.0.0 - ok
22:47:44.0000 0x08f4 [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
22:47:44.0015 0x08f4 FsDepends - ok
22:47:44.0106 0x08f4 [ 6C06701BF1DB05405804D7EB610991CE, 75DEB2204D9AC338ED7C4742BEFAFA0AFC7E42B2C1B54A57DF8A1AD097D9EC3E ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
22:47:44.0118 0x08f4 fssfltr - ok
22:47:44.0343 0x08f4 [ 4CE9DAC1518FF7E77BD213E6394B9D77, D7D0D29DF93AC7DC5F85E385EEB45306C7BD87ACA7AAC5A8D47893D120C32C03 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
22:47:44.0399 0x08f4 fsssvc - ok
22:47:44.0476 0x08f4 [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:47:44.0507 0x08f4 Fs_Rec - ok
22:47:44.0638 0x08f4 [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
22:47:44.0668 0x08f4 fvevol - ok
22:47:44.0752 0x08f4 [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
22:47:44.0785 0x08f4 gagp30kx - ok
22:47:44.0885 0x08f4 [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
22:47:44.0902 0x08f4 GEARAspiWDM - ok
22:47:44.0958 0x08f4 [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\Windows\System32\gpsvc.dll
22:47:45.0155 0x08f4 gpsvc - ok
22:47:45.0201 0x08f4 gucgznbc - ok
22:47:45.0325 0x08f4 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:47:45.0344 0x08f4 gupdate - ok
22:47:45.0353 0x08f4 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:47:45.0364 0x08f4 gupdatem - ok
22:47:45.0429 0x08f4 [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
22:47:45.0499 0x08f4 hcw85cir - ok
22:47:45.0578 0x08f4 [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:47:45.0636 0x08f4 HdAudAddService - ok
22:47:45.0670 0x08f4 [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
22:47:45.0727 0x08f4 HDAudBus - ok
22:47:45.0736 0x08f4 [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
22:47:45.0790 0x08f4 HidBatt - ok
22:47:45.0821 0x08f4 [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\drivers\hidbth.sys
22:47:45.0846 0x08f4 HidBth - ok
22:47:45.0867 0x08f4 [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\drivers\hidir.sys
22:47:45.0908 0x08f4 HidIr - ok
22:47:45.0945 0x08f4 [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\System32\hidserv.dll
22:47:46.0004 0x08f4 hidserv - ok
22:47:46.0054 0x08f4 [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\drivers\hidusb.sys
22:47:46.0089 0x08f4 HidUsb - ok
22:47:46.0111 0x08f4 [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll
22:47:46.0176 0x08f4 hkmsvc - ok
22:47:46.0208 0x08f4 [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:47:46.0286 0x08f4 HomeGroupListener - ok
22:47:46.0315 0x08f4 [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:47:46.0358 0x08f4 HomeGroupProvider - ok
22:47:46.0393 0x08f4 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
22:47:46.0409 0x08f4 HpSAMD - ok
22:47:46.0473 0x08f4 [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:47:46.0562 0x08f4 HTTP - ok
22:47:46.0598 0x08f4 [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
22:47:46.0609 0x08f4 hwpolicy - ok
22:47:46.0652 0x08f4 [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
22:47:46.0677 0x08f4 i8042prt - ok
22:47:46.0827 0x08f4 [ 26CF4275034214ECEDD8EC17B0A18A99, 95A08C63971C28F1BC97040C0ADA247E3B43DE7D937B14E33A394B955D0AC8B7 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
22:47:46.0857 0x08f4 iaStor - ok
22:47:46.0930 0x08f4 [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
22:47:46.0962 0x08f4 iaStorV - ok
22:47:47.0009 0x08f4 [ DE9E40BAEE2E48FD1E3EB423074C014C, 33F0738F8E0C803C025E72401E9A3A5B54E5256BFF18CEE6D913EB65E8003D2B ] iBtFltCoex C:\Windows\system32\DRIVERS\iBtFltCoex.sys
22:47:47.0053 0x08f4 iBtFltCoex - ok
22:47:47.0399 0x08f4 [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:47:47.0440 0x08f4 idsvc - ok
22:47:47.0477 0x08f4 IEEtwCollectorService - ok
22:47:48.0074 0x08f4 [ 8C44E6B688790E2AD3846C97661C54F1, CB487D167EDA3C1E30BD5FB8F98C15EB9E75A6FB793009C2F1BBCAAB4285F772 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
22:47:48.0341 0x08f4 igfx - ok
22:47:48.0380 0x08f4 [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\drivers\iirsp.sys
22:47:48.0392 0x08f4 iirsp - ok
22:47:48.0659 0x08f4 [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT C:\Windows\System32\ikeext.dll
22:47:48.0699 0x08f4 IKEEXT - ok
22:47:48.0706 0x08f4 inqltdso - ok
22:47:48.0956 0x08f4 [ 9F573C952961F444F400489E81ECA381, FA390CA173A2C67C7DB37B7F386CE6B91B160C5BAEE3DD1BDCC17A0B49F7A61B ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
22:47:49.0106 0x08f4 IntcAzAudAddService - ok
22:47:49.0306 0x08f4 [ FC727061C0F47C8059E88E05D5C8E381, C7A3782F5D86C7FDE57AA1F2EE81638C5FC3072ACC6E572BA2EC7B3CFF389800 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
22:47:49.0374 0x08f4 IntcDAud - ok
22:47:49.0404 0x08f4 [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys
22:47:49.0421 0x08f4 intelide - ok
22:47:49.0474 0x08f4 [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:47:49.0501 0x08f4 intelppm - ok
22:47:49.0569 0x08f4 [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:47:49.0619 0x08f4 IPBusEnum - ok
22:47:49.0634 0x08f4 [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:47:49.0715 0x08f4 IpFilterDriver - ok
22:47:49.0835 0x08f4 [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:47:49.0949 0x08f4 iphlpsvc - ok
22:47:49.0987 0x08f4 [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
22:47:50.0064 0x08f4 IPMIDRV - ok
22:47:50.0111 0x08f4 [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys
22:47:50.0184 0x08f4 IPNAT - ok
22:47:50.0481 0x08f4 [ 7FAE5B6CDB18B0B2E81F32869F595022, D873A7EE94749E1700E8F6B8BB7B485AE1B0B83388D63BE06335720498D4794F ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
22:47:50.0516 0x08f4 iPod Service - ok
22:47:50.0553 0x08f4 [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:47:50.0649 0x08f4 IRENUM - ok
22:47:50.0700 0x08f4 [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys
22:47:50.0726 0x08f4 isapnp - ok
22:47:50.0773 0x08f4 [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
22:47:50.0792 0x08f4 iScsiPrt - ok
22:47:50.0823 0x08f4 [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
22:47:50.0835 0x08f4 kbdclass - ok
22:47:50.0853 0x08f4 [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
22:47:50.0884 0x08f4 kbdhid - ok
22:47:50.0929 0x08f4 [ E63EF8C3271D014F14E2469CE75FECB4, 3A8DFA4B446AFDC35F01FD5218D0BEBC510A1E3DE9976210F00D19767D0F9069 ] kbfiltr C:\Windows\system32\DRIVERS\kbfiltr.sys
22:47:50.0938 0x08f4 kbfiltr - ok
22:47:50.0967 0x08f4 [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] KeyIso C:\Windows\system32\lsass.exe
22:47:50.0979 0x08f4 KeyIso - ok
22:47:51.0035 0x08f4 [ 353009DEDF918B2A51414F330CF72DEC, BF157D6E329F26E02FA16271B751B421396040DBB1D7BF9B2E0A21BC569672E2 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:47:51.0062 0x08f4 KSecDD - ok
22:47:51.0150 0x08f4 [ 1C2D8E18AA8FD50CD04C15CC27F7F5AB, 4BA3B0F9F01BD47D66091D3AD86B69A523981D61DFB4D677F2CD39405B2DA989 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
22:47:51.0180 0x08f4 KSecPkg - ok
22:47:51.0211 0x08f4 [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
22:47:51.0272 0x08f4 ksthunk - ok
22:47:51.0358 0x08f4 [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll
22:47:51.0407 0x08f4 KtmRm - ok
22:47:51.0459 0x08f4 [ 655A5D8E80869781CCE23760ADA7E695, 86DA2FC5DBA28762A89BC70D9DA0F370FC4A9F4F28E6802AD5972C387F4EEFD3 ] L1C C:\Windows\system32\DRIVERS\L1C62x64.sys
22:47:51.0475 0x08f4 L1C - ok
22:47:51.0512 0x08f4 laaolckg - ok
22:47:51.0556 0x08f4 [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\System32\srvsvc.dll
22:47:51.0628 0x08f4 LanmanServer - ok
22:47:51.0679 0x08f4 [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:47:51.0788 0x08f4 LanmanWorkstation - ok
22:47:51.0834 0x08f4 [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:47:51.0909 0x08f4 lltdio - ok
22:47:51.0946 0x08f4 [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:47:51.0990 0x08f4 lltdsvc - ok
22:47:52.0017 0x08f4 [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll
22:47:52.0072 0x08f4 lmhosts - ok
22:47:52.0314 0x08f4 [ 7F32D4C47A50E7223491E8FB9359907D, 6D3F59A8D006BED3234697933D09C8EE8F7A9F4A4196CFA878F8E8A929B24CE5 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:47:52.0344 0x08f4 LMS - ok
22:47:52.0385 0x08f4 [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
22:47:52.0399 0x08f4 LSI_FC - ok
22:47:52.0405 0x08f4 [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
22:47:52.0418 0x08f4 LSI_SAS - ok
22:47:52.0426 0x08f4 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
22:47:52.0438 0x08f4 LSI_SAS2 - ok
22:47:52.0447 0x08f4 [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
22:47:52.0460 0x08f4 LSI_SCSI - ok
22:47:52.0492 0x08f4 [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys
22:47:52.0529 0x08f4 luafv - ok
22:47:52.0605 0x08f4 [ 0C85B2B6FB74B36A251792D45E0EF860, 2E04204560C1159ABC25F273B0B7F81FDF9BA5E88C17929FD924C4E945DE5020 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys
22:47:52.0631 0x08f4 LVRS64 - ok
22:47:53.0149 0x08f4 [ FF3A488924B0032B1A9CA6948C1FA9E8, 6F05852B75498210926F5CDF49D2A6DD97C39CD93D32E3200D7240AADA3E7BEE ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys
22:47:53.0396 0x08f4 LVUVC64 - ok
22:47:53.0460 0x08f4 lxdu_device - ok
22:47:53.0469 0x08f4 lxukkwfx - ok
22:47:53.0550 0x08f4 [ 922CBAC7B992B9614CAB7122F4BF9406, CD6FFA2DE518DFD92604F1C6E3D274566410BEE02B6F3D575F2218EA4E165321 ] ManyCam C:\Windows\system32\DRIVERS\mcvidrv_x64.sys
22:47:53.0618 0x08f4 ManyCam - ok
22:47:53.0682 0x08f4 [ FAA4F845D478F4CEDF95981AFF859712, B7A8E2C6D26148DF34179A195FD7B73D830E5B729DD7D3A8C467634211FF5B77 ] massfilter C:\Windows\system32\drivers\massfilter.sys
22:47:53.0750 0x08f4 massfilter - ok
22:47:53.0790 0x08f4 [ 34A42DD7CF525D0D2C5232916496E4B8, FC703E247FB5D88470F57BCC10890F830BDE782BF7D24B12B2EAAB2C5EC23223 ] mcaudrv_simple C:\Windows\system32\drivers\mcaudrv_x64.sys
22:47:53.0838 0x08f4 mcaudrv_simple - ok
22:47:53.0874 0x08f4 [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
22:47:53.0899 0x08f4 Mcx2Svc - ok
22:47:53.0962 0x08f4 [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\drivers\megasas.sys
22:47:53.0992 0x08f4 megasas - ok
22:47:54.0017 0x08f4 [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
22:47:54.0039 0x08f4 MegaSR - ok
22:47:54.0094 0x08f4 [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
22:47:54.0106 0x08f4 MEIx64 - ok
22:47:54.0282 0x08f4 [ 123271BD5237AB991DC5C21FDF8835EB, 004F8F9228EE291A0E36CE33078D572D61733516F9AA5CFC832AF204C6869E89 ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
22:47:54.0312 0x08f4 Microsoft Office Groove Audit Service - ok
22:47:54.0346 0x08f4 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll
22:47:54.0417 0x08f4 MMCSS - ok
22:47:54.0445 0x08f4 [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys
22:47:54.0480 0x08f4 Modem - ok
22:47:54.0509 0x08f4 [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:47:54.0559 0x08f4 monitor - ok
22:47:54.0593 0x08f4 [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:47:54.0607 0x08f4 mouclass - ok
22:47:54.0647 0x08f4 [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
22:47:54.0662 0x08f4 mouhid - ok
22:47:54.0675 0x08f4 [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
22:47:54.0689 0x08f4 mountmgr - ok
22:47:54.0786 0x08f4 [ DEA022193DF8C88F6E2B3E33D148A5DB, 97DFC47DB83E04A975A1969AA120385463FCAF4E1A9984FD3220442D7026B45A ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:47:54.0810 0x08f4 MozillaMaintenance - ok
22:47:54.0914 0x08f4 [ 6439D1E559D08BD8A1465A8943357053, 0E300508C22D12FBA3BE566B722F574CBE1B4A1A305356B92B8EA8B86267071B ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
22:47:54.0945 0x08f4 MpFilter - ok
22:47:55.0029 0x08f4 [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys
22:47:55.0055 0x08f4 mpio - ok
22:47:55.0139 0x08f4 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:47:55.0208 0x08f4 mpsdrv - ok
22:47:55.0418 0x08f4 [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll
22:47:55.0481 0x08f4 MpsSvc - ok
22:47:55.0523 0x08f4 [ 1A4F75E63C9FB84B85DFFC6B63FD5404, 01AFA6DBB4CDE55FE4EA05BBE8F753A4266F8D072EA1EE01DB79F5126780C21F ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:47:55.0591 0x08f4 MRxDAV - ok
22:47:55.0689 0x08f4 [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:47:55.0755 0x08f4 mrxsmb - ok
22:47:55.0913 0x08f4 [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:47:55.0952 0x08f4 mrxsmb10 - ok
22:47:55.0986 0x08f4 [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:47:56.0001 0x08f4 mrxsmb20 - ok
22:47:56.0069 0x08f4 [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys
22:47:56.0096 0x08f4 msahci - ok
22:47:56.0176 0x08f4 [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys
22:47:56.0205 0x08f4 msdsm - ok
22:47:56.0288 0x08f4 [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe
22:47:56.0318 0x08f4 MSDTC - ok
22:47:56.0341 0x08f4 [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:47:56.0412 0x08f4 Msfs - ok
22:47:56.0436 0x08f4 [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
22:47:56.0518 0x08f4 mshidkmdf - ok
22:47:56.0544 0x08f4 [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
22:47:56.0554 0x08f4 msisadrv - ok
22:47:56.0607 0x08f4 [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:47:56.0694 0x08f4 MSiSCSI - ok
22:47:56.0698 0x08f4 msiserver - ok
22:47:56.0719 0x08f4 [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:47:56.0772 0x08f4 MSKSSRV - ok
22:47:56.0914 0x08f4 [ F0D5494D8B177C37E16966262F5D0F68, DD63427DFFD9DD2BEC8336F6AD1BEFE347012331631DC5FEC65E83B1EACDBC67 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
22:47:56.0940 0x08f4 MsMpSvc - ok
22:47:56.0989 0x08f4 [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:47:57.0043 0x08f4 MSPCLOCK - ok
22:47:57.0062 0x08f4 [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:47:57.0096 0x08f4 MSPQM - ok
22:47:57.0169 0x08f4 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:47:57.0200 0x08f4 MsRPC - ok
22:47:57.0223 0x08f4 [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
22:47:57.0234 0x08f4 mssmbios - ok
22:47:57.0263 0x08f4 [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:47:57.0297 0x08f4 MSTEE - ok
22:47:57.0330 0x08f4 [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
22:47:57.0342 0x08f4 MTConfig - ok
22:47:57.0381 0x08f4 [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys
22:47:57.0395 0x08f4 Mup - ok
22:47:57.0540 0x08f4 [ 4BBB9D9C4DF259FAE2D172C5BB25DDD0, 165EE2AB6F989E8D48AA52121B608510E932106835DA43071CC6476630C012FE ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
22:47:57.0573 0x08f4 MyWiFiDHCPDNS - ok
22:47:57.0612 0x08f4 [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll
22:47:57.0676 0x08f4 napagent - ok
22:47:57.0765 0x08f4 [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:47:57.0819 0x08f4 NativeWifiP - ok
22:47:57.0900 0x08f4 [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS C:\Windows\system32\drivers\ndis.sys
22:47:57.0951 0x08f4 NDIS - ok
22:47:57.0987 0x08f4 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
22:47:58.0024 0x08f4 NdisCap - ok
22:47:58.0080 0x08f4 [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:47:58.0114 0x08f4 NdisTapi - ok
22:47:58.0147 0x08f4 [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:47:58.0182 0x08f4 Ndisuio - ok
22:47:58.0215 0x08f4 [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:47:58.0274 0x08f4 NdisWan - ok
22:47:58.0320 0x08f4 [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:47:58.0377 0x08f4 NDProxy - ok
22:47:58.0497 0x08f4 [ D5AC41AE382738483FAFFBD7E373D49A, 68793D15566F387650E9C5010E1CA73BDE3EB4BA431EA0A1673004CAE08413B0 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
22:47:58.0536 0x08f4 Net Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
22:48:00.0963 0x08f4 Detect skipped due to KSN trusted
22:48:00.0963 0x08f4 Net Driver HPZ12 - ok
22:48:01.0023 0x08f4 [ EE00C544C025958AF50C7B199F3C8595, D774DB020D9C46D1AA0B2DB9FA2C36C4A9C38D904CC6929695321D32ACA0D4D1 ] Netaapl C:\Windows\system32\DRIVERS\netaapl64.sys
22:48:01.0092 0x08f4 Netaapl - ok
22:48:01.0138 0x08f4 [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:48:01.0223 0x08f4 NetBIOS - ok
22:48:01.0303 0x08f4 [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
22:48:01.0355 0x08f4 NetBT - ok
22:48:01.0377 0x08f4 [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] Netlogon C:\Windows\system32\lsass.exe
22:48:01.0389 0x08f4 Netlogon - ok
22:48:01.0452 0x08f4 [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\Windows\System32\netman.dll
22:48:01.0543 0x08f4 Netman - ok
22:48:01.0838 0x08f4 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:48:01.0867 0x08f4 NetMsmqActivator - ok
22:48:01.0876 0x08f4 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:48:01.0893 0x08f4 NetPipeActivator - ok
22:48:01.0910 0x08f4 [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\Windows\System32\netprofm.dll
22:48:01.0968 0x08f4 netprofm - ok
22:48:01.0992 0x08f4 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:48:02.0008 0x08f4 NetTcpActivator - ok
22:48:02.0014 0x08f4 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:48:02.0029 0x08f4 NetTcpPortSharing - ok
22:48:02.0830 0x08f4 [ AC69618DE5BCCE8747C9AB0AAE1003C1, D975963FA338AB58684BE0556633F3A846D5360FAD1A5E11BB7A273474DFB64D ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys
22:48:03.0227 0x08f4 NETwNs64 - ok
22:48:03.0298 0x08f4 [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
22:48:03.0310 0x08f4 nfrd960 - ok
22:48:03.0402 0x08f4 [ F9EEFFC65C68A45001D1349E652B8B6F, E5F223129416083A12A85D48C65B2C8D1BF1124110399938E144308C89F9241D ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
22:48:03.0432 0x08f4 NisDrv - ok
22:48:03.0619 0x08f4 [ 9690F420A99364C1E5C439914B0DE25C, 6C6E0B27C4255001FE5F1EAD911DE1A8BF922C405B0C8031A6BD253CEB1D02A6 ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
22:48:03.0647 0x08f4 NisSrv - ok
22:48:03.0810 0x08f4 [ 8AD77806D336673F270DB31645267293, E23F324913554A23CD043DD27D4305AF62F48C0561A0FC7B7811E55B74B1BE79 ] NlaSvc C:\Windows\System32\nlasvc.dll
22:48:03.0850 0x08f4 NlaSvc - ok
22:48:03.0897 0x08f4 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:48:03.0948 0x08f4 Npfs - ok
22:48:03.0978 0x08f4 [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\Windows\system32\nsisvc.dll
22:48:04.0013 0x08f4 nsi - ok
22:48:04.0033 0x08f4 [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:48:04.0068 0x08f4 nsiproxy - ok
22:48:04.0340 0x08f4 [ 1A29A59A4C5BA6F8C85062A613B7E2B2, CC137F499A12C724D4166C2D85E9F447413419A0683DAC6F1A802B7F210C77F1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:48:04.0401 0x08f4 Ntfs - ok
22:48:04.0458 0x08f4 [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\Windows\system32\drivers\Null.sys
22:48:04.0492 0x08f4 Null - ok
22:48:04.0540 0x08f4 [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\Windows\system32\drivers\nvraid.sys
22:48:04.0563 0x08f4 nvraid - ok
22:48:04.0629 0x08f4 [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\Windows\system32\drivers\nvstor.sys
22:48:04.0657 0x08f4 nvstor - ok
22:48:04.0706 0x08f4 [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
22:48:04.0729 0x08f4 nv_agp - ok
22:48:05.0008 0x08f4 [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:48:05.0042 0x08f4 odserv - ok
22:48:05.0048 0x08f4 [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
22:48:05.0118 0x08f4 ohci1394 - ok
22:48:05.0208 0x08f4 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:48:05.0242 0x08f4 ose - ok
22:48:05.0286 0x08f4 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
22:48:05.0322 0x08f4 p2pimsvc - ok
22:48:05.0482 0x08f4 [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\Windows\system32\p2psvc.dll
22:48:05.0541 0x08f4 p2psvc - ok
22:48:05.0584 0x08f4 [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\Windows\system32\drivers\parport.sys
22:48:05.0632 0x08f4 Parport - ok
22:48:05.0699 0x08f4 [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr C:\Windows\system32\drivers\partmgr.sys
22:48:05.0730 0x08f4 partmgr - ok
22:48:05.0823 0x08f4 [ 256390425414F90FCBC12F525A84EB11, A4992020BF6A239AD8A77125426E2C39980C9ABC971C4DBCB24B358F946AD7F9 ] PcaSvc C:\Windows\System32\pcasvc.dll
22:48:05.0906 0x08f4 PcaSvc - ok
22:48:05.0982 0x08f4 [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci C:\Windows\system32\drivers\pci.sys
22:48:06.0023 0x08f4 pci - ok
22:48:06.0081 0x08f4 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\Windows\system32\drivers\pciide.sys
22:48:06.0108 0x08f4 pciide - ok
22:48:06.0140 0x08f4 [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
22:48:06.0160 0x08f4 pcmcia - ok
22:48:06.0207 0x08f4 [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\Windows\system32\drivers\pcw.sys
22:48:06.0236 0x08f4 pcw - ok
22:48:06.0295 0x08f4 [ 946010CDFA91469351B22E2620CEBCD8, F099C92706D42ADC289B72724F7932E5D4F62A427AEC967DDB0A1D728AE59A63 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
22:48:06.0405 0x08f4 PEAUTH - ok
22:48:06.0761 0x08f4 [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
22:48:06.0846 0x08f4 PeerDistSvc - ok
22:48:07.0082 0x08f4 [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\Windows\SysWow64\perfhost.exe
22:48:07.0111 0x08f4 PerfHost - ok
22:48:07.0267 0x08f4 [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\Windows\system32\pla.dll
22:48:07.0363 0x08f4 pla - ok
22:48:07.0552 0x08f4 [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
22:48:07.0607 0x08f4 PlugPlay - ok
22:48:07.0667 0x08f4 [ 37F6046CDC630442D7DC087501FF6FC6, EFC0F3DA49839CA263CD95AE5015F4FC554D9D845A58A699C542C8C96E70ED3C ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
22:48:07.0727 0x08f4 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
22:48:10.0162 0x08f4 Detect skipped due to KSN trusted
22:48:10.0162 0x08f4 Pml Driver HPZ12 - ok
22:48:10.0204 0x08f4 [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
22:48:10.0258 0x08f4 PNRPAutoReg - ok
22:48:10.0298 0x08f4 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
22:48:10.0322 0x08f4 PNRPsvc - ok
22:48:10.0484 0x08f4 [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
22:48:10.0548 0x08f4 PolicyAgent - ok
22:48:10.0596 0x08f4 [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power C:\Windows\system32\umpo.dll
22:48:10.0685 0x08f4 Power - ok
22:48:10.0745 0x08f4 [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
22:48:10.0800 0x08f4 PptpMiniport - ok
22:48:10.0876 0x08f4 [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\Windows\system32\drivers\processr.sys
22:48:10.0902 0x08f4 Processor - ok
22:48:10.0955 0x08f4 [ 53E83F1F6CF9D62F32801CF66D8352A8, 1225FED810BE8E0729EEAE5B340035CCBB9BACD3EF247834400F9B72D05ACE48 ] ProfSvc C:\Windows\system32\profsvc.dll
22:48:10.0996 0x08f4 ProfSvc - ok
22:48:11.0010 0x08f4 [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] ProtectedStorage C:\Windows\system32\lsass.exe
22:48:11.0023 0x08f4 ProtectedStorage - ok
22:48:11.0048 0x08f4 [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
22:48:11.0084 0x08f4 Psched - ok
22:48:11.0287 0x08f4 [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
22:48:11.0344 0x08f4 ql2300 - ok
22:48:11.0352 0x08f4 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
22:48:11.0366 0x08f4 ql40xx - ok
22:48:11.0443 0x08f4 [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\Windows\system32\qwave.dll
22:48:11.0477 0x08f4 QWAVE - ok
22:48:11.0503 0x08f4 [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
22:48:11.0541 0x08f4 QWAVEdrv - ok
22:48:11.0688 0x08f4 [ A55E7D0D873B2C97585B3B5926AC6ADE, 3BE3895DA7F0888E85B1941525878BA0846A8F215AD39ED8138BB39615468E32 ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
22:48:11.0716 0x08f4 RapiMgr - ok
22:48:11.0722 0x08f4 [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
22:48:11.0772 0x08f4 RasAcd - ok
22:48:11.0821 0x08f4 [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
22:48:11.0907 0x08f4 RasAgileVpn - ok
22:48:11.0932 0x08f4 [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\Windows\System32\rasauto.dll
22:48:11.0970 0x08f4 RasAuto - ok
22:48:12.0002 0x08f4 [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
22:48:12.0058 0x08f4 Rasl2tp - ok
22:48:12.0197 0x08f4 [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\Windows\System32\rasmans.dll
22:48:12.0267 0x08f4 RasMan - ok
22:48:12.0312 0x08f4 [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
22:48:12.0368 0x08f4 RasPppoe - ok
22:48:12.0410 0x08f4 [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
22:48:12.0462 0x08f4 RasSstp - ok
22:48:12.0539 0x08f4 [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
22:48:12.0600 0x08f4 rdbss - ok
22:48:12.0657 0x08f4 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
22:48:12.0689 0x08f4 rdpbus - ok
22:48:12.0708 0x08f4 [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
22:48:12.0742 0x08f4 RDPCDD - ok
22:48:12.0816 0x08f4 [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
22:48:12.0880 0x08f4 RDPDR - ok
22:48:12.0894 0x08f4 [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
22:48:12.0973 0x08f4 RDPENCDD - ok
22:48:12.0986 0x08f4 [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
22:48:13.0036 0x08f4 RDPREFMP - ok
22:48:13.0121 0x08f4 [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
22:48:13.0199 0x08f4 RdpVideoMiniport - ok
22:48:13.0308 0x08f4 [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
22:48:13.0373 0x08f4 RDPWD - ok
22:48:13.0474 0x08f4 [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
22:48:13.0503 0x08f4 rdyboost - ok
22:48:13.0729 0x08f4 [ A436F5E7D80BBDBB0826D0F176D5BEA8, 7862CE61F182C7613E34415C01AC1C228F79A45470CFD1D316DF2BD24EE09E3C ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
22:48:13.0795 0x08f4 RegSrvc - ok
22:48:13.0884 0x08f4 [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\Windows\System32\mprdim.dll
22:48:13.0937 0x08f4 RemoteAccess - ok
22:48:14.0003 0x08f4 [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\Windows\system32\regsvc.dll
22:48:14.0048 0x08f4 RemoteRegistry - ok
22:48:14.0085 0x08f4 [ 3DD798846E2C28102B922C56E71B7932, 30B111615D74CB2213997A5C08DD9C8613ADE441D9423CC1C49A753D13CE524D ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
22:48:14.0124 0x08f4 RFCOMM - ok
22:48:14.0161 0x08f4 [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
22:48:14.0213 0x08f4 RpcEptMapper - ok
22:48:14.0267 0x08f4 [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\Windows\system32\locator.exe
22:48:14.0281 0x08f4 RpcLocator - ok
22:48:14.0310 0x08f4 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs C:\Windows\system32\rpcss.dll
22:48:14.0357 0x08f4 RpcSs - ok
22:48:14.0415 0x08f4 [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
22:48:14.0503 0x08f4 rspndr - ok
22:48:14.0516 0x08f4 [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap C:\Windows\system32\drivers\vms3cap.sys
22:48:14.0567 0x08f4 s3cap - ok
22:48:14.0588 0x08f4 [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] SamSs C:\Windows\system32\lsass.exe
22:48:14.0605 0x08f4 SamSs - ok
22:48:14.0672 0x08f4 [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
22:48:14.0698 0x08f4 sbp2port - ok
22:48:14.0772 0x08f4 [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\Windows\System32\SCardSvr.dll
22:48:14.0829 0x08f4 SCardSvr - ok
22:48:14.0888 0x08f4 [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
22:48:14.0923 0x08f4 scfilter - ok
22:48:14.0972 0x08f4 [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule C:\Windows\system32\schedsvc.dll
22:48:15.0077 0x08f4 Schedule - ok
22:48:15.0128 0x08f4 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\Windows\System32\certprop.dll
22:48:15.0183 0x08f4 SCPolicySvc - ok
22:48:15.0253 0x08f4 [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\Windows\System32\SDRSVC.dll
22:48:15.0303 0x08f4 SDRSVC - ok
22:48:15.0315 0x08f4 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys
22:48:15.0365 0x08f4 secdrv - ok
22:48:15.0384 0x08f4 [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon C:\Windows\system32\seclogon.dll
22:48:15.0444 0x08f4 seclogon - ok
22:48:15.0468 0x08f4 [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\Windows\system32\sens.dll
22:48:15.0505 0x08f4 SENS - ok
22:48:15.0510 0x08f4 [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\Windows\system32\sensrsvc.dll
22:48:15.0546 0x08f4 SensrSvc - ok
22:48:15.0572 0x08f4 [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\Windows\system32\drivers\serenum.sys
22:48:15.0619 0x08f4 Serenum - ok
22:48:15.0629 0x08f4 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\Windows\system32\drivers\serial.sys
22:48:15.0659 0x08f4 Serial - ok
22:48:15.0683 0x08f4 [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\Windows\system32\drivers\sermouse.sys
22:48:15.0713 0x08f4 sermouse - ok
22:48:15.0761 0x08f4 [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\Windows\system32\sessenv.dll
22:48:15.0798 0x08f4 SessionEnv - ok
22:48:15.0802 0x08f4 [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
22:48:15.0830 0x08f4 sffdisk - ok
22:48:15.0833 0x08f4 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
22:48:15.0860 0x08f4 sffp_mmc - ok
22:48:15.0865 0x08f4 [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
22:48:15.0880 0x08f4 sffp_sd - ok
22:48:15.0884 0x08f4 [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
22:48:15.0906 0x08f4 sfloppy - ok
22:48:16.0004 0x08f4 [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\Windows\System32\ipnathlp.dll
22:48:16.0081 0x08f4 SharedAccess - ok
22:48:16.0129 0x08f4 [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:48:16.0198 0x08f4 ShellHWDetection - ok
22:48:16.0255 0x08f4 [ E9E830D540EDEDED650F906628468548, 9800160C6807B28A2A1E57810151473C96F1484F2EF75D3E378E8C96440CD4CE ] simptcp C:\Windows\System32\tcpsvcs.exe
22:48:16.0306 0x08f4 simptcp - ok
22:48:16.0357 0x08f4 [ 1BC348CF6BAA90EC8E533EF6E6A69933, 2B26F6EB701F48E092DED6A7B888F24736F2899EE81D54DD4B1E9DF7CFD36E7A ] SiSGbeLH C:\Windows\system32\DRIVERS\SiSG664.sys
22:48:16.0390 0x08f4 SiSGbeLH - ok
22:48:16.0395 0x08f4 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
22:48:16.0408 0x08f4 SiSRaid2 - ok
22:48:16.0414 0x08f4 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
22:48:16.0427 0x08f4 SiSRaid4 - ok
22:48:16.0599 0x08f4 [ 050A4112B00BCA2E13314CDE48C1DEEE, 86C679CD494DEEB984372BF954EFBB8982AC7995FBF89FCF83BC228991D1B825 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
22:48:16.0655 0x08f4 SkypeUpdate - ok
22:48:16.0662 0x08f4 [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\Windows\system32\DRIVERS\smb.sys
22:48:16.0714 0x08f4 Smb - ok
22:48:16.0798 0x08f4 [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
22:48:16.0836 0x08f4 SNMPTRAP - ok
22:48:17.0026 0x08f4 [ 88A4C3A2144E992A78C92545A47CBB2C, 83F13C436AAEF6122B47742187966E3851FB818D61D6EE4832132B058B6A0E4F ] SplashtopRemoteService C:\Program Files (x86)\Splashtop\Splashtop Remote\SERVER\SRService.exe
22:48:17.0060 0x08f4 SplashtopRemoteService - ok
22:48:17.0103 0x08f4 [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\Windows\system32\drivers\spldr.sys
22:48:17.0126 0x08f4 spldr - ok
22:48:17.0331 0x08f4 [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler C:\Windows\System32\spoolsv.exe
22:48:17.0394 0x08f4 Spooler - ok
22:48:17.0905 0x08f4 [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\Windows\system32\sppsvc.exe
22:48:18.0077 0x08f4 sppsvc - ok
22:48:18.0114 0x08f4 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\Windows\system32\sppuinotify.dll
22:48:18.0151 0x08f4 sppuinotify - ok
22:48:18.0231 0x08f4 [ B9657A0AFF28C1CB114ACC0CB93EE4BB, 619DE6438827A648566CB6F6407DF30E3BBCE345775B0154D883A48E244A62EE ] sp_rsdrv2 C:\Windows\system32\DRIVERS\stflt.sys
22:48:18.0294 0x08f4 sp_rsdrv2 - ok
22:48:18.0352 0x08f4 [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv C:\Windows\system32\DRIVERS\srv.sys
22:48:18.0422 0x08f4 srv - ok
22:48:18.0518 0x08f4 [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
22:48:18.0572 0x08f4 srv2 - ok
22:48:18.0599 0x08f4 [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
22:48:18.0636 0x08f4 srvnet - ok
22:48:18.0698 0x08f4 [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
22:48:18.0783 0x08f4 SSDPSRV - ok
22:48:18.0809 0x08f4 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\Windows\system32\sstpsvc.dll
22:48:18.0846 0x08f4 SstpSvc - ok
22:48:19.0046 0x08f4 [ 6E6B9B863C5B894F3C6A60680C7317A4, FB5FC319430949AA8B2216F187083E280DF6E4F3BC6DA63333168F5612D58349 ] SSUService C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
22:48:19.0080 0x08f4 SSUService - ok
22:48:19.0291 0x08f4 [ 24543AAF056D3AFCED3F4FF487F53C90, A6755E4180FEA51BA6E310CCC84C9232C8D655ACA6720EA92903353CE5224422 ] ST2012_Svc C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
22:48:19.0401 0x08f4 ST2012_Svc - ok
22:48:19.0428 0x08f4 [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\Windows\system32\drivers\stexstor.sys
22:48:19.0439 0x08f4 stexstor - ok
22:48:19.0526 0x08f4 [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\Windows\System32\wiaservc.dll
22:48:19.0562 0x08f4 stisvc - ok
22:48:19.0610 0x08f4 [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt C:\Windows\system32\drivers\vmstorfl.sys
22:48:19.0623 0x08f4 storflt - ok
22:48:19.0670 0x08f4 [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc C:\Windows\system32\storsvc.dll
22:48:19.0741 0x08f4 StorSvc - ok
22:48:19.0768 0x08f4 [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc C:\Windows\system32\drivers\storvsc.sys
22:48:19.0795 0x08f4 storvsc - ok
22:48:19.0812 0x08f4 [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
22:48:19.0825 0x08f4 swenum - ok
22:48:19.0861 0x08f4 [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\Windows\System32\swprv.dll
22:48:19.0929 0x08f4 swprv - ok
22:48:20.0180 0x08f4 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain C:\Windows\system32\sysmain.dll
22:48:20.0329 0x08f4 SysMain - ok
22:48:20.0362 0x08f4 [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:48:20.0395 0x08f4 TabletInputService - ok
22:48:20.0510 0x08f4 [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\Windows\System32\tapisrv.dll
22:48:20.0582 0x08f4 TapiSrv - ok
22:48:20.0610 0x08f4 [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS C:\Windows\System32\tbssvc.dll
22:48:20.0672 0x08f4 TBS - ok
22:48:20.0901 0x08f4 [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
22:48:20.0993 0x08f4 Tcpip - ok
22:48:21.0077 0x08f4 [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
22:48:21.0136 0x08f4 TCPIP6 - ok
22:48:21.0159 0x08f4 [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
22:48:21.0193 0x08f4 tcpipreg - ok
22:48:21.0234 0x08f4 [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
22:48:21.0277 0x08f4 TDPIPE - ok
22:48:21.0313 0x08f4 [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
22:48:21.0356 0x08f4 TDTCP - ok
22:48:21.0382 0x08f4 [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719C48B08FAFA9661 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
22:48:21.0455 0x08f4 tdx - ok
22:48:22.0378 0x08f4 [ 93A5111B177891DCEBC161E327B04F90, 3F095622A8FB0BE1702D44979FB176F9E5B6717409AA4CC4D92270EE1AFF0246 ] TeamViewer9 C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
22:48:22.0524 0x08f4 TeamViewer9 - ok
22:48:22.0557 0x08f4 [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
22:48:22.0569 0x08f4 TermDD - ok
22:48:22.0615 0x08f4 [ 4FC4C50985E5B840F4D72E57286887B8, 0BCBB4A938803AE3A3532B6D8FFC85594AA9AEF5D8F9792684841BEA8780AE9E ] TermService C:\Windows\System32\termsrv.dll
22:48:22.0744 0x08f4 TermService - ok
22:48:22.0807 0x08f4 [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\Windows\system32\themeservice.dll
22:48:22.0874 0x08f4 Themes - ok
22:48:22.0926 0x08f4 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\Windows\system32\mmcss.dll
22:48:22.0994 0x08f4 THREADORDER - ok
22:48:23.0059 0x08f4 [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\Windows\System32\trkwks.dll
22:48:23.0110 0x08f4 TrkWks - ok
22:48:23.0250 0x08f4 [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:48:23.0297 0x08f4 TrustedInstaller - ok
22:48:23.0328 0x08f4 [ E232A3B43A894BB327FC161529BD9ED1, F2673DA8C920F21ACCECC25F7C59A05822E5E577D47F126EDF9C94FEB4B30C5F ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
22:48:23.0340 0x08f4 tssecsrv - ok
22:48:23.0376 0x08f4 [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
22:48:23.0413 0x08f4 TsUsbFlt - ok
22:48:23.0456 0x08f4 [ AD64450A4ABE076F5CB34CC08EEACB07, B5C386635441A19178E7FEEE299BA430C8D72F9110866C13A216B12A1080AD12 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
22:48:23.0520 0x08f4 TsUsbGD - ok
22:48:23.0598 0x08f4 [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
22:48:23.0677 0x08f4 tunnel - ok
22:48:23.0701 0x08f4 [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
22:48:23.0713 0x08f4 uagp35 - ok
22:48:23.0746 0x08f4 [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
22:48:23.0790 0x08f4 udfs - ok
22:48:24.0017 0x08f4 [ A447361E6156AFEF47A42AE9E89B2BB3, 45198D24586560C93490D2E0E866032504FB6AA4FC4F81BADBB01514E18F72F8 ] UI Assistant Service C:\Program Files (x86)\Join Air\AssistantServices.exe
22:48:24.0110 0x08f4 UI Assistant Service - detected UnsignedFile.Multi.Generic ( 1 )
22:48:26.0535 0x08f4 Detect skipped due to KSN trusted
22:48:26.0535 0x08f4 UI Assistant Service - ok
22:48:26.0577 0x08f4 [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\Windows\system32\UI0Detect.exe
22:48:26.0621 0x08f4 UI0Detect - ok
22:48:26.0655 0x08f4 [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
22:48:26.0670 0x08f4 uliagpkx - ok
22:48:26.0769 0x08f4 [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\Windows\system32\DRIVERS\umbus.sys
22:48:26.0822 0x08f4 umbus - ok
22:48:26.0829 0x08f4 [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\Windows\system32\drivers\umpass.sys
22:48:26.0849 0x08f4 UmPass - ok
22:48:26.0879 0x08f4 [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService C:\Windows\System32\umrdp.dll
22:48:26.0900 0x08f4 UmRdpService - ok
22:48:27.0176 0x08f4 [ 67A95B9D129ED5399E7965CD09CF30E7, F1F2F684146F1CCB293BB9871117B8CFC1D04588A830F67CE5D3F0D034D93B2A ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
22:48:27.0209 0x08f4 UMVPFSrv - ok
22:48:27.0848 0x08f4 [ 2C16648A12999AE69A9EBF41974B0BA2, 06008F61B6EC36CD34CB8C4BA983371DB7A9F4BEE15E5329F5E90FEEE300D258 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
22:48:27.0998 0x08f4 UNS - ok
22:48:28.0038 0x08f4 [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\Windows\System32\upnphost.dll
22:48:28.0083 0x08f4 upnphost - ok
22:48:28.0131 0x08f4 [ 5C3BE22E485B9BF11FCEFDC676C728D0, F55061066ECF6920D56518A677BB538C18B7F1BB150ED6DB3591408F44E8D53A ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
22:48:28.0197 0x08f4 USBAAPL64 - ok
22:48:28.0259 0x08f4 [ B0435098C81D04CAFFF80DDB746CD3A2, A17B207740382E38729571F0B0BC98FF874E856A7C7CE9EB930328A2AD88F52A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
22:48:28.0291 0x08f4 usbaudio - ok
22:48:28.0322 0x08f4 [ DCA68B0943D6FA415F0C56C92158A83A, BEE5A5B33B22D1DF50B884D46D89FC3B8286EB16E38AD5A20F0A49E5C6766C57 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
22:48:28.0376 0x08f4 usbccgp - ok
22:48:28.0436 0x08f4 [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir C:\Windows\system32\drivers\usbcir.sys
22:48:28.0480 0x08f4 usbcir - ok
22:48:28.0524 0x08f4 [ 18A85013A3E0F7E1755365D287443965, 811C5EDF38C765BCF71BCE25CB6626FF6988C3699F5EF1846240EA0052F34C33 ] usbehci C:\Windows\system32\drivers\usbehci.sys
22:48:28.0544 0x08f4 usbehci - ok
22:48:28.0610 0x08f4 [ 8D1196CFBB223621F2C67D45710F25BA, B5D7AFE51833B24FC9576F3AED3D8A2B290E5846060E73F9FFFAC1890A8B6003 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
22:48:28.0641 0x08f4 usbhub - ok
22:48:28.0673 0x08f4 [ 765A92D428A8DB88B960DA5A8D6089DC, 56DE8A2ED58E53B202C399CA7BACB1551136303C2EE0AB426BDBBF880E3C542C ] usbohci C:\Windows\system32\drivers\usbohci.sys
22:48:28.0719 0x08f4 usbohci - ok
22:48:28.0769 0x08f4 [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
22:48:28.0784 0x08f4 usbprint - ok
22:48:28.0824 0x08f4 [ 9661DA76B4531B2DA272ECCE25A8AF24, FEA93254A21E71A7EB8AD35FCCAD2C1E41F7329EC33B1734F5B41307A34D8637 ] usbscan C:\Windows\system32\drivers\usbscan.sys
22:48:28.0869 0x08f4 usbscan - ok
22:48:28.0909 0x08f4 [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:48:28.0975 0x08f4 USBSTOR - ok
22:48:28.0991 0x08f4 [ DD253AFC3BC6CBA412342DE60C3647F3, 146F8613F1057AC054DC3593E84BC52899DA27EA33B0E72ACFB78C3699ADCDE7 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
22:48:29.0025 0x08f4 usbuhci - ok
22:48:29.0065 0x08f4 [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
22:48:29.0084 0x08f4 usbvideo - ok
22:48:29.0134 0x08f4 [ 7B28E2FBE75115660FAB31079C0A9F29, 81BB5A3E64B652A672A0782A88ABF6DDD729D38712D0706CE0FB9DE6D1EE1515 ] usb_rndisx C:\Windows\system32\drivers\usb8023x.sys
22:48:29.0185 0x08f4 usb_rndisx - ok
22:48:29.0237 0x08f4 [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\Windows\System32\uxsms.dll
22:48:29.0287 0x08f4 UxSms - ok
22:48:29.0344 0x08f4 [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] VaultSvc C:\Windows\system32\lsass.exe
22:48:29.0372 0x08f4 VaultSvc - ok
22:48:29.0464 0x08f4 [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
22:48:29.0493 0x08f4 vdrvroot - ok
22:48:29.0647 0x08f4 [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\Windows\System32\vds.exe
22:48:29.0740 0x08f4 vds - ok
22:48:29.0814 0x08f4 [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
22:48:29.0851 0x08f4 vga - ok
22:48:29.0901 0x08f4 [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\Windows\System32\drivers\vga.sys
22:48:30.0002 0x08f4 VgaSave - ok
22:48:30.0039 0x08f4 [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
22:48:30.0055 0x08f4 vhdmp - ok
22:48:30.0093 0x08f4 [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\Windows\system32\drivers\viaide.sys
22:48:30.0104 0x08f4 viaide - ok
22:48:30.0130 0x08f4 [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus C:\Windows\system32\drivers\vmbus.sys
22:48:30.0147 0x08f4 vmbus - ok
22:48:30.0151 0x08f4 [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
22:48:30.0164 0x08f4 VMBusHID - ok
22:48:30.0191 0x08f4 vngoazpn - ok
22:48:30.0218 0x08f4 [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr C:\Windows\system32\drivers\volmgr.sys
22:48:30.0230 0x08f4 volmgr - ok
22:48:30.0330 0x08f4 [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
22:48:30.0351 0x08f4 volmgrx - ok
22:48:30.0381 0x08f4 [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap C:\Windows\system32\drivers\volsnap.sys
22:48:30.0401 0x08f4 volsnap - ok
22:48:30.0428 0x08f4 [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
22:48:30.0443 0x08f4 vsmraid - ok
22:48:30.0755 0x08f4 [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\Windows\system32\vssvc.exe
22:48:30.0838 0x08f4 VSS - ok
22:48:30.0899 0x08f4 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
22:48:30.0954 0x08f4 vwifibus - ok
22:48:30.0988 0x08f4 [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
22:48:31.0013 0x08f4 vwififlt - ok
22:48:31.0054 0x08f4 [ 6A638FC4BFDDC4D9B186C28C91BD1A01, 5521F1DC515586777EC4837E0AEAA3E613CC178AF1074031C4D0D0C695A93168 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
22:48:31.0070 0x08f4 vwifimp - ok
22:48:31.0237 0x08f4 [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\Windows\system32\w32time.dll
22:48:31.0336 0x08f4 W32Time - ok
22:48:31.0586 0x08f4 [ B32009DB1972E7F2C227499289C4384A, D491CD90ACE895EC60A5A2F995EAE39F8ED662B71BC548C3FF5BBDBC60054788 ] W3SVC C:\Windows\system32\inetsrv\iisw3adm.dll
22:48:31.0611 0x08f4 W3SVC - ok
22:48:31.0637 0x08f4 [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
22:48:31.0650 0x08f4 WacomPen - ok
22:48:31.0710 0x08f4 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
22:48:31.0782 0x08f4 WANARP - ok
22:48:31.0802 0x08f4 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
22:48:31.0836 0x08f4 Wanarpv6 - ok
22:48:31.0871 0x08f4 [ B32009DB1972E7F2C227499289C4384A, D491CD90ACE895EC60A5A2F995EAE39F8ED662B71BC548C3FF5BBDBC60054788 ] WAS C:\Windows\system32\inetsrv\iisw3adm.dll
22:48:31.0893 0x08f4 WAS - ok
22:48:32.0098 0x08f4 [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\Windows\system32\wbengine.exe
22:48:32.0302 0x08f4 wbengine - ok
22:48:32.0397 0x08f4 [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
22:48:32.0433 0x08f4 WbioSrvc - ok
22:48:32.0475 0x08f4 [ 8BDA6DB43AA54E8BB5E0794541DDC209, 8753C507BE77B019A3403AF5252434A01DB9F9332E58AC3783ABCE3D21AD9DD4 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
22:48:32.0497 0x08f4 WcesComm - ok
22:48:32.0734 0x08f4 [ 8F105ADE434064ADFBBFBE198513B84F, 613F6C224D5FE079C038C2813BC92F769877AEC8E0071026B63D2A548371880E ] WCMVCAM C:\Windows\system32\DRIVERS\wcmvcam64.sys
22:48:32.0787 0x08f4 WCMVCAM - ok
22:48:32.0834 0x08f4 [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\Windows\System32\wcncsvc.dll
22:48:32.0864 0x08f4 wcncsvc - ok
22:48:32.0878 0x08f4 [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:48:32.0923 0x08f4 WcsPlugInService - ok
22:48:32.0942 0x08f4 [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\Windows\system32\drivers\wd.sys
22:48:32.0954 0x08f4 Wd - ok
22:48:33.0036 0x08f4 [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
22:48:33.0114 0x08f4 Wdf01000 - ok
22:48:33.0162 0x08f4 [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost C:\Windows\system32\wdi.dll
22:48:33.0268 0x08f4 WdiServiceHost - ok
22:48:33.0281 0x08f4 [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost C:\Windows\system32\wdi.dll
22:48:33.0311 0x08f4 WdiSystemHost - ok
22:48:33.0444 0x08f4 [ 0EB0E5D22B1760F2DBCE632F2DD7A54D, B8A4CC62F88768947FB0A161CF9564DB28FD9C1C037B5475DF192982DE035C22 ] WebClient C:\Windows\System32\webclnt.dll
22:48:33.0465 0x08f4 WebClient - ok
22:48:33.0496 0x08f4 [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc C:\Windows\system32\wecsvc.dll
22:48:33.0561 0x08f4 Wecsvc - ok
22:48:33.0583 0x08f4 [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\Windows\System32\wercplsupport.dll
22:48:33.0621 0x08f4 wercplsupport - ok
22:48:33.0656 0x08f4 [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\Windows\System32\WerSvc.dll
22:48:33.0711 0x08f4 WerSvc - ok
22:48:33.0748 0x08f4 [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
22:48:33.0782 0x08f4 WfpLwf - ok
22:48:33.0876 0x08f4 [ 52DED146E4797E6CCF94799E8E22BB2A, 57A29260D81AA3AD3F8C29E9CFA7CE3970D7A8BF673ADD9B256EE76C7DEC080E ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys
22:48:33.0925 0x08f4 WimFltr - ok
22:48:33.0972 0x08f4 [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
22:48:33.0990 0x08f4 WIMMount - ok
22:48:34.0016 0x08f4 WinDefend - ok
22:48:34.0039 0x08f4 WinHttpAutoProxySvc - ok
22:48:34.0169 0x08f4 [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
22:48:34.0247 0x08f4 Winmgmt - ok
22:48:34.0492 0x08f4 [ BCB1310604AA415C4508708975B3931E, 9D943F086D454345153A0DD426B4432532A44FD87950386B186E1CAD2AC70565 ] WinRM C:\Windows\system32\WsmSvc.dll
22:48:34.0683 0x08f4 WinRM - ok
22:48:34.0851 0x08f4 [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
22:48:34.0889 0x08f4 WinUsb - ok
22:48:34.0950 0x08f4 [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\Windows\System32\wlansvc.dll
22:48:35.0020 0x08f4 Wlansvc - ok
22:48:35.0371 0x08f4 [ 7E47C328FC4768CB8BEAFBCFAFA70362, C98BD6A0C2F70E069D5FD3BAB31BD028DFEAC0490D180BBC28A14BE375897D8C ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:48:35.0511 0x08f4 wlidsvc - ok
22:48:35.0561 0x08f4 [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
22:48:35.0600 0x08f4 WmiAcpi - ok
22:48:35.0724 0x08f4 [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
22:48:35.0816 0x08f4 wmiApSrv - ok
22:48:35.0911 0x08f4 WMPNetworkSvc - ok
22:48:35.0978 0x08f4 [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\Windows\System32\wpcsvc.dll
22:48:36.0024 0x08f4 WPCSvc - ok
22:48:36.0089 0x08f4 [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
22:48:36.0124 0x08f4 WPDBusEnum - ok
22:48:36.0181 0x08f4 [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
22:48:36.0220 0x08f4 ws2ifsl - ok
22:48:36.0263 0x08f4 [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\Windows\system32\wscsvc.dll
22:48:36.0304 0x08f4 wscsvc - ok
22:48:36.0308 0x08f4 WSearch - ok
22:48:36.0372 0x08f4 [ 83575C43B2BFE9AB0661A7F957E843C0, 6FCE62721902A4F35F1A4CED8AF60A0346CFAB657ED92DE4CEFF19BDB830D32D ] wsvd C:\Windows\system32\DRIVERS\wsvd.sys
22:48:36.0404 0x08f4 wsvd - ok
22:48:36.0811 0x08f4 [ 61FF576450CCC80564B850BC3FB6713A, B2843BC9E2F62D27DCF6787D063378926748CE75002BADA1873DCB5039883705 ] wuauserv C:\Windows\system32\wuaueng.dll
22:48:36.0898 0x08f4 wuauserv - ok
22:48:36.0965 0x08f4 [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
22:48:37.0038 0x08f4 WudfPf - ok
22:48:37.0167 0x08f4 [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
22:48:37.0207 0x08f4 WUDFRd - ok
22:48:37.0241 0x08f4 [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
22:48:37.0259 0x08f4 wudfsvc - ok
22:48:37.0298 0x08f4 [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc C:\Windows\System32\wwansvc.dll
22:48:37.0374 0x08f4 WwanSvc - ok
22:48:37.0511 0x08f4 [ 31DB70A61814E4F33181D48190D46845, 35DF4A0549649848ECC347EBBD603D5C7F9554C7B6DA60405B4D70C6060AA44A ] ZTEusbmdm6k C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
22:48:37.0551 0x08f4 ZTEusbmdm6k - ok
22:48:37.0585 0x08f4 [ C9ADA887BF326D8413E81FE80B1BE7EB, C5DAD40030D37A586D4B04F4516F140D5F45CB24CB39B5770AF51557A267DD42 ] ZTEusbnmea C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
22:48:37.0623 0x08f4 ZTEusbnmea - ok
22:48:37.0695 0x08f4 [ 31DB70A61814E4F33181D48190D46845, 35DF4A0549649848ECC347EBBD603D5C7F9554C7B6DA60405B4D70C6060AA44A ] ZTEusbser6k C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
22:48:37.0730 0x08f4 ZTEusbser6k - ok
22:48:37.0797 0x08f4 ================ Scan global ===============================
22:48:37.0837 0x08f4 [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll
22:48:37.0880 0x08f4 [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll
22:48:37.0902 0x08f4 [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll
22:48:37.0946 0x08f4 [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
22:48:38.0000 0x08f4 [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe
22:48:38.0050 0x08f4 [ Global ] - ok
22:48:38.0051 0x08f4 ================ Scan MBR ==================================
22:48:38.0066 0x08f4 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
22:48:38.0771 0x08f4 \Device\Harddisk0\DR0 - ok
22:48:38.0772 0x08f4 ================ Scan VBR ==================================
22:48:38.0781 0x08f4 [ BEB34928E75ADA2C2548ECE6C5638061 ] \Device\Harddisk0\DR0\Partition1
22:48:38.0783 0x08f4 \Device\Harddisk0\DR0\Partition1 - ok
22:48:38.0791 0x08f4 [ 1853A023BCEEB1941BC33D64D6CDC994 ] \Device\Harddisk0\DR0\Partition2
22:48:38.0793 0x08f4 \Device\Harddisk0\DR0\Partition2 - ok
22:48:38.0795 0x08f4 ================ Scan generic autorun ======================
22:48:38.0795 0x08f4 ETDCtrl - ok
22:48:38.0892 0x08f4 [ 4490896F4491FD5F1BE601BA9C8245BD, 53709493AFDDE795A08F5E54FCF210479304B998522A06054AA9FAF514C8F1C6 ] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
22:48:39.0025 0x08f4 AmIcoSinglun64 - detected UnsignedFile.Multi.Generic ( 1 )
22:48:41.0433 0x08f4 Detect skipped due to KSN trusted
22:48:41.0433 0x08f4 AmIcoSinglun64 - ok
22:48:41.0727 0x08f4 [ 36EDD4D517496598491EB5609908E7BC, 77E3CAFD7B8CB099BA90DA7435E596B87B80D940EA166D11789A4345BC695913 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
22:48:41.0802 0x08f4 RtHDVBg - ok
22:48:42.0206 0x08f4 [ 6A94CD69E9C2BD1864096AB0B16660E6, E22F3C432F104AD25512D1F97526D772D50BE0FC7910FFF12335F4ECC0EEE184 ] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
22:48:42.0312 0x08f4 IntelPAN - ok
22:48:42.0316 0x08f4 BTMTrayAgent - ok
22:48:42.0399 0x08f4 [ 233A10D4B3F6897899112E4EC60F1906, 1F7E768E57064938114DF2EFC5B219EB0D30A7D9E574924E9CED054462505AF0 ] C:\Windows\WindowsMobile\wmdc.exe
22:48:42.0431 0x08f4 Windows Mobile Device Center - ok
22:48:42.0656 0x08f4 [ A6AAD37CDCAE75CB62D039E3A4D8F5E3, 4FF763B0D129175BA1B1E794BA313E6C63F7A89D377C786BF5E730AF2A1D95D1 ] C:\Program Files\Microsoft Security Client\msseces.exe
22:48:42.0763 0x08f4 MSC - ok
22:48:43.0480 0x08f4 [ 51B09EE702873A05CBA87E87BFA4CB9E, 3C2739DE4E30BBD798BE382DEEFA63FAABB5059F1B597A22FA89A026D3DCC363 ] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
22:48:44.0257 0x08f4 SpywareTerminatorShield - ok
22:48:44.0742 0x08f4 [ 920942A477B7A43B38AB53E47D9887A6, 06B283890CBFD4D9A258F32FDFB47D21DC28637BFD58AA729372E5A25541D139 ] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
22:48:47.0450 0x08f4 SpywareTerminatorUpdater - ok
22:48:47.0545 0x08f4 [ 28062B17191C9450BF6C6C3EF8C7EB27, 4859C5708DFD119021F7B7FFB38F0B316675E1E4D5D51A10D4265F712CF8CDB6 ] C:\Windows\system32\igfxtray.exe
22:48:47.0648 0x08f4 IgfxTray - ok
22:48:47.0680 0x08f4 [ 28FC280487F0BAAE5E8119257C4EEF8C, F574BC70B79B77912FC683B3EB0BE6929E7758284ED5B47008E18B0E4A4A09FD ] C:\Windows\system32\hkcmd.exe
22:48:47.0794 0x08f4 HotKeysCmds - ok
22:48:47.0955 0x08f4 [ F29BEA821C753E4F00177690F70CDC13, 0EDB40F4A4C23553C0288E6E3AD65E7B523F6764C87C6C36C3ECB0C1940C5176 ] C:\Windows\system32\igfxpers.exe
22:48:48.0058 0x08f4 Persistence - ok
22:48:48.0381 0x08f4 [ BD87D5F5D68AC07243010A6F5176F897, D6518C2990DDAE5E88C9BE649B34A09A0C19A2EAA14967B45F6B176E34DC2EEB ] C:\Program Files (x86)\ASUS\APRP\APRP.EXE
22:48:48.0786 0x08f4 ASUSPRP - detected UnsignedFile.Multi.Generic ( 1 )
22:48:51.0206 0x08f4 Detect skipped due to KSN trusted
22:48:51.0206 0x08f4 ASUSPRP - ok
22:48:51.0448 0x08f4 [ 7EE22E13DEC8A6D18F4643C1EA34B0F0, C36CE0B46763359AD0A9D02DA538A7E3A1A8CA5E6A02F36CE1AC46D5FAF03CF5 ] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
22:48:51.0553 0x08f4 SonicMasterTray - ok
22:48:52.0132 0x08f4 [ 5BB1F77C8AF725A15EC9366498D275BB, 87146A81FB6F313ACF087C72F219CFAA92D4CA456810C49241BD182384B2DAAC ] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
22:48:52.0339 0x08f4 ATKOSD2 - ok
22:48:52.0423 0x08f4 [ 79A3B950988F8D2B81906D0C0473158B, 7D9EDB4F9A4800D31C103CF2BBC93C0F5F31888E93E899C43EC5984B4807C3D8 ] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
22:48:52.0442 0x08f4 ATKMEDIA - ok
22:48:52.0503 0x08f4 [ 5AEBF6FA9805C9101220AA4FB4FA17E7, A9B2FC41380211A6C44E839A95676A5BA868CEEBB56D83A780230434C2A20836 ] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
22:48:52.0528 0x08f4 HControlUser - ok
22:48:53.0078 0x08f4 [ 36E7CE6EA4C190AA88C25CDD3C89D84C, F5F927116329982712310295CBFB3B9EA228FF9A7054E6BCB395B37C45D8DEA8 ] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
22:48:53.0411 0x08f4 Wireless Console 3 - detected UnsignedFile.Multi.Generic ( 1 )
22:48:55.0831 0x08f4 Detect skipped due to KSN trusted
22:48:55.0831 0x08f4 Wireless Console 3 - ok
22:48:55.0996 0x08f4 [ 4EFCDF3DB1BBA69C09622991280C4ACB, A86D4694BCFFF3C0FAF07C56A410A8317A953FB581CDCDBED5CAF735A0E2AC0D ] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
22:48:56.0017 0x08f4 UpdateLBPShortCut - ok
22:48:56.0157 0x08f4 [ 4EFCDF3DB1BBA69C09622991280C4ACB, A86D4694BCFFF3C0FAF07C56A410A8317A953FB581CDCDBED5CAF735A0E2AC0D ] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
22:48:56.0185 0x08f4 UpdateP2GoShortCut - ok
22:48:56.0356 0x08f4 [ 09E60B4FE341A94A300830C008907099, 5F07868953FAA8FFA9E6477F6BAC52DEEDF3EA4A3F8AF5B4E15878D8240223AB ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
22:48:56.0366 0x08f4 APSDaemon - ok
22:48:56.0556 0x08f4 [ 47EA5F76FAB723C61AB4A0D79BAD512C, A7A38EB0A7068B160E6949945EF639F999A06AE35746F6E79C7350745798E5C9 ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
22:48:56.0724 0x08f4 Adobe ARM - ok
22:48:56.0830 0x08f4 [ 4EF08A95991555DD2981C09367CCA6C8, 9CE518CBAF2AD4998062ED2FD160D03275328603A4ABFC49B92951DCE0734284 ] C:\Program Files (x86)\Join Air\UIExec.exe
22:48:56.0981 0x08f4 UIExec - detected UnsignedFile.Multi.Generic ( 1 )
22:48:59.0398 0x08f4 Detect skipped due to KSN trusted
22:48:59.0398 0x08f4 UIExec - ok
22:48:59.0584 0x08f4 [ 08E7173D1B74095335052459200CB1EA, 5B6EB8A65B5F451BF6115EB7CD1355E5870E6D764F22D767D13216BF17C5668F ] C:\Program Files (x86)\QuickTime\QTTask.exe
22:48:59.0606 0x08f4 QuickTime Task - detected UnsignedFile.Multi.Generic ( 1 )
22:49:02.0018 0x08f4 Detect skipped due to KSN trusted
22:49:02.0018 0x08f4 QuickTime Task - ok
22:49:02.0215 0x08f4 [ 14D6542607ACD4B2D1DDB1A36E0D8813, 3A270600549E8E7988D5AF3486C0F504269B9573393D87BF87BDB2287BF007B2 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
22:49:02.0241 0x08f4 SunJavaUpdateSched - ok
22:49:02.0306 0x08f4 [ 0EF0822810009D58118CCDFD098FA9F4, 9FAA263057898BCDBCB0A064C463F48D149474AA339A3C4C47626CC118750D2D ] C:\Program Files (x86)\iTunes\iTunesHelper.exe
22:49:02.0336 0x08f4 iTunesHelper - ok
22:49:02.0755 0x08f4 [ CA595FA53E6C797EC1AB43AFB4B4F183, A0A7DDD2ECA97D6533DF908861C000B69C327184F4FFC7C4D971AE4651AD337F ] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
22:49:02.0779 0x08f4 iCloudServices - ok
22:49:02.0814 0x08f4 [ 096407F0CB75519F4DBFBA5BB413187B, 9F7A13FA6DA2B2FE58B69AD94DA372DA0C73918C1E3C57D1BC8F7662875C7CBD ] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
22:49:02.0824 0x08f4 ApplePhotoStreams - ok
22:49:03.0098 0x08f4 Wiuhyfreyquwh - ok
22:49:03.0720 0x08f4 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
22:49:03.0829 0x08f4 Sidebar - ok
22:49:03.0858 0x08f4 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
22:49:03.0877 0x08f4 mctadmin - ok
22:49:03.0878 0x08f4 Waiting for KSN requests completion. In queue: 6
22:49:04.0878 0x08f4 Waiting for KSN requests completion. In queue: 6
22:49:05.0878 0x08f4 Waiting for KSN requests completion. In queue: 6
22:49:06.0901 0x08f4 AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.6.305.0 ), 0x61000 ( enabled : updated )
22:49:06.0944 0x08f4 Win FW state via NFP2: enabled
22:49:09.0407 0x08f4 ============================================================
22:49:09.0407 0x08f4 Scan finished
22:49:09.0407 0x08f4 ============================================================
22:49:09.0429 0x0ca8 Detected object count: 0
22:49:09.0429 0x0ca8 Actual detected object count: 0

deeprybka 10.11.2014 23:08

Sieht gut aus...

Schritt 1
http://deeprybka.trojaner-board.de/b...isoft/emsi.png

Download
  • Bitte installiere das Programm in den vorgegebenen Pfad.
  • Starte das Programm durch Doppelklick der Desktopverknüpfung.
  • Das EEK ist nach dem Laden der Malwaresignaturen für den Scan bereit.
  • Folge nun bitte der animierten Bildanleitung, entferne alle Funde und poste am Ende des Scans bzw. der Bereinigung das Log.
http://deeprybka.trojaner-board.de/b...ft/emsikit.gif


Schritt 2

http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png

Bitte starte FRST erneut, markiere auch die checkbox http://deeprybka.trojaner-board.de/b...t/addition.pngund drücke auf Scan.
Bitte poste mir den Inhalt der beiden Logs die erstellt werden.

Anchovi 10.11.2014 23:25

Vielen Dank soweit, total super Deine Hilfe!

Die beiden Scans sind in Arbeit :)

deeprybka 10.11.2014 23:27

:abklatsch:

Gerne...Lass Dir ruhig Zeit. Aber lass den PC nicht zu lange "einfach so" mit dem Internet verbunden. Bis wir fertig sind, solltest den nur für unsere Schritte verwenden... ;)

Bis morgen dann... :)

Anchovi 10.11.2014 23:30

Noch bin ich ein bisschen wach ;)

Momentan hakt der Emisoft-Scan bei ca. 60 Prozent, schon eine geraume Zeit. Ist das normal?

deeprybka 10.11.2014 23:41

Warte mal ab...Wenn die Windows-Uhr stehen bleibt oder er ewig die gleiche Datei scannt, dann läuft wohl was schief.

Anchovi 11.11.2014 00:07

Alles klar. Habe neu gestartet, jetzt läuft er und scannt- zwar recht langsam, aber er scannt ;)

deeprybka 11.11.2014 00:09

Naja, was heißt langsam? Der befummelt jetzt jede einzelne Datei... :D

Anchovi 11.11.2014 10:06

So, hier jetzt die beiden von dir gewünschten Scans.
Code:

Emsisoft Emergency Kit - Version 9.0
Letztes Update: 10.11.2014 23:19:57
Benutzerkonto: Hendrik-PC\Hendrik

Scan Einstellungen:

Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\

PUPs-Erkennung: An
Archiv Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus

Scan Beginn:        10.11.2014 23:37:01

Gescannt        576009
Gefunden        0

Scan Ende:        11.11.2014 05:43:53
Scan Zeit:        6:06:52


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-11-2014 01
Ran by Hendrik (administrator) on HENDRIK-PC on 11-11-2014 09:59:35
Running from C:\Users\Hendrik\Desktop
Loaded Profiles: Hendrik & DefaultAppPool (Available profiles: Hendrik & DefaultAppPool)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
() C:\Program Files (x86)\Join Air\UIExec.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Hendrik\Desktop\FRST64(1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-09] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2255360 2011-06-10] (ASUS)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UIExec] => C:\Program Files (x86)\Join Air\UIExec.exe [132608 2009-08-31] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [Wiuhyfreyquwh] => "C:\Users\Hendrik\AppData\Roaming\Urmytiyf\ywwego.exe"
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-18\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideSCAHealth] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Plugin HKU\S-1-5-21-1724138799-3868663929-1243099489-1000: @torrentstream.net/tsplugin,version=1.0.6 -> C:\Users\Hendrik\AppData\Roaming\TorrentStream\player\npts.dll (The Torrent Stream and VideoLAN and Delft University of Technology)
FF Plugin ProgramFiles/Appdata: C:\Users\Hendrik\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ddg.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018\Extensions\gmailnoads@mywebber.com.xpi [2014-10-11]
FF Extension: Adblock Plus - C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-11]

Chrome:
=======
CHR HomePage: Default -> chrome://newtab
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.671\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll ()
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Users\Hendrik\AppData\Roaming\Mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.670.1) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U67) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Torrent Stream P2P Multimedia Plug-in) - C:\Users\Hendrik\AppData\Roaming\TorrentStream\player\npts.dll (The Torrent Stream and VideoLAN and Delft University of Technology)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll No File
CHR Profile: C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-16]
CHR Extension: (Google Drive) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-16]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04]
CHR Extension: (YouTube) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-16]
CHR Extension: (Google-Suche) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-16]
CHR Extension: (Google Wallet) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-16]
CHR Extension: (TS Magic Player) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ochbjojkpcmlfeagbaahkofepalngihg [2014-04-26]
CHR Extension: (Google Mail) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-11] (Seiko Epson Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com)
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [241664 2009-08-31] () [File not signed]
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S2 lxdu_device; C:\Windows\system32\lxducoms.exe -service [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 assd; C:\Windows\System32\Drivers\assd.sys [27264 2010-04-28] (ASUS Corporation)
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2014-11-10] (Emsisoft GmbH)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-11] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2013-12-08] (Windows (R) Win 7 DDK provider)
S2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam64.sys [1071032 2012-04-15] (Windows (R) Win 7 DDK provider)
S1 brdzkxcp; \??\C:\Windows\system32\drivers\brdzkxcp.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S1 gucgznbc; \??\C:\Windows\system32\drivers\gucgznbc.sys [X]
S1 inqltdso; \??\C:\Windows\system32\drivers\inqltdso.sys [X]
S1 laaolckg; \??\C:\Windows\system32\drivers\laaolckg.sys [X]
S1 lxukkwfx; \??\C:\Windows\system32\drivers\lxukkwfx.sys [X]
S1 vngoazpn; \??\C:\Windows\system32\drivers\vngoazpn.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 07:45 - 2014-11-11 07:45 - 00000934 _____ () C:\Users\Hendrik\Desktop\a2scan_141110-233701.txt
2014-11-10 23:16 - 2014-11-10 23:16 - 00000745 _____ () C:\Users\Hendrik\Desktop\Start Emsisoft Emergency Kit.lnk
2014-11-10 23:15 - 2014-11-10 23:17 - 00000000 ____D () C:\EEK
2014-11-10 23:12 - 2014-11-10 23:14 - 156056136 _____ () C:\Users\Hendrik\Desktop\EmsisoftEmergencyKit.exe
2014-11-10 22:44 - 2014-11-10 22:44 - 04184008 _____ (Kaspersky Lab ZAO) C:\Users\Hendrik\Desktop\tdsskiller.exe
2014-11-10 22:19 - 2014-11-10 22:19 - 00061319 _____ () C:\Users\Hendrik\Desktop\ESETRovnixCleaner.exe_20141110.221918.6052.zip
2014-11-10 22:19 - 2014-11-10 22:19 - 00006510 _____ () C:\Users\Hendrik\Desktop\ESETRovnixCleaner.exe_20141110.221918.6052.log
2014-11-10 21:58 - 2014-11-10 22:19 - 00170280 _____ (ESET) C:\Windows\system32\Drivers\ESETCleanersDriver.sys
2014-11-10 21:58 - 2014-11-10 21:59 - 00007370 _____ () C:\Users\Hendrik\Downloads\ESETRovnixCleaner.exe_20141110.215848.8388.log
2014-11-10 21:58 - 2014-11-10 21:58 - 00064500 _____ () C:\Users\Hendrik\Downloads\ESETRovnixCleaner.exe_20141110.215848.8388.zip
2014-11-10 21:57 - 2014-11-10 21:57 - 00338120 _____ (ESET) C:\Users\Hendrik\Desktop\ESETRovnixCleaner.exe
2014-11-10 21:49 - 2014-11-11 10:00 - 00024950 _____ () C:\Users\Hendrik\Desktop\FRST.txt
2014-11-10 21:33 - 2014-11-10 21:35 - 02116096 _____ (Farbar) C:\Users\Hendrik\Desktop\FRST64(1).exe
2014-11-10 20:13 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-11-10 20:13 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-11-10 20:13 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-11-10 20:12 - 2014-11-10 21:29 - 00000000 ____D () C:\ComboFix
2014-11-10 20:10 - 2014-11-10 20:12 - 00000000 ____D () C:\Qoobox
2014-11-10 20:06 - 2014-11-10 21:18 - 00000000 ____D () C:\Windows\erdnt
2014-11-10 19:57 - 2014-11-10 19:58 - 05598341 ____R (Swearware) C:\Users\Hendrik\Desktop\ComboFix.exe
2014-11-10 19:47 - 2014-11-10 19:47 - 00000000 ____D () C:\OETemp
2014-11-10 19:41 - 2014-11-10 19:41 - 05598341 _____ (Swearware) C:\Users\Hendrik\Downloads\ComboFix(1).exe
2014-11-10 19:40 - 2014-11-10 19:41 - 05598341 _____ (Swearware) C:\Users\Hendrik\Downloads\ComboFix.exe
2014-11-10 18:58 - 2014-11-10 19:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Gyxyewlu
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Baexkir
2014-11-08 11:48 - 2014-11-08 11:48 - 00003834 _____ () C:\Windows\System32\Tasks\Security Center Update - 1783181859
2014-11-08 11:48 - 2014-11-08 11:48 - 00003830 _____ () C:\Windows\System32\Tasks\Security Center Update - 279616795
2014-11-08 11:48 - 2014-11-08 11:48 - 00003826 _____ () C:\Windows\System32\Tasks\Security Center Update - 3634134863
2014-11-08 11:47 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Vyyhxe
2014-11-07 16:38 - 2014-11-10 19:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2014-11-06 21:29 - 2014-11-06 21:43 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (78)
2014-11-06 19:00 - 2014-11-10 19:51 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-11-06 18:59 - 2014-11-06 18:59 - 04583464 _____ (Avira Operations GmbH & Co. KG) C:\Users\Hendrik\Downloads\avira_de_av___ws.exe
2014-11-06 18:41 - 2014-11-06 18:41 - 00380416 _____ () C:\Users\Hendrik\Desktop\Gmer-19357.exe
2014-11-06 18:34 - 2014-11-06 18:36 - 00041719 _____ () C:\Users\Hendrik\Downloads\Addition.txt
2014-11-06 18:31 - 2014-11-10 21:47 - 00063412 _____ () C:\Users\Hendrik\Downloads\FRST.txt
2014-11-06 18:30 - 2014-11-11 09:59 - 00000000 ____D () C:\FRST
2014-11-06 18:30 - 2014-11-06 18:30 - 02114560 _____ (Farbar) C:\Users\Hendrik\Downloads\FRST64.exe
2014-11-06 18:28 - 2014-11-06 18:29 - 00000476 _____ () C:\Users\Hendrik\Downloads\defogger_disable.log
2014-11-06 18:28 - 2014-11-06 18:28 - 00000000 _____ () C:\Users\Hendrik\defogger_reenable
2014-11-06 18:27 - 2014-11-06 18:27 - 00050477 _____ () C:\Users\Hendrik\Downloads\Defogger.exe
2014-11-06 16:25 - 2014-11-06 18:20 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-06 16:19 - 2014-11-06 16:19 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-06 16:19 - 2014-11-06 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-06 16:18 - 2014-11-06 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-06 16:18 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-06 16:18 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-06 16:18 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-06 16:16 - 2014-11-06 16:17 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025(2).exe
2014-11-06 16:00 - 2014-11-06 16:00 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025(1).exe
2014-11-06 15:43 - 2014-11-06 15:43 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-06 12:02 - 2014-11-06 12:06 - 121435896 _____ (Microsoft Corporation) C:\Users\Hendrik\Downloads\msert(2).exe
2014-11-05 17:18 - 2014-11-05 17:18 - 01125200 _____ () C:\Users\Hendrik\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe
2014-11-05 16:42 - 2014-11-05 16:42 - 00896504 _____ (Microsoft Corporation) C:\Users\Hendrik\Downloads\mssstool64.exe
2014-11-04 22:47 - 2014-11-05 15:52 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Urmytiyf
2014-11-04 21:50 - 2014-11-06 13:44 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-11-04 17:44 - 2014-11-06 15:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2014-11-04 17:44 - 2014-11-06 15:30 - 00000000 ____D () C:\Program Files\Wondershare
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ___HD () C:\Program Files (x86)\Dr.Fone_Temp
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Wondershare
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ____D () C:\ProgramData\Wondershare
2014-11-04 17:43 - 2014-11-04 17:43 - 00000000 ____D () C:\Users\Public\Documents\Wondershare
2014-11-04 17:16 - 2014-11-04 17:16 - 00000000 ____D () C:\Users\Hendrik\Desktop\Media
2014-11-04 17:07 - 2014-11-05 16:09 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Reincubate
2014-11-04 10:42 - 2014-11-04 10:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\WindSolutions
2014-11-04 10:42 - 2014-11-04 10:46 - 00000000 ____D () C:\ProgramData\WindSolutions
2014-11-04 00:08 - 2014-11-04 00:08 - 00000000 ____D () C:\Users\Hendrik\.android
2014-11-03 23:53 - 2014-11-04 00:05 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-11-02 00:42 - 2014-11-02 00:43 - 107254738 _____ () C:\Users\Hendrik\Documents\clip0918.avi
2014-11-01 12:32 - 2014-11-01 12:32 - 04078544 _____ (iMobie Inc. ) C:\Users\Hendrik\Downloads\phonerescue-setup.exe
2014-10-30 22:34 - 2014-10-30 22:36 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (21)
2014-10-29 15:01 - 2014-10-29 15:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-10-29 14:06 - 2014-10-29 14:06 - 00002192 _____ () C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2014-10-29 14:05 - 2014-10-29 14:05 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2014-10-27 17:43 - 2014-10-27 17:43 - 00002170 _____ () C:\Users\Hendrik\.recently-used.xbel
2014-10-27 00:15 - 2014-10-27 00:16 - 118253116 _____ () C:\Users\Hendrik\Documents\clip0917.avi
2014-10-26 23:50 - 2014-10-26 23:52 - 195895978 _____ () C:\Users\Hendrik\Documents\clip0916.avi
2014-10-25 23:09 - 2014-10-25 23:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2014-10-24 23:21 - 2014-10-24 23:21 - 25336014 _____ () C:\Users\Hendrik\Documents\clip0915.avi
2014-10-24 23:13 - 2014-10-24 23:13 - 06658282 _____ () C:\Users\Hendrik\Documents\clip0914.avi
2014-10-21 15:36 - 2014-10-21 15:36 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-21 15:36 - 2014-10-21 15:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\Program Files\iTunes
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-21 15:35 - 2014-10-21 15:35 - 00000000 ____D () C:\Program Files\iPod
2014-10-21 13:47 - 2014-10-21 13:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\pdfforge
2014-10-20 11:42 - 2014-10-20 11:42 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Oracle
2014-10-20 11:24 - 2014-10-20 11:23 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-10-20 11:23 - 2014-10-20 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-20 00:40 - 2014-10-20 01:10 - 2638644386 _____ () C:\Users\Hendrik\Documents\clip0913.avi
2014-10-19 18:19 - 2014-10-19 18:19 - 00613203 _____ () C:\Users\Hendrik\Downloads\Plain Cloud_1.0(1).zip
2014-10-19 17:50 - 2014-10-19 17:50 - 00613203 _____ () C:\Users\Hendrik\Downloads\Plain Cloud_1.0.zip
2014-10-19 17:18 - 2014-10-19 17:18 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Python
2014-10-19 17:18 - 2014-10-19 17:18 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\ActiveState
2014-10-19 17:10 - 2014-10-19 18:05 - 00000000 ____D () C:\Users\Hendrik\Downloads\Whatsapp_Xtract_V2.2_2012-11-17
2014-10-19 15:38 - 2014-11-04 23:21 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Apple Inc
2014-10-15 21:36 - 2014-10-15 21:36 - 00144627 _____ () C:\Users\Hendrik\Downloads\NB SB.aac
2014-10-15 10:55 - 2014-10-15 10:55 - 00000000 ____H () C:\Users\Hendrik\Desktop\~WRL0254.tmp
2014-10-15 10:53 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 10:53 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-15 10:53 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2014-10-15 10:53 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 10:52 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-10-15 10:52 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-10-15 10:52 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-10-15 10:52 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-15 10:52 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-10-15 10:52 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-15 10:52 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-15 10:52 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2014-10-15 10:52 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-10-15 10:52 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-15 10:52 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-15 10:52 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-15 10:52 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-15 10:52 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-15 10:52 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-15 10:52 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-15 10:52 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2014-10-15 10:52 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2014-10-15 10:52 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-10-15 10:52 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-10-15 10:52 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-10-15 10:52 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-15 10:52 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-15 10:51 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-15 10:51 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-15 10:50 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-15 10:50 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 10:50 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-15 10:50 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-15 10:50 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-15 10:50 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-15 10:50 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 10:50 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 10:50 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 10:50 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 10:50 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-15 10:50 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 10:50 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 10:50 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 10:50 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 10:50 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 10:50 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 10:50 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 10:50 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 10:50 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 10:50 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 10:50 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-15 10:50 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 10:50 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 10:50 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 10:50 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-15 10:50 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 10:50 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 10:50 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-15 10:50 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 10:50 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-15 10:50 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 10:50 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-15 10:50 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-15 10:50 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-15 10:50 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-15 10:50 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-15 10:50 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-15 10:50 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 10:50 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 10:50 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 10:50 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 10:50 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 10:50 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-15 10:50 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-15 10:50 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-15 10:50 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 10:50 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-15 10:50 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 10:50 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-15 10:50 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-15 10:49 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-15 10:49 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-15 10:48 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 10:48 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-15 10:48 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 10:48 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 10:48 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-15 10:48 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-15 10:48 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-15 10:48 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 10:48 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-15 10:46 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 10:46 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-15 10:46 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 10:46 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll


==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 09:54 - 2009-07-14 05:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-11 09:54 - 2009-07-14 05:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-11 09:51 - 2012-02-20 09:59 - 00000000 ___HD () C:\ASUS.DAT
2014-11-11 09:51 - 2011-11-18 22:11 - 01081600 _____ () C:\Windows\WindowsUpdate.log
2014-11-11 09:50 - 2012-04-12 17:11 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-11 09:50 - 2012-04-12 17:11 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-11 09:45 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-11 09:44 - 2014-01-03 20:01 - 00040939 _____ () C:\Windows\setupact.log
2014-11-11 07:08 - 2013-10-16 10:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-10 21:05 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-11-10 21:03 - 2014-02-15 20:18 - 00299502 _____ () C:\Windows\PFRO.log
2014-11-10 20:44 - 2011-11-18 22:28 - 00000000 ____D () C:\ProgramData\Temp
2014-11-10 19:51 - 2012-05-02 16:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 19:49 - 2013-01-12 14:29 - 00000000 ____D () C:\ProgramData\Package Cache
2014-11-10 19:21 - 2013-01-28 17:23 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{40B698CB-62BD-4EE1-A271-0656D24B8F85}
2014-11-07 15:03 - 2013-12-08 21:30 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-11-06 21:56 - 2013-10-19 22:00 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\vlc
2014-11-06 20:11 - 2011-11-18 22:28 - 00001860 _____ () C:\Windows\system32\ServiceFilter.ini
2014-11-06 18:28 - 2012-02-20 09:58 - 00000000 ____D () C:\Users\Hendrik
2014-11-06 15:38 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-06 15:31 - 2014-08-15 17:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iMobie
2014-11-06 15:31 - 2014-08-15 16:39 - 00000000 ____D () C:\Program Files (x86)\iMobie
2014-11-05 15:55 - 2012-02-20 10:27 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Apple Computer
2014-11-04 17:58 - 2014-01-28 14:11 - 00000000 ____D () C:\Users\Hendrik\Desktop\sortieren
2014-11-04 17:07 - 2012-02-20 10:15 - 00000000 ____D () C:\Users\Hendrik\Desktop\Programme
2014-11-04 10:10 - 2013-03-18 12:04 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\uTorrent
2014-11-03 14:08 - 2012-02-20 09:59 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-11-02 11:26 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-01 12:33 - 2014-08-15 16:39 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\iMobie
2014-11-01 12:33 - 2014-08-15 16:39 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\iMobie_Inc
2014-10-30 12:25 - 2012-04-27 08:56 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-29 18:46 - 2014-10-06 11:03 - 00000000 ____D () C:\Users\Hendrik\Desktop\Bewerbungen Verena
2014-10-29 15:13 - 2012-02-20 11:41 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Skype
2014-10-29 15:02 - 2012-02-20 11:41 - 00000000 ____D () C:\ProgramData\Skype
2014-10-29 15:01 - 2014-08-11 20:27 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-10-29 13:48 - 2014-08-20 17:26 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Adobe
2014-10-29 13:47 - 2013-10-16 10:01 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-29 13:47 - 2013-10-16 10:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-29 13:47 - 2013-10-16 10:01 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-27 17:46 - 2012-04-12 15:48 - 00000000 ____D () C:\Users\Hendrik\.gimp-2.6
2014-10-27 12:07 - 2011-02-19 10:08 - 00745910 _____ () C:\Windows\system32\perfh007.dat
2014-10-27 12:07 - 2011-02-19 10:08 - 00162816 _____ () C:\Windows\system32\perfc007.dat
2014-10-27 12:07 - 2009-07-14 06:13 - 01732678 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-25 23:11 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-25 23:09 - 2012-03-14 13:46 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-10-24 11:45 - 2012-04-12 17:11 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-24 11:45 - 2012-04-12 17:11 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-22 11:07 - 2014-06-10 18:44 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\7-PDFSplitMerge
2014-10-22 08:02 - 2012-11-20 10:20 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-10-22 07:59 - 2013-11-20 16:47 - 00000000 ____D () C:\ProgramData\MAGIX
2014-10-21 19:03 - 2012-02-20 10:27 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Apple Computer
2014-10-21 15:35 - 2014-09-10 23:19 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-20 11:24 - 2013-10-19 11:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-20 11:23 - 2012-02-22 16:25 - 00000000 ____D () C:\Program Files (x86)\Java
2014-10-20 10:54 - 2009-07-14 05:45 - 00518968 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-19 17:25 - 2012-02-20 09:59 - 00160264 _____ () C:\Users\Hendrik\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-19 15:56 - 2013-12-17 15:19 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\C24C21DE-B653-4E21-81BE-22AF552FB2ED.aplzod
2014-10-19 15:53 - 2012-03-17 13:25 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Microsoft Help
2014-10-17 17:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-10-16 00:16 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-15 22:29 - 2013-01-09 22:52 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-10-15 22:29 - 2012-02-22 13:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\DVDVideoSoft
2014-10-15 22:27 - 2012-02-22 13:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-10-15 17:33 - 2014-05-06 23:24 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-10-15 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-10-15 17:01 - 2012-03-17 13:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 16:47 - 2013-08-19 02:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 16:38 - 2012-10-20 09:57 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Windows Live
2014-10-15 16:19 - 2012-02-21 18:34 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-06 14:23

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-11-2014 01
Ran by Hendrik at 2014-11-11 10:01:27
Running from C:\Users\Hendrik\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\uTorrent) (Version: 3.4.2.34309 - BitTorrent Inc.)
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-PDF Split & Merge Version 2.1.0 (Build 128) (HKLM-x32\...\7-PDF Split & Merge_is1) (Version: 7-PDF Split & Merge - Version 2.1.0 (Build 128) - 7-PDF, Germany - Thorsten Hodes)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
ANNO 1503 GOLD (HKLM-x32\...\{DB833EF9-A198-49BE-970A-BD46F30BFBB4}) (Version: 1.05.00 - )
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo StartUp Tuner 2.00 (HKLM-x32\...\Ashampoo StartUp Tuner 2_is1) (Version: 2.0.0 - ashampoo GmbH & Co. KG)
ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.14 - ASUS)
ASUS FancyStart (HKLM-x32\...\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}) (Version: 1.1.1 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.22 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.0.6 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS)
ASUS Secure Delete (HKLM\...\{761C6783-D3BC-48AB-8E7C-61CE918A8436}) (Version: 1.00.0007 - ASUS)
ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0033 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.84.161 - eCareme Technologies, Inc.)
Asus_PSeries_Screensaver (HKLM-x32\...\Asus_PSeries_Screensaver) (Version: 1.0.0001 - ASUS)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.4.617 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS)
Audacity 2.0.4 (HKLM-x32\...\Audacity_is1) (Version: 2.0.4 - Audacity Team)
Audiodope 0.24 (HKLM-x32\...\Audiodope_is1) (Version:  - Audiodope Team)
AVI Splitter (HKLM-x32\...\AVI Splitter_is1) (Version:  - )
Benutzerhandbuch - Grundlagen EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Bog) (Version:  - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (x32 Version: 13.50.854.0 - Logitech) Hidden
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5067 - CDBurnerXP)
Cinergy T USB XE V6.11.23.01 (HKLM-x32\...\Cinergy T USB XE) (Version: 6.11.23.01 - )
Cinergy T-Stick V8.08.18.01 (HKLM-x32\...\Cinergy T-Stick) (Version: 8.08.18.01 - )
ClipGrab 3.4.7 (HKLM-x32\...\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version:  - Philipp Schmieder Medien)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.)
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.6.1622 - CyberLink Corp.)
CyberLink PowerRecover (Version: 5.6.1622 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Debut Video Capture Software (HKLM-x32\...\Debut) (Version:  - NCH Software)
Diercke Globus Online (HKLM-x32\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH)
Dropbox (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Dropbox) (Version: 2.10.29 - Dropbox, Inc.)
Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.1.1 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print 2 (HKLM-x32\...\{30E01116-5666-4807-8EF1-D80E9FF16717}) (Version: 2.3.2.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM-x32\...\{BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}) (Version: 3.01.0000 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON XP-302 303 305 306 Series Printer Uninstall (HKLM\...\EPSON XP-302 303 305 306 Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
ETDWare PS/2-X64 8.0.5.3_WHQL (HKLM\...\Elantech) (Version: 8.0.5.3 - ELAN Microelectronic Corp.)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.9 - ASUS)
Filedrop version 1.1.4 (HKLM-x32\...\{3A309583-1B4A-4C90-85EA-124EB8DB331A}_is1) (Version: 1.1.4 - Filedrop)
Folienviewer2 (HKLM-x32\...\Folienviewer2) (Version: 1.01 - Imagon GmbH)
FormatFactory 3.2.1.0 (HKLM-x32\...\FormatFactory) (Version: 3.2.1.0 - Free Time)
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
Free YouTube to iPod Converter version 3.10.37.1212 (HKLM-x32\...\Free YouTube to iPod Converter_is1) (Version: 3.10.37.1212 - DVDVideoSoft Ltd.)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
HyperCam 2 (HKLM\...\HyperCam 2) (Version: 2.25.01 - Hyperionics Technology LLC)
iCloud (HKLM\...\{6096C0CC-7E19-4355-87F0-627EC5AA146D}) (Version: 4.0.3.56 - Apple Inc.)
iExplorer 2.2.1.3 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant, LLC)
iFunbox (v2.7.2386.747), iFunbox DevTeam (HKLM-x32\...\iFunbox_is1) (Version: v2.7.2386.747 - )
Image Resizer for Windows (64 bit) (Version: 3.0.4442.6002 - Brice Lambson) Hidden
Image Resizer for Windows (HKLM-x32\...\{9dfff2f7-5cd7-4fd4-9b75-7d53b042d94b}) (Version: 3.0.4442.6002 - Brice Lambson)
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{A0E106D2-4815-4B7A-BAA7-7E21B530CFB4}) (Version: 1.1.0.0157 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{006B5C65-3938-4246-B182-994A7E415EDE}) (Version: 1.1.0.0537 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH)
Join Air (HKLM-x32\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.1 - ZTE Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.31 - Logitech Inc.)
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
ManyCam 3.0.80 (remove only) (HKLM-x32\...\ManyCam) (Version: 3.0.80 - ManyCam LLC)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 33.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.1 (x86 de)) (Version: 33.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Netzwerkhandbuch EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Netg) (Version:  - )
Notebook Interactive Viewer (HKLM-x32\...\{24BA79B5-53F9-475C-9D49-EC4BDE8B09CF}) (Version: 9.5.126.5 - SMART Technologies Inc.)
Nuance PDF Reader (HKLM-x32\...\{B480904D-F73F-4673-B034-8A5F492C9184}) (Version: 6.00.0041 - Nuance Communications, Inc.)
Opera Stable 18.0.1284.63 (HKLM-x32\...\Opera 18.0.1284.63) (Version: 18.0.1284.63 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.0.11.77 - Electronic Arts, Inc.)
PC-WELT-TuneUpSuite 1.0 (HKLM-x32\...\{36B01464-5050-4492-BAA3-46E62551EEAB}_is1) (Version:  - IDG Magazine Media GmbH)
PDF Split And Merge Basic (HKLM\...\{C91B24F6-1629-11E2-B696-21676188709B}) (Version: 2.2.2 - Andrea Vacondio)
Politik transparent (HKLM-x32\...\{B8591E60-8A0E-43F9-A82D-7EAE368A8BBC}) (Version: 1.00.0000 - Bildungshaus Schulbuchverlage Westermann Schroedel Diesterweg Schöningh Winklers GmbH)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.8 - ASUS)
Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
Software Updater (HKLM-x32\...\{A3B308B9-BE96-4334-816F-3D82B19A7DE2}) (Version: 4.1.7 - SEIKO EPSON CORPORATION)
Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
SopCast 3.8.3 (HKLM-x32\...\SopCast) (Version: 3.8.3 - www.sopcast.com)
Splashtop Software Updater (HKLM-x32\...\Splashtop Software Updater) (Version: 1.5.6.14 - Splashtop Inc.)
Splashtop Streamer (HKLM-x32\...\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.4.0.1 - Splashtop Inc.)
Spotify (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com)
StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version:  - )
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
syncables desktop SE (HKLM-x32\...\{341697D8-9923-445E-B42A-529E5A99CB7A}) (Version: 5.5.746.11492 - syncables)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.24482 - TeamViewer)
Torrent Stream 1.0.6 (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\TorrentStream) (Version: 1.0.6 - Torrent Stream)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.1 - ASUS)
Wireless Console 3 (HKLM-x32\...\{8150221C-8F7E-4997-AD4E-AFDEE7F4B410}) (Version: 3.0.21 - ASUS)
Yahoo! Detect (HKLM-x32\...\YTdetect) (Version:  - )
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================

10-11-2014 21:28:57 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2014-11-10 21:05 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0DCC669E-305D-4490-A22A-DACF8ACDA332} - System32\Tasks\{2538AA23-41A8-46F9-A9B8-1600A487A194} => E:\Launch.exe
Task: {175D2B5D-9282-4DAB-AFE5-11C45F41FFB4} - System32\Tasks\Security Center Update - 1783181859 => C:\Users\Hendrik\AppData\Roaming\Gyxyewlu\useruw.exe <==== ATTENTION
Task: {3B213F98-6641-44F4-8CB8-1F4564F105BF} - System32\Tasks\Security Center Update - 279616795 => C:\Users\Hendrik\AppData\Roaming\Baexkir\ybibeq.exe <==== ATTENTION
Task: {43C8FC67-FE7A-400D-B176-A7BA5670AAC8} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduamon.exe
Task: {4BD9B6A0-BF11-446B-8759-2ED56E4BF34D} - System32\Tasks\{86C211C5-1FA9-4FB3-AC24-7E9E7FB67409} => E:\Install.exe
Task: {4FEAFF65-7EAC-4AB6-B595-81CE32212A34} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-12] (Google Inc.)
Task: {5379F8D5-FD26-45BD-9BA2-807F743E5F9D} - \Security Center Update - 2964684536 No Task File <==== ATTENTION
Task: {5BCFBD93-1AF7-436D-A7B4-93DA8DB9ACE8} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS)
Task: {607DF730-0AA8-4FC8-B700-0BA42F63D2F0} - System32\Tasks\Security Center Update - 3634134863 => C:\Users\Hendrik\AppData\Roaming\Vyyhxe\xunoik.exe <==== ATTENTION
Task: {74A6AE27-5B37-403C-90E2-F82BD52EFD7C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {823355DA-B080-4C2E-8E9F-D7DF9F5AE4EF} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {845121B3-024E-43FD-9DDA-813E16664F90} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: {88A197AC-BAAA-491A-BB7B-74B5901A114B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-29] (Adobe Systems Incorporated)
Task: {A117D9B8-4DD6-41F5-8DF6-9B965A73444A} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-08-31] (ASUSTeK Computer Inc.)
Task: {B55C227F-8780-44C4-A6F6-D10F1B3D2A77} - System32\Tasks\ASUS Secure Delete => C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe [2011-01-24] ()
Task: {C1376A8C-6329-4AB1-A91F-09D10534B1E5} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS)
Task: {C5263A43-5637-4F45-A703-1D997E5E657A} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-05-30] (ASUS)
Task: {C86F9397-3A3B-42CA-8E8D-09C4EC4F269B} - System32\Tasks\{5E595A7B-3F2A-4C14-AE3D-C733F9915D0E} => E:\Launch.exe
Task: {DDEE7187-E174-496B-9B6A-6A10147BE6C6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-12] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2014-03-11 15:29 - 2009-08-31 10:43 - 00241664 _____ () C:\Program Files (x86)\Join Air\AssistantServices.exe
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2011-01-24 19:55 - 2011-01-24 19:55 - 00541696 _____ () C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-09-06 04:29 - 2011-05-24 01:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-03-11 15:29 - 2009-08-31 10:43 - 00132608 _____ () C:\Program Files (x86)\Join Air\UIExec.exe
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-08-31 15:33 - 2011-08-31 15:33 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
2011-05-30 22:48 - 2011-05-30 22:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2011-06-10 19:49 - 2011-06-10 19:49 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2014-11-10 18:59 - 2014-11-10 19:00 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:3E7393FC
AlternateDataStreams: C:\ProgramData\Temp:D20FFA63

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: EEventManager => "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Hendrik\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: UIExec => "C:\Program Files (x86)\Join Air\UIExec.exe"
MSCONFIG\startupreg: Wisdom-soft AutoScreenRecorder 3.1 Free => 0

========================= Accounts: ==========================

Administrator (S-1-5-21-1724138799-3868663929-1243099489-500 - Administrator - Disabled)
Gast (S-1-5-21-1724138799-3868663929-1243099489-501 - Limited - Disabled)
Hendrik (S-1-5-21-1724138799-3868663929-1243099489-1000 - Administrator - Enabled) => C:\Users\Hendrik
HomeGroupUser$ (S-1-5-21-1724138799-3868663929-1243099489-1002 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/10/2014 09:49:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000000000
ID des fehlerhaften Prozesses: 0x1dd8
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3

Error: (11/10/2014 09:16:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24
Ausnahmecode: 0xc000000d
Fehleroffset: 0x00000000000731cb
ID des fehlerhaften Prozesses: 0x1a90
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3

Error: (11/10/2014 08:15:21 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\wbem\wmiprvse.exe; Beschreibung = ComboFix created restore point; Fehler = 0x80042306).

Error: (11/10/2014 08:15:15 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 0000000000000144,0x0053c06c,00000000002503D0,0,000000000013ED60,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/10/2014 08:15:01 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 0000000000000104,0x0053c06c,000000000013E570,0,000000000013D560,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/10/2014 08:14:47 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 0000000000000184,0x0053c06c,000000000013E570,0,000000000013D560,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/10/2014 08:14:31 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 000000000000018C,0x0053c06c,000000000013E570,0,000000000013D560,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/10/2014 08:14:18 PM) (Source: VSS) (EventID: 12289) (User: )
Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "DeviceIoControl(\\?\Volume{f1f23644-1228-11e1-9c08-806e6f6e6963} - 0000000000000144,0x0053c06c,000000000013DD70,0,000000000013CD60,4096,[0])". hr = 0x8007045d, Die Anforderung konnte wegen eines E/A-Gerätefehlers nicht ausgeführt werden.
.


Vorgang:
  Ein Vergleichsbereichvolume wird automatisch ausgewählt
  EndPrepareSnapshots wird verarbeitet

Kontext:
  Ausführungskontext: System Provider

Error: (11/10/2014 07:27:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: wmpnscfg.exe, Version: 12.0.7600.16385, Zeitstempel: 0x4a5bd026
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000004847e
ID des fehlerhaften Prozesses: 0x27d0
Startzeit der fehlerhaften Anwendung: 0xwmpnscfg.exe0
Pfad der fehlerhaften Anwendung: wmpnscfg.exe1
Pfad des fehlerhaften Moduls: wmpnscfg.exe2
Berichtskennung: wmpnscfg.exe3

Error: (11/10/2014 07:27:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: wmpnscfg.exe, Version: 12.0.7600.16385, Zeitstempel: 0x4a5bd026
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000004847e
ID des fehlerhaften Prozesses: 0x210c
Startzeit der fehlerhaften Anwendung: 0xwmpnscfg.exe0
Pfad der fehlerhaften Anwendung: wmpnscfg.exe1
Pfad des fehlerhaften Moduls: wmpnscfg.exe2
Berichtskennung: wmpnscfg.exe3


System errors:
=============
Error: (11/11/2014 09:45:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WebcamMax, WDM Video Capture" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1058

Error: (11/11/2014 09:45:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "lxdu_device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (11/10/2014 10:23:09 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Intel(R) Management and Security Application User Notification Service" wurde nicht richtig gestartet.

Error: (11/10/2014 10:21:09 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (11/10/2014 10:15:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WebcamMax, WDM Video Capture" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1058

Error: (11/10/2014 10:14:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "lxdu_device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (11/10/2014 10:11:21 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Intel(R) Management and Security Application User Notification Service" wurde nicht richtig gestartet.

Error: (11/10/2014 10:09:21 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (11/10/2014 10:03:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WebcamMax, WDM Video Capture" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1058

Error: (11/10/2014 10:02:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "lxdu_device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2


Microsoft Office Sessions:
=========================
Error: (08/26/2014 04:52:59 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6700.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1784 seconds with 960 seconds of active time.  This session ended with a crash.

Error: (04/06/2014 05:25:31 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (02/18/2014 07:27:55 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 64 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (05/16/2013 04:00:44 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1650 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (09/25/2012 03:45:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 904 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2014-11-10 20:52:24.253
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-11-10 20:52:24.211
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-26 10:55:36.047
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-26 10:55:35.965
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz
Percentage of memory in use: 47%
Total physical RAM: 4008.17 MB
Available physical RAM: 2101.68 MB
Total Pagefile: 8014.52 MB
Available Pagefile: 6003.84 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:11.41 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:153.85 GB) (Free:22.95 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=119.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=153.9 GB) - (Type=07 NTFS)

==================== End Of Log ============================


deeprybka 11.11.2014 12:22

Hi...Wie gehts, wie stehts? ;)

Wie läuft der Rechner nach den folgenden Schritten:

Schritt 1

http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...st/frstfix.png

Drücke bitte die http://deeprybka.trojaner-board.de/b...ne/revo/w7.png + R Taste und schreibe notepad in das Ausführen Fenster.
Klicke auf OK und kopiere nun den Text aus der Codebox in das leere Textdokument:
Code:

CloseProcesses:
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [Wiuhyfreyquwh] => "C:\Users\Hendrik\AppData\Roaming\Urmytiyf\ywwego.exe"
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
S1 brdzkxcp; \??\C:\Windows\system32\drivers\brdzkxcp.sys [X]
S1 gucgznbc; \??\C:\Windows\system32\drivers\gucgznbc.sys [X]
S1 inqltdso; \??\C:\Windows\system32\drivers\inqltdso.sys [X]
S1 laaolckg; \??\C:\Windows\system32\drivers\laaolckg.sys [X]
S1 lxukkwfx; \??\C:\Windows\system32\drivers\lxukkwfx.sys [X]
S1 vngoazpn; \??\C:\Windows\system32\drivers\vngoazpn.sys [X]
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Gyxyewlu
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Baexkir
2014-11-08 11:48 - 2014-11-08 11:48 - 00003834 _____ () C:\Windows\System32\Tasks\Security Center Update - 1783181859
2014-11-08 11:48 - 2014-11-08 11:48 - 00003830 _____ () C:\Windows\System32\Tasks\Security Center Update - 279616795
2014-11-08 11:48 - 2014-11-08 11:48 - 00003826 _____ () C:\Windows\System32\Tasks\Security Center Update - 3634134863
2014-11-08 11:47 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Vyyhxe
2014-11-04 22:47 - 2014-11-05 15:52 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Urmytiyf
2014-11-04 21:50 - 2014-11-06 13:44 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
File: C:\Windows\SysWOW64\acovcnt.exe
Task: {175D2B5D-9282-4DAB-AFE5-11C45F41FFB4} - System32\Tasks\Security Center Update - 1783181859 => C:\Users\Hendrik\AppData\Roaming\Gyxyewlu\useruw.exe <==== ATTENTION
Task: {3B213F98-6641-44F4-8CB8-1F4564F105BF} - System32\Tasks\Security Center Update - 279616795 => C:\Users\Hendrik\AppData\Roaming\Baexkir\ybibeq.exe <==== ATTENTION
Task: {5379F8D5-FD26-45BD-9BA2-807F743E5F9D} - \Security Center Update - 2964684536 No Task File <==== ATTENTION
Task: {607DF730-0AA8-4FC8-B700-0BA42F63D2F0} - System32\Tasks\Security Center Update - 3634134863 => C:\Users\Hendrik\AppData\Roaming\Vyyhxe\xunoik.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:3E7393FC
AlternateDataStreams: C:\ProgramData\Temp:D20FFA63
EmptyTemp:

Speichere dieses bitte als Fixlist.txt in das Verzeichnis ab, in dem sich auch die FRST-Anwendung befindet.
  • Starte FRST und drücke auf den Fix-Button.
  • Das Tool erstellt eine "Fixlog.txt" -Datei.
  • Poste mir bitte deren Inhalt.

Schritt 2


Downloade Dir HitmanProhttp://deeprybka.trojaner-board.de/b.../hitmanpro.pngauf Deinen Desktop:

HitmanPro-32 Bit Version
HitmanPro-64 Bit Version
Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset



Schritt 4
Downloade dir bitte Farbar Service Scanner Farbar Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.

Poste bitte den Inhalt hier.




Schritt 5

http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png

Bitte starte FRST erneut, markiere auch die checkbox http://deeprybka.trojaner-board.de/b...t/addition.pngund drücke auf Scan.
Bitte poste mir den Inhalt der beiden Logs die erstellt werden.

Anchovi 11.11.2014 14:21

Hi!

Der Rechner läuft wieder sehr gut, auch mein Microsoft Security Essential meldet nach einem Schnellscan keinerlei Schadprogramme mehr. Habe aber jetzt dennoch Schritt 1 gestartet. Sollte ich die von dir beschriebenen Schritte dennoch durchführen?

LG Anchovi

Schritt 1:
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-11-2014 01
Ran by Hendrik at 2014-11-11 13:56:38 Run:1
Running from C:\Users\Hendrik\Desktop\FRST
Loaded Profiles: Hendrik & DefaultAppPool (Available profiles: Hendrik & DefaultAppPool)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
CloseProcesses:
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [Wiuhyfreyquwh] => "C:\Users\Hendrik\AppData\Roaming\Urmytiyf\ywwego.exe"
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
S1 brdzkxcp; \??\C:\Windows\system32\drivers\brdzkxcp.sys [X]
S1 gucgznbc; \??\C:\Windows\system32\drivers\gucgznbc.sys [X]
S1 inqltdso; \??\C:\Windows\system32\drivers\inqltdso.sys [X]
S1 laaolckg; \??\C:\Windows\system32\drivers\laaolckg.sys [X]
S1 lxukkwfx; \??\C:\Windows\system32\drivers\lxukkwfx.sys [X]
S1 vngoazpn; \??\C:\Windows\system32\drivers\vngoazpn.sys [X]
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Gyxyewlu
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Baexkir
2014-11-08 11:48 - 2014-11-08 11:48 - 00003834 _____ () C:\Windows\System32\Tasks\Security Center Update - 1783181859
2014-11-08 11:48 - 2014-11-08 11:48 - 00003830 _____ () C:\Windows\System32\Tasks\Security Center Update - 279616795
2014-11-08 11:48 - 2014-11-08 11:48 - 00003826 _____ () C:\Windows\System32\Tasks\Security Center Update - 3634134863
2014-11-08 11:47 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Vyyhxe
2014-11-04 22:47 - 2014-11-05 15:52 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Urmytiyf
2014-11-04 21:50 - 2014-11-06 13:44 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
File: C:\Windows\SysWOW64\acovcnt.exe
Task: {175D2B5D-9282-4DAB-AFE5-11C45F41FFB4} - System32\Tasks\Security Center Update - 1783181859 => C:\Users\Hendrik\AppData\Roaming\Gyxyewlu\useruw.exe <==== ATTENTION
Task: {3B213F98-6641-44F4-8CB8-1F4564F105BF} - System32\Tasks\Security Center Update - 279616795 => C:\Users\Hendrik\AppData\Roaming\Baexkir\ybibeq.exe <==== ATTENTION
Task: {5379F8D5-FD26-45BD-9BA2-807F743E5F9D} - \Security Center Update - 2964684536 No Task File <==== ATTENTION
Task: {607DF730-0AA8-4FC8-B700-0BA42F63D2F0} - System32\Tasks\Security Center Update - 3634134863 => C:\Users\Hendrik\AppData\Roaming\Vyyhxe\xunoik.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:3E7393FC
AlternateDataStreams: C:\ProgramData\Temp:D20FFA63
EmptyTemp:
*****************

Processes closed successfully.
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Wiuhyfreyquwh => value deleted successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully.
"HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found.
brdzkxcp => Service deleted successfully.
gucgznbc => Service deleted successfully.
inqltdso => Service deleted successfully.
laaolckg => Service deleted successfully.
lxukkwfx => Service deleted successfully.
vngoazpn => Service deleted successfully.
C:\Users\Hendrik\AppData\Roaming\Gyxyewlu => Moved successfully.
C:\Users\Hendrik\AppData\Roaming\Baexkir => Moved successfully.
C:\Windows\System32\Tasks\Security Center Update - 1783181859 => Moved successfully.
C:\Windows\System32\Tasks\Security Center Update - 279616795 => Moved successfully.
C:\Windows\System32\Tasks\Security Center Update - 3634134863 => Moved successfully.
C:\Users\Hendrik\AppData\Roaming\Vyyhxe => Moved successfully.
C:\Users\Hendrik\AppData\Roaming\Urmytiyf => Moved successfully.
C:\ProgramData\Windows Genuine Advantage => Moved successfully.

========================= File: C:\Windows\SysWOW64\acovcnt.exe ========================

MD5: 6BCAF46E2B7FA9ACE92B4D39F3037C5C
Creation and modification date: 2012-02-20 09:59 - 2014-11-03 14:08
Size: 0045056
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product Name:
Description:
File Version:
Product Version:
Copyright:

====== End Of File: ======

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{175D2B5D-9282-4DAB-AFE5-11C45F41FFB4}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{175D2B5D-9282-4DAB-AFE5-11C45F41FFB4}" => Key deleted successfully.
C:\Windows\System32\Tasks\Security Center Update - 1783181859 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 1783181859" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3B213F98-6641-44F4-8CB8-1F4564F105BF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B213F98-6641-44F4-8CB8-1F4564F105BF}" => Key deleted successfully.
C:\Windows\System32\Tasks\Security Center Update - 279616795 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 279616795" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5379F8D5-FD26-45BD-9BA2-807F743E5F9D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5379F8D5-FD26-45BD-9BA2-807F743E5F9D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 2964684536" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{607DF730-0AA8-4FC8-B700-0BA42F63D2F0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{607DF730-0AA8-4FC8-B700-0BA42F63D2F0}" => Key deleted successfully.
C:\Windows\System32\Tasks\Security Center Update - 3634134863 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 3634134863" => Key deleted successfully.
C:\ProgramData\Temp => ":3E7393FC" ADS removed successfully.
C:\ProgramData\Temp => ":D20FFA63" ADS removed successfully.
EmptyTemp: => Removed 2.3 GB temporary data.


The system needed a reboot.

==== End of Fixlog ====

Schritt 1:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-11-2014 01
Ran by Hendrik at 2014-11-11 13:56:38 Run:1
Running from C:\Users\Hendrik\Desktop\FRST
Loaded Profiles: Hendrik & DefaultAppPool (Available profiles: Hendrik & DefaultAppPool)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
CloseProcesses:
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [Wiuhyfreyquwh] => "C:\Users\Hendrik\AppData\Roaming\Urmytiyf\ywwego.exe"
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
S1 brdzkxcp; \??\C:\Windows\system32\drivers\brdzkxcp.sys [X]
S1 gucgznbc; \??\C:\Windows\system32\drivers\gucgznbc.sys [X]
S1 inqltdso; \??\C:\Windows\system32\drivers\inqltdso.sys [X]
S1 laaolckg; \??\C:\Windows\system32\drivers\laaolckg.sys [X]
S1 lxukkwfx; \??\C:\Windows\system32\drivers\lxukkwfx.sys [X]
S1 vngoazpn; \??\C:\Windows\system32\drivers\vngoazpn.sys [X]
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Gyxyewlu
2014-11-08 11:48 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Baexkir
2014-11-08 11:48 - 2014-11-08 11:48 - 00003834 _____ () C:\Windows\System32\Tasks\Security Center Update - 1783181859
2014-11-08 11:48 - 2014-11-08 11:48 - 00003830 _____ () C:\Windows\System32\Tasks\Security Center Update - 279616795
2014-11-08 11:48 - 2014-11-08 11:48 - 00003826 _____ () C:\Windows\System32\Tasks\Security Center Update - 3634134863
2014-11-08 11:47 - 2014-11-08 13:38 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Vyyhxe
2014-11-04 22:47 - 2014-11-05 15:52 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Urmytiyf
2014-11-04 21:50 - 2014-11-06 13:44 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
File: C:\Windows\SysWOW64\acovcnt.exe
Task: {175D2B5D-9282-4DAB-AFE5-11C45F41FFB4} - System32\Tasks\Security Center Update - 1783181859 => C:\Users\Hendrik\AppData\Roaming\Gyxyewlu\useruw.exe <==== ATTENTION
Task: {3B213F98-6641-44F4-8CB8-1F4564F105BF} - System32\Tasks\Security Center Update - 279616795 => C:\Users\Hendrik\AppData\Roaming\Baexkir\ybibeq.exe <==== ATTENTION
Task: {5379F8D5-FD26-45BD-9BA2-807F743E5F9D} - \Security Center Update - 2964684536 No Task File <==== ATTENTION
Task: {607DF730-0AA8-4FC8-B700-0BA42F63D2F0} - System32\Tasks\Security Center Update - 3634134863 => C:\Users\Hendrik\AppData\Roaming\Vyyhxe\xunoik.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:3E7393FC
AlternateDataStreams: C:\ProgramData\Temp:D20FFA63
EmptyTemp:
*****************

Processes closed successfully.
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Wiuhyfreyquwh => value deleted successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully.
"HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found.
brdzkxcp => Service deleted successfully.
gucgznbc => Service deleted successfully.
inqltdso => Service deleted successfully.
laaolckg => Service deleted successfully.
lxukkwfx => Service deleted successfully.
vngoazpn => Service deleted successfully.
C:\Users\Hendrik\AppData\Roaming\Gyxyewlu => Moved successfully.
C:\Users\Hendrik\AppData\Roaming\Baexkir => Moved successfully.
C:\Windows\System32\Tasks\Security Center Update - 1783181859 => Moved successfully.
C:\Windows\System32\Tasks\Security Center Update - 279616795 => Moved successfully.
C:\Windows\System32\Tasks\Security Center Update - 3634134863 => Moved successfully.
C:\Users\Hendrik\AppData\Roaming\Vyyhxe => Moved successfully.
C:\Users\Hendrik\AppData\Roaming\Urmytiyf => Moved successfully.
C:\ProgramData\Windows Genuine Advantage => Moved successfully.

========================= File: C:\Windows\SysWOW64\acovcnt.exe ========================

MD5: 6BCAF46E2B7FA9ACE92B4D39F3037C5C
Creation and modification date: 2012-02-20 09:59 - 2014-11-03 14:08
Size: 0045056
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product Name:
Description:
File Version:
Product Version:
Copyright:

====== End Of File: ======

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{175D2B5D-9282-4DAB-AFE5-11C45F41FFB4}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{175D2B5D-9282-4DAB-AFE5-11C45F41FFB4}" => Key deleted successfully.
C:\Windows\System32\Tasks\Security Center Update - 1783181859 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 1783181859" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3B213F98-6641-44F4-8CB8-1F4564F105BF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B213F98-6641-44F4-8CB8-1F4564F105BF}" => Key deleted successfully.
C:\Windows\System32\Tasks\Security Center Update - 279616795 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 279616795" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5379F8D5-FD26-45BD-9BA2-807F743E5F9D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5379F8D5-FD26-45BD-9BA2-807F743E5F9D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 2964684536" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{607DF730-0AA8-4FC8-B700-0BA42F63D2F0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{607DF730-0AA8-4FC8-B700-0BA42F63D2F0}" => Key deleted successfully.
C:\Windows\System32\Tasks\Security Center Update - 3634134863 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 3634134863" => Key deleted successfully.
C:\ProgramData\Temp => ":3E7393FC" ADS removed successfully.
C:\ProgramData\Temp => ":D20FFA63" ADS removed successfully.
EmptyTemp: => Removed 2.3 GB temporary data.


The system needed a reboot.

==== End of Fixlog ====

deeprybka 11.11.2014 14:43

Ja... Bitte alle Schritte, die sind wichtig.

Anchovi 11.11.2014 16:12

Alles klar, wird gemacht. ESET hat in den vorläufigen Suchergebnissen einen "Win32/TrojanDownloader.Wauchos.AK" Trojaner gefunden, das nur vorab, Ich lasse den Scan weiter durchlaufen und poste dann die gewünschten logs.

deeprybka 11.11.2014 16:28

Vor ESET kommt doch aber HitmanPro oder? ;)

Anchovi 11.11.2014 16:34

Ja, stimmt ;) Hab ich auch gemacht, aber wollte alle logs auf einmal posten.

Hier schonmal das log von Hitman Pro:

Code:


       
Code:

       
HitmanPro 3.7.9.232
www.hitmanpro.com

   Computer name . . . . : HENDRIK-PC
   Windows . . . . . . . : 6.1.1.7601.X64/4
   User name . . . . . . : Hendrik-PC\Hendrik
   UAC . . . . . . . . . : Disabled
   License . . . . . . . : Free

   Scan date . . . . . . : 2014-11-11 14:23:20
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 20m 20s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 75

   Objects scanned . . . : 2.567.218
   Files scanned . . . . : 245.080
   Remnants scanned  . . : 955.306 files / 1.366.832 keys

Suspicious files ____________________________________________________________

   C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
      Size . . . . . . . : 2.116.096 bytes
      Age  . . . . . . . : 0.7 days (2014-11-10 21:33:35)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : 9D17E46B4EAEC0509800C43B23765D00810EA2CEF362301BFB2E0B174DFE5AFD
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      Forensic Cluster
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe
          0.0s C:\Users\Hendrik\Desktop\FRST\FRST64(1).exe

   C:\Users\Hendrik\Downloads\FRST64.exe
      Size . . . . . . . : 2.114.560 bytes
      Age  . . . . . . . : 4.8 days (2014-11-06 18:30:29)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : 9A92493668D313771DB011C6FD2BF7B894B97281BC5E3C3DEE5C104372A33DCA
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      Forensic Cluster
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
          0.0s C:\Users\Hendrik\Downloads\FRST64.exe
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.1s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{72C03BE5-A5FC-445A-821A-B38ECCCCE00C}
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         18.2s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MetaStore\2\76\2AB4A391E48B40F0.dat
         25.5s C:\FRST\
         25.5s C:\FRST\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Logs\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Quarantine\
         25.5s C:\FRST\Hives\
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.INF
         28.9s C:\FRST\Hives\ERDNT.CON
         28.9s C:\FRST\Hives\BCD
         28.9s C:\FRST\Hives\BCD
         28.9s C:\FRST\Hives\BCD
         28.9s C:\FRST\Hives\BCD
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         28.9s C:\FRST\Hives\software
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         36.9s C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\Results\Resource\{26CD843E-7839-48D4-9584-C904EBDB71B8}
         39.7s C:\FRST\Hives\system
         39.7s C:\FRST\Hives\system
         39.7s C:\FRST\Hives\system
         39.7s C:\FRST\Hives\system
         43.1s C:\FRST\Hives\default
         43.1s C:\FRST\Hives\default
         43.1s C:\FRST\Hives\default
         43.1s C:\FRST\Hives\default
         43.1s C:\FRST\Hives\default
         43.1s C:\FRST\Hives\default
         44.2s C:\FRST\Hives\security
         44.2s C:\FRST\Hives\sam
         44.2s C:\FRST\Hives\sam
         44.2s C:\FRST\Hives\sam
         44.2s C:\FRST\Hives\sam
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\
         44.3s C:\FRST\Hives\Users\00000001\
         44.3s C:\FRST\Hives\Users\00000001\
         44.3s C:\FRST\Hives\Users\00000001\
         44.3s C:\FRST\Hives\Users\00000001\
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         44.3s C:\FRST\Hives\Users\00000001\ntuser.dat
         45.0s C:\FRST\Hives\Users\00000002\
         45.0s C:\FRST\Hives\Users\00000002\UsrClass.dat
         45.0s C:\FRST\Hives\Users\00000002\UsrClass.dat
         45.0s C:\FRST\Hives\Users\00000002\UsrClass.dat
         45.0s C:\FRST\Hives\Users\00000002\UsrClass.dat
         45.0s C:\FRST\Hives\Users\00000002\UsrClass.dat
         45.0s C:\FRST\Hives\Users\00000002\UsrClass.dat
         45.4s C:\FRST\Hives\ERDNT.EXE
         45.4s C:\FRST\Hives\ERDNT.EXE
         45.4s C:\FRST\Hives\ERDNT.EXE
         45.4s C:\FRST\Hives\ERDNT.EXE
         45.4s C:\FRST\Hives\ERDNT.EXE
         45.4s C:\FRST\Hives\ERDNT.EXE
         45.4s C:\FRST\Hives\ERDNT.EXE
         45.4s C:\FRST\Hives\ERDNT.EXE
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTWIN.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.7s C:\FRST\Hives\ERDNTDOS.LOC
         45.8s C:\Users\Hendrik\Downloads\FRST.txt


Potential Unwanted Programs _________________________________________________

   C:\ProgramData\EmailNotifier\ (MyStart)
   C:\ProgramData\EmailNotifier\AOL.lnk (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\ (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\0\ (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\0\config.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\0\confignologin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\0\configpin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\0\splash_icon.gif (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\0\splash_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\0\tb_icon.ico (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\0\tb_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\1\ (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\1\config.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\1\confignologin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\1\configpin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\1\splash_icon.gif (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\1\splash_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\1\tb_icon.ico (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\1\tb_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\2\ (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\2\config.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\2\confignologin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\2\configpin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\2\splash_icon.gif (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\2\splash_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\2\tb_icon.ico (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\2\tb_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\7\ (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\7\config.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\7\confignologin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\7\configpin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\7\splash_icon.gif (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\7\splash_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\7\tb_icon.ico (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\7\tb_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\8\ (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\8\config.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\8\confignologin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\8\configpin.xml (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\8\splash_icon.gif (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\8\splash_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\8\tb_icon.ico (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\8\tb_icon.png (MyStart)
   C:\ProgramData\EmailNotifier\dtuser\dtUser.exe (MyStart)
      Size . . . . . . . : 338.016 bytes
      Age  . . . . . . . : 358.9 days (2013-11-17 16:07:24)
      Entropy  . . . . . : 6.9
      SHA-256  . . . . . : 4C4A4215BD2BE8FD6DC4988EB103CFEFE49FA1860DF441128C78FEC388F77B68
      Publisher  . . . . : Visicom Media Inc.
      Description  . . . : DtUser(Email)
      Version  . . . . . : 1.0.0.109
      Copyright  . . . . : © 2010-2013 Visicom Media Inc.
      RSA Key Size . . . : 2048
      Authenticode . . . : Invalid
      Fuzzy  . . . . . . : 20.0
      References
         C:\ProgramData\EmailNotifier\AOL.lnk
         C:\ProgramData\EmailNotifier\Gmail.lnk
         C:\ProgramData\EmailNotifier\Hotmail.lnk
         C:\ProgramData\EmailNotifier\RRTimeWarner.lnk
         C:\ProgramData\EmailNotifier\Yahoo.lnk

   C:\ProgramData\EmailNotifier\EmailNotifier.exe (MyStart)
      Size . . . . . . . : 1.240.672 bytes
      Age  . . . . . . . : 358.9 days (2013-11-17 16:07:20)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 57A1A4AB0793689F587816A30F1E51A97C4BF0230998985854933C4349DF102F
      Product  . . . . . : Email Notifier (TimeWarner Edition)
      Publisher
      Description  . . . : Email Notifier User Interface
      Version  . . . . . : 1.0.1.22
      RSA Key Size . . . : 2048
      LanguageID . . . . : 4105
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -4.0

   C:\ProgramData\EmailNotifier\EmailNotifier.xml (MyStart)
   C:\ProgramData\EmailNotifier\EmailNotifierAPI.dll (MyStart)
      Size . . . . . . . : 858.584 bytes
      Age  . . . . . . . : 358.9 days (2013-11-17 16:07:20)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : F41783CDE97511F0DE13485FCCCB8B75A6C2EA9053ECF96D84A28EDD911E42A2
      Product  . . . . . : Email Notifier
      Publisher
      Description  . . . : Email Notifier API
      Version  . . . . . : 1.0.0.58
      RSA Key Size . . . : 2048
      LanguageID . . . . : 4105
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -4.0

   C:\ProgramData\EmailNotifier\EmailNotifierEN.lng (MyStart)
   C:\ProgramData\EmailNotifier\EmailNotifierFR.lng (MyStart)
   C:\ProgramData\EmailNotifier\EmailNotifierHI.lng (MyStart)
   C:\ProgramData\EmailNotifier\EmailNotifierPOL.lng (MyStart)
   C:\ProgramData\EmailNotifier\EmailNotifierRO.lng (MyStart)
   C:\ProgramData\EmailNotifier\EmailNotifierRU.lng (MyStart)
   C:\ProgramData\EmailNotifier\EmailNotifierTHAI.lng (MyStart)
   C:\ProgramData\EmailNotifier\EmailNotifierTUR.lng (MyStart)
   C:\ProgramData\EmailNotifier\Gmail.lnk (MyStart)
   C:\ProgramData\EmailNotifier\Hotmail.lnk (MyStart)
   C:\ProgramData\EmailNotifier\RRTimeWarner.lnk (MyStart)
   C:\ProgramData\EmailNotifier\Yahoo.lnk (MyStart)
   HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0C5365B7-358F-402d-A440-F1270AEF1175}\ (MyStart)
   HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}\ (MyStart)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{58124A0B-DC32-4180-9BFF-E0E21AE34026} (Iminent)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} (Iminent)
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} (Iminent)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0C5365B7-358F-402d-A440-F1270AEF1175}\ (MyStart)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}\ (MyStart)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\TBNotifier_RASAPI32\ (AskBar)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\TBNotifier_RASMANCS\ (AskBar)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{58124A0B-DC32-4180-9BFF-E0E21AE34026} (Iminent)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} (Iminent)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} (Iminent)
   HKU\.DEFAULT\Software\AskPartnerNetwork\ (AskBar)
   HKU\S-1-5-18\Software\AskPartnerNetwork\ (AskBar)




deeprybka 11.11.2014 16:54

:daumenhoc

Anchovi 11.11.2014 18:38

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=0767c4726381b144832d7f0389457c9a
# engine=21038
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-11-11 05:34:09
# local_time=2014-11-11 06:34:09 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 5378788 38707642 0 0
# scanned=455591
# found=16
# cleaned=0
# scan_time=13477
sh=6DB3990112C0F858B0E7C606166CB69B97A550AB ft=1 fh=474d3ef3e9ceed58 vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\mystarttb\dtuser.exe.vir"
sh=356CA08ADDEC8B345F2854C3082C3F952658CA8E ft=1 fh=af6067b861516f68 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\mystarttb\mystarttb.dll.vir"
sh=06DCCB89C6121AFA797A02DA65FA95A1E4381429 ft=1 fh=74e150ef83d24130 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\NCH Software\Debut\debut.exe.vir"
sh=EE9DCE7BBF010B312AFFA06B992E3CF8761B69A9 ft=1 fh=1029c1ef39627f0d vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\NCH Software\Debut\debutsetup163_v1.63.exe.vir"
sh=54CA39AE404E7F38EB94E03E503E83AE2048381A ft=1 fh=8edf142583d24130 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\NCH Software\Debut\uninst.exe.vir"
sh=31CE21FE36C11E107A6E315EFE1875743809B4CC ft=1 fh=48abcfa6ce4a4014 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Hendrik\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=6DB3990112C0F858B0E7C606166CB69B97A550AB ft=1 fh=474d3ef3e9ceed58 vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\njlvxj07.default\Extensions\{607b689f-7600-45e4-b8e5-887f72dab15c}\dtuser.exe.vir"
sh=24EACADAF8910146B00A3B6146FAD19E11BFF03B ft=1 fh=5e1dc8d93e2d8e01 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-egypt.exe"
sh=34D77A23AA7C7648948E4BFAB31F33F517A785DC ft=1 fh=11cdaad78b073df2 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-japan.exe"
sh=E5A3C100D2D0FD94482783AF2B2FF94CDFC9923F ft=1 fh=a0ddd0619a504a2e vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst.exe"
sh=278EE35195AE43C347F49D0CA496433998E23DD4 ft=1 fh=212c5df74415422e vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="C:\ProgramData\EmailNotifier\dtuser\dtUser.exe"
sh=F726A0A47B2E762D52866C371E72CB73BF22E7B1 ft=1 fh=0ab92e385352f7f8 vn="Win32/TrojanDownloader.Wauchos.AK Trojaner" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\mslojpbc.exe.vir"
sh=278EE35195AE43C347F49D0CA496433998E23DD4 ft=1 fh=212c5df74415422e vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\All Users\EmailNotifier\dtuser\dtUser.exe"
sh=9B6954E1E6B36E385F81FCBC7ED3A5AB88E1865B ft=1 fh=48d725e0853640bd vn="Variante von Win32/Kryptik.CPUR Trojaner" ac=I fn="C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D}\api-ms-win-system-wmdrmnet-l1-1-0.dll"
sh=692B8806576717A2FD740368C21F2CBFA47A034D ft=1 fh=2914790e3b2a93d5 vn="Variante von Win32/InstallIQ.A evtl. unerwünschte Anwendung" ac=I fn="D:\Eigene Dokumente\Schule\Schuljahr 2013_14\Q1 SW\EZB-Material\EZB\PPP & Video-Dateien\FLVPlayer30Upgrade.exe"
sh=692B8806576717A2FD740368C21F2CBFA47A034D ft=1 fh=2914790e3b2a93d5 vn="Variante von Win32/InstallIQ.A evtl. unerwünschte Anwendung" ac=I fn="D:\Eigene Dokumente\Schule\Sowi_Politik\Themen 1\Wirtschaft\Wirtschaftspolitik\EZB\PPP & Video-Dateien\FLVPlayer30Upgrade.exe"


deeprybka 11.11.2014 19:05

Bitte lasse die Datei aus der Code-Box bei
http://deeprybka.trojaner-board.de/b...virustotal.png überprüfen.
  • Klicke auf Wählen Sie eine
  • Kopiere nun folgendes in die Suchleiste
    Code:

    C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D}\api-ms-win-system-wmdrmnet-l1-1-0.dll
  • und klicke auf Öffnen.
  • Klicke auf Scannen!.
  • Warte bitte bis die Datei vollständig hochgeladen wurde. Solltest Du folgende Meldung bekommen
    Zitat:

    Diese Datei wurde bereits von VirusTotal analysiert...
    klicke auf Neu analysieren.
  • Warte bis dir das Analysedatum angezeigt wird und der Scan abgeschlossen ist.
  • Kopiere den Link aus deiner Adresszeile und poste ihn hier.

Anchovi 11.11.2014 19:52

Farbar Service Scanner Version: 21-07-2014
Ran by Hendrik (administrator) on 11-11-2014 at 19:38:38
Running from "C:\Users\Hendrik\Desktop"
Microsoft Windows 7 Professional Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-11-2014 01
Ran by Hendrik (administrator) on HENDRIK-PC on 11-11-2014 19:40:54
Running from C:\Users\Hendrik\Desktop
Loaded Profile: Hendrik (Available profiles: Hendrik & DefaultAppPool)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
() C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
() C:\Program Files (x86)\Join Air\UIExec.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Farbar) C:\Users\Hendrik\Desktop\FRST64(1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-09] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2255360 2011-06-10] (ASUS)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UIExec] => C:\Program Files (x86)\Join Air\UIExec.exe [132608 2009-08-31] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-07] (Apple Inc.)
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-18\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideSCAHealth] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Hendrik\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ddg.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Webmail Ad Blocker - C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018\Extensions\gmailnoads@mywebber.com.xpi [2014-10-11]
FF Extension: Adblock Plus - C:\Users\Hendrik\AppData\Roaming\Mozilla\Firefox\Profiles\0j0h3k4m.default-1413030961018\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-11]

Chrome:
=======
CHR HomePage: Default -> chrome://newtab
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.671\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll ()
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Users\Hendrik\AppData\Roaming\Mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.670.1) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U67) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Torrent Stream P2P Multimedia Plug-in) - C:\Users\Hendrik\AppData\Roaming\TorrentStream\player\npts.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll No File
CHR Profile: C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-16]
CHR Extension: (Google Drive) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-16]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04]
CHR Extension: (YouTube) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-16]
CHR Extension: (Google-Suche) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-16]
CHR Extension: (Google Wallet) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-16]
CHR Extension: (Google Mail) - C:\Users\Hendrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-11] (Seiko Epson Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
S3 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com)
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [241664 2009-08-31] () [File not signed]
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S2 lxdu_device; C:\Windows\system32\lxducoms.exe -service [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 assd; C:\Windows\System32\Drivers\assd.sys [27264 2010-04-28] (ASUS Corporation)
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2014-11-10] (Emsisoft GmbH)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-11] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2013-12-08] (Windows (R) Win 7 DDK provider)
S2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam64.sys [1071032 2012-04-15] (Windows (R) Win 7 DDK provider)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 19:40 - 2014-11-11 19:41 - 00024071 _____ () C:\Users\Hendrik\Desktop\FRST.txt
2014-11-11 19:38 - 2014-11-11 19:38 - 00002761 _____ () C:\Users\Hendrik\Desktop\FSS.txt
2014-11-11 15:02 - 2014-11-11 15:02 - 00415232 _____ (Farbar) C:\Users\Hendrik\Desktop\FSS.exe
2014-11-11 14:45 - 2014-11-11 14:46 - 02347384 _____ (ESET) C:\Users\Hendrik\Desktop\esetsmartinstaller_deu.exe
2014-11-11 14:43 - 2014-11-11 14:43 - 00078850 _____ () C:\Users\Hendrik\Desktop\HitmanPro_20141111_1443.log
2014-11-11 14:22 - 2014-11-11 14:44 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-11-11 14:00 - 2014-11-11 14:00 - 11222744 _____ (SurfRight B.V.) C:\Users\Hendrik\Desktop\HitmanPro_x64.exe
2014-11-11 13:55 - 2014-11-11 15:01 - 00000000 ____D () C:\Users\Hendrik\Desktop\FRST
2014-11-11 12:40 - 2014-11-11 12:40 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (28)
2014-11-11 12:11 - 2014-11-11 14:21 - 00003856 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1381916617
2014-11-11 12:06 - 2014-11-11 12:06 - 00001847 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk
2014-11-11 12:06 - 2014-11-11 12:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-11-11 12:06 - 2014-11-11 12:06 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-11-11 11:54 - 2014-11-11 12:11 - 00001431 _____ () C:\Windows\SecuniaPackage.log
2014-11-11 11:36 - 2014-11-11 11:37 - 71648048 _____ (Apple Inc.) C:\Users\Hendrik\Downloads\iCloudSetup.exe
2014-11-11 11:31 - 2014-11-11 11:31 - 00001075 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
2014-11-11 11:02 - 2014-11-11 13:55 - 00000000 ____D () C:\Users\Hendrik\Desktop\Neuer Ordner
2014-11-11 10:15 - 2014-11-11 10:15 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Secunia PSI
2014-11-11 10:15 - 2014-11-11 10:15 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-11-10 23:15 - 2014-11-10 23:17 - 00000000 ____D () C:\EEK
2014-11-10 21:58 - 2014-11-10 22:19 - 00170280 _____ (ESET) C:\Windows\system32\Drivers\ESETCleanersDriver.sys
2014-11-10 21:58 - 2014-11-10 21:59 - 00007370 _____ () C:\Users\Hendrik\Downloads\ESETRovnixCleaner.exe_20141110.215848.8388.log
2014-11-10 21:58 - 2014-11-10 21:58 - 00064500 _____ () C:\Users\Hendrik\Downloads\ESETRovnixCleaner.exe_20141110.215848.8388.zip
2014-11-10 21:33 - 2014-11-10 21:35 - 02116096 _____ (Farbar) C:\Users\Hendrik\Desktop\FRST64(1).exe
2014-11-10 20:13 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-11-10 20:13 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-11-10 20:13 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-11-10 20:13 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-11-10 20:12 - 2014-11-10 21:29 - 00000000 ____D () C:\ComboFix
2014-11-10 20:10 - 2014-11-10 20:12 - 00000000 ____D () C:\Qoobox
2014-11-10 20:06 - 2014-11-10 21:18 - 00000000 ____D () C:\Windows\erdnt
2014-11-10 19:47 - 2014-11-10 19:47 - 00000000 ____D () C:\OETemp
2014-11-10 19:41 - 2014-11-10 19:41 - 05598341 _____ (Swearware) C:\Users\Hendrik\Downloads\ComboFix(1).exe
2014-11-10 19:40 - 2014-11-10 19:41 - 05598341 _____ (Swearware) C:\Users\Hendrik\Downloads\ComboFix.exe
2014-11-10 18:58 - 2014-11-10 19:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-08 11:21 - 2014-11-08 11:21 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (15)
2014-11-08 10:45 - 2014-11-08 10:50 - 710442486 _____ () C:\Users\Hendrik\Documents\clip0919.avi
2014-11-07 16:38 - 2014-11-10 19:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2014-11-06 21:29 - 2014-11-06 21:43 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (78)
2014-11-06 19:00 - 2014-11-10 19:51 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-11-06 18:59 - 2014-11-06 18:59 - 04583464 _____ (Avira Operations GmbH & Co. KG) C:\Users\Hendrik\Downloads\avira_de_av___ws.exe
2014-11-06 18:34 - 2014-11-06 18:36 - 00041719 _____ () C:\Users\Hendrik\Downloads\Addition.txt
2014-11-06 18:31 - 2014-11-10 21:47 - 00063412 _____ () C:\Users\Hendrik\Downloads\FRST.txt
2014-11-06 18:30 - 2014-11-11 19:41 - 00000000 ____D () C:\FRST
2014-11-06 18:30 - 2014-11-06 18:30 - 02114560 _____ (Farbar) C:\Users\Hendrik\Downloads\FRST64.exe
2014-11-06 18:28 - 2014-11-06 18:29 - 00000476 _____ () C:\Users\Hendrik\Downloads\defogger_disable.log
2014-11-06 18:28 - 2014-11-06 18:28 - 00000000 _____ () C:\Users\Hendrik\defogger_reenable
2014-11-06 18:27 - 2014-11-06 18:27 - 00050477 _____ () C:\Users\Hendrik\Downloads\Defogger.exe
2014-11-06 16:25 - 2014-11-06 18:20 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-06 16:19 - 2014-11-06 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-06 16:18 - 2014-11-06 16:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-06 16:18 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-06 16:18 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-06 16:18 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-06 16:16 - 2014-11-06 16:17 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025(2).exe
2014-11-06 16:00 - 2014-11-06 16:00 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025(1).exe
2014-11-06 15:43 - 2014-11-06 15:43 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Hendrik\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-06 12:02 - 2014-11-06 12:06 - 121435896 _____ (Microsoft Corporation) C:\Users\Hendrik\Downloads\msert(2).exe
2014-11-05 17:18 - 2014-11-05 17:18 - 01125200 _____ () C:\Users\Hendrik\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe
2014-11-05 16:42 - 2014-11-05 16:42 - 00896504 _____ (Microsoft Corporation) C:\Users\Hendrik\Downloads\mssstool64.exe
2014-11-04 17:44 - 2014-11-06 15:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2014-11-04 17:44 - 2014-11-06 15:30 - 00000000 ____D () C:\Program Files\Wondershare
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ___HD () C:\Program Files (x86)\Dr.Fone_Temp
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Wondershare
2014-11-04 17:44 - 2014-11-04 17:44 - 00000000 ____D () C:\ProgramData\Wondershare
2014-11-04 17:43 - 2014-11-04 17:43 - 00000000 ____D () C:\Users\Public\Documents\Wondershare
2014-11-04 17:16 - 2014-11-04 17:16 - 00000000 ____D () C:\Users\Hendrik\Desktop\Media
2014-11-04 17:07 - 2014-11-05 16:09 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Reincubate
2014-11-04 10:42 - 2014-11-04 10:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\WindSolutions
2014-11-04 10:42 - 2014-11-04 10:46 - 00000000 ____D () C:\ProgramData\WindSolutions
2014-11-04 00:08 - 2014-11-04 00:08 - 00000000 ____D () C:\Users\Hendrik\.android
2014-11-03 23:53 - 2014-11-04 00:05 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-11-03 19:47 - 2014-11-03 19:47 - 09035819 _____ () C:\Users\Hendrik\Downloads\Video de maestra -Lucita Sandoval- teniendo sexo con su alumno.FLV
2014-11-03 19:46 - 2014-11-03 19:46 - 20630713 _____ () C:\Users\Hendrik\Downloads\Video de maestra -Lucita Sandoval- teniendo sexo con su alumno_3.FLV
2014-11-03 19:46 - 2014-11-03 19:46 - 20373249 _____ () C:\Users\Hendrik\Downloads\Video de maestra -Lucita Sandoval- teniendo sexo con su alumno_2.FLV
2014-11-02 00:42 - 2014-11-02 00:43 - 107254738 _____ () C:\Users\Hendrik\Documents\clip0918.avi
2014-11-01 12:32 - 2014-11-01 12:32 - 04078544 _____ (iMobie Inc. ) C:\Users\Hendrik\Downloads\phonerescue-setup.exe
2014-10-30 22:34 - 2014-10-30 22:36 - 00000000 ____D () C:\Users\Hendrik\Downloads\pictures (21)
2014-10-29 15:01 - 2014-10-29 15:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-10-29 14:06 - 2014-10-29 14:06 - 00002192 _____ () C:\Users\Hendrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2014-10-29 14:05 - 2014-10-29 14:05 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2014-10-27 17:43 - 2014-10-27 17:43 - 00002170 _____ () C:\Users\Hendrik\.recently-used.xbel
2014-10-27 00:15 - 2014-10-27 00:16 - 118253116 _____ () C:\Users\Hendrik\Documents\clip0917.avi
2014-10-26 23:50 - 2014-10-26 23:52 - 195895978 _____ () C:\Users\Hendrik\Documents\clip0916.avi
2014-10-25 23:09 - 2014-10-25 23:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2014-10-24 23:21 - 2014-10-24 23:21 - 25336014 _____ () C:\Users\Hendrik\Documents\clip0915.avi
2014-10-24 23:13 - 2014-10-24 23:13 - 06658282 _____ () C:\Users\Hendrik\Documents\clip0914.avi
2014-10-21 15:36 - 2014-10-21 15:36 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-21 15:36 - 2014-10-21 15:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\Program Files\iTunes
2014-10-21 15:35 - 2014-10-21 15:36 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-21 15:35 - 2014-10-21 15:35 - 00000000 ____D () C:\Program Files\iPod
2014-10-21 13:47 - 2014-10-21 13:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\pdfforge
2014-10-20 11:42 - 2014-10-20 11:42 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Oracle
2014-10-20 11:24 - 2014-10-20 11:23 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-10-20 11:23 - 2014-10-20 11:23 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-10-20 11:23 - 2014-10-20 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-20 00:40 - 2014-10-20 01:10 - 2638644386 _____ () C:\Users\Hendrik\Documents\clip0913.avi
2014-10-19 18:19 - 2014-10-19 18:19 - 00613203 _____ () C:\Users\Hendrik\Downloads\Plain Cloud_1.0(1).zip
2014-10-19 17:50 - 2014-10-19 17:50 - 00613203 _____ () C:\Users\Hendrik\Downloads\Plain Cloud_1.0.zip
2014-10-19 17:18 - 2014-10-19 17:18 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Python
2014-10-19 17:18 - 2014-10-19 17:18 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\ActiveState
2014-10-19 17:10 - 2014-10-19 18:05 - 00000000 ____D () C:\Users\Hendrik\Downloads\Whatsapp_Xtract_V2.2_2012-11-17
2014-10-19 15:38 - 2014-11-11 12:00 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Apple Inc
2014-10-15 21:36 - 2014-10-15 21:36 - 00144627 _____ () C:\Users\Hendrik\Downloads\NB SB.aac
2014-10-15 10:55 - 2014-10-15 10:55 - 00000000 ____H () C:\Users\Hendrik\Desktop\~WRL0254.tmp
2014-10-15 10:53 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 10:53 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-15 10:53 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-15 10:53 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2014-10-15 10:53 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2014-10-15 10:53 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-15 10:53 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 10:52 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-10-15 10:52 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-10-15 10:52 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-10-15 10:52 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-15 10:52 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-10-15 10:52 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-15 10:52 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-15 10:52 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-15 10:52 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2014-10-15 10:52 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-10-15 10:52 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-15 10:52 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-15 10:52 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-15 10:52 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-15 10:52 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-15 10:52 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-15 10:52 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-15 10:52 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-15 10:52 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-15 10:52 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2014-10-15 10:52 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2014-10-15 10:52 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2014-10-15 10:52 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-10-15 10:52 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-10-15 10:52 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-10-15 10:52 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-10-15 10:52 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-15 10:52 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-15 10:51 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-15 10:51 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-15 10:50 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-15 10:50 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 10:50 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-15 10:50 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-15 10:50 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-15 10:50 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-15 10:50 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-15 10:50 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 10:50 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 10:50 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 10:50 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 10:50 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-15 10:50 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 10:50 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 10:50 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 10:50 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 10:50 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 10:50 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 10:50 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 10:50 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 10:50 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 10:50 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 10:50 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-15 10:50 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 10:50 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 10:50 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 10:50 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-15 10:50 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 10:50 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 10:50 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-15 10:50 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-15 10:50 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 10:50 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-15 10:50 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 10:50 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-15 10:50 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-15 10:50 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-15 10:50 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-15 10:50 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-15 10:50 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-15 10:50 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 10:50 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 10:50 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 10:50 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 10:50 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 10:50 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-15 10:50 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-15 10:50 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-15 10:50 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 10:50 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-15 10:50 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 10:50 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-15 10:50 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-15 10:49 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-15 10:49 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-15 10:48 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 10:48 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-15 10:48 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 10:48 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 10:48 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 10:48 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-15 10:48 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-15 10:48 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-15 10:48 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 10:48 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-15 10:46 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 10:46 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-15 10:46 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 10:46 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-11 19:35 - 2009-07-14 05:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-11 19:35 - 2009-07-14 05:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-11 19:34 - 2013-12-08 21:30 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-11-11 19:34 - 2012-02-20 09:59 - 00000000 ___HD () C:\ASUS.DAT
2014-11-11 19:33 - 2012-04-12 17:11 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-11 19:32 - 2011-11-18 22:11 - 01147301 _____ () C:\Windows\WindowsUpdate.log
2014-11-11 19:32 - 2011-02-19 10:08 - 00745910 _____ () C:\Windows\system32\perfh007.dat
2014-11-11 19:32 - 2011-02-19 10:08 - 00162816 _____ () C:\Windows\system32\perfc007.dat
2014-11-11 19:32 - 2009-07-14 06:13 - 01732678 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-11 19:27 - 2014-02-15 20:18 - 00300926 _____ () C:\Windows\PFRO.log
2014-11-11 19:27 - 2014-01-03 20:01 - 00041051 _____ () C:\Windows\setupact.log
2014-11-11 19:27 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-11 18:09 - 2013-10-16 10:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-11 17:50 - 2012-04-12 17:11 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-11 14:21 - 2013-10-16 10:43 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-11-11 14:14 - 2011-11-18 22:28 - 00001899 _____ () C:\Windows\system32\ServiceFilter.ini
2014-11-11 12:00 - 2012-02-20 09:58 - 00000000 ____D () C:\Users\Hendrik
2014-11-11 11:55 - 2013-10-16 10:01 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-11 11:55 - 2013-10-16 10:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-11 11:55 - 2013-10-16 10:01 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-11 11:42 - 2012-02-20 10:27 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Apple Computer
2014-11-11 10:57 - 2014-04-26 17:15 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\.Torrent Stream
2014-11-11 10:57 - 2014-04-26 17:14 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\TorrentStream
2014-11-10 21:05 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-11-10 20:44 - 2011-11-18 22:28 - 00000000 ____D () C:\ProgramData\Temp
2014-11-10 19:51 - 2012-05-02 16:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 19:49 - 2013-01-12 14:29 - 00000000 ____D () C:\ProgramData\Package Cache
2014-11-10 19:21 - 2013-01-28 17:23 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{40B698CB-62BD-4EE1-A271-0656D24B8F85}
2014-11-06 21:56 - 2013-10-19 22:00 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\vlc
2014-11-06 15:38 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-06 15:31 - 2014-08-15 17:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iMobie
2014-11-06 15:31 - 2014-08-15 16:39 - 00000000 ____D () C:\Program Files (x86)\iMobie
2014-11-04 17:58 - 2014-01-28 14:11 - 00000000 ____D () C:\Users\Hendrik\Desktop\sortieren
2014-11-04 17:07 - 2012-02-20 10:15 - 00000000 ____D () C:\Users\Hendrik\Desktop\Programme
2014-11-04 10:10 - 2013-03-18 12:04 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\uTorrent
2014-11-03 14:08 - 2012-02-20 09:59 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-11-02 11:26 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-01 12:33 - 2014-08-15 16:39 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\iMobie
2014-11-01 12:33 - 2014-08-15 16:39 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\iMobie_Inc
2014-10-30 12:25 - 2012-04-27 08:56 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-29 18:46 - 2014-10-06 11:03 - 00000000 ____D () C:\Users\Hendrik\Desktop\Bewerbungen Verena
2014-10-29 15:13 - 2012-02-20 11:41 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\Skype
2014-10-29 15:02 - 2012-02-20 11:41 - 00000000 ____D () C:\ProgramData\Skype
2014-10-29 15:01 - 2014-08-11 20:27 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-10-29 13:48 - 2014-08-20 17:26 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Adobe
2014-10-27 17:46 - 2012-04-12 15:48 - 00000000 ____D () C:\Users\Hendrik\.gimp-2.6
2014-10-25 23:11 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-25 23:09 - 2012-03-14 13:46 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-10-24 11:45 - 2012-04-12 17:11 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-24 11:45 - 2012-04-12 17:11 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-22 11:07 - 2014-06-10 18:44 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\7-PDFSplitMerge
2014-10-22 08:02 - 2012-11-20 10:20 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-10-22 07:59 - 2013-11-20 16:47 - 00000000 ____D () C:\ProgramData\MAGIX
2014-10-21 19:03 - 2012-02-20 10:27 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Apple Computer
2014-10-21 15:35 - 2014-09-10 23:19 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-20 11:24 - 2013-10-19 11:48 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-20 11:23 - 2012-02-22 16:25 - 00000000 ____D () C:\Program Files (x86)\Java
2014-10-20 10:54 - 2009-07-14 05:45 - 00518968 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-19 17:25 - 2012-02-20 09:59 - 00160264 _____ () C:\Users\Hendrik\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-19 15:56 - 2013-12-17 15:19 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\C24C21DE-B653-4E21-81BE-22AF552FB2ED.aplzod
2014-10-19 15:53 - 2012-03-17 13:25 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Microsoft Help
2014-10-17 17:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-10-16 00:16 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-15 22:29 - 2013-01-09 22:52 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-10-15 22:29 - 2012-02-22 13:47 - 00000000 ____D () C:\Users\Hendrik\AppData\Roaming\DVDVideoSoft
2014-10-15 22:27 - 2012-02-22 13:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-10-15 17:33 - 2014-05-06 23:24 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-10-15 17:33 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-10-15 17:01 - 2012-03-17 13:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 16:47 - 2013-08-19 02:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 16:38 - 2012-10-20 09:57 - 00000000 ____D () C:\Users\Hendrik\AppData\Local\Windows Live
2014-10-15 16:19 - 2012-02-21 18:34 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-06 14:23

==================== End Of Log ============================

--- --- ---

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-11-2014 01
Ran by Hendrik at 2014-11-11 19:43:20
Running from C:\Users\Hendrik\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\uTorrent) (Version: 3.4.2.34309 - BitTorrent Inc.)
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-PDF Split & Merge Version 2.1.0 (Build 128) (HKLM-x32\...\7-PDF Split & Merge_is1) (Version: 7-PDF Split & Merge - Version 2.1.0 (Build 128) - 7-PDF, Germany - Thorsten Hodes)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\{BC8AC77D-6A6F-491F-BEED-2958F09C6CAE}) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
ANNO 1503 GOLD (HKLM-x32\...\{DB833EF9-A198-49BE-970A-BD46F30BFBB4}) (Version: 1.05.00 - )
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo StartUp Tuner 2.00 (HKLM-x32\...\Ashampoo StartUp Tuner 2_is1) (Version: 2.0.0 - ashampoo GmbH & Co. KG)
ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.14 - ASUS)
ASUS FancyStart (HKLM-x32\...\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}) (Version: 1.1.1 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.22 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.0.6 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS)
ASUS Secure Delete (HKLM\...\{761C6783-D3BC-48AB-8E7C-61CE918A8436}) (Version: 1.00.0007 - ASUS)
ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0033 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.84.161 - eCareme Technologies, Inc.)
Asus_PSeries_Screensaver (HKLM-x32\...\Asus_PSeries_Screensaver) (Version: 1.0.0001 - ASUS)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.4.617 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS)
Audacity 2.0.4 (HKLM-x32\...\Audacity_is1) (Version: 2.0.4 - Audacity Team)
Audiodope 0.24 (HKLM-x32\...\Audiodope_is1) (Version:  - Audiodope Team)
AVI Splitter (HKLM-x32\...\AVI Splitter_is1) (Version:  - )
Benutzerhandbuch - Grundlagen EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Bog) (Version:  - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (x32 Version: 13.50.854.0 - Logitech) Hidden
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5067 - CDBurnerXP)
Cinergy T USB XE V6.11.23.01 (HKLM-x32\...\Cinergy T USB XE) (Version: 6.11.23.01 - )
Cinergy T-Stick V8.08.18.01 (HKLM-x32\...\Cinergy T-Stick) (Version: 8.08.18.01 - )
ClipGrab 3.4.7 (HKLM-x32\...\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version:  - Philipp Schmieder Medien)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.)
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.6.1622 - CyberLink Corp.)
CyberLink PowerRecover (Version: 5.6.1622 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Debut Video Capture Software (HKLM-x32\...\Debut) (Version:  - NCH Software)
Diercke Globus Online (HKLM-x32\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH)
Dropbox (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Dropbox) (Version: 2.10.29 - Dropbox, Inc.)
Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.1.1 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print 2 (HKLM-x32\...\{30E01116-5666-4807-8EF1-D80E9FF16717}) (Version: 2.3.2.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM-x32\...\{BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}) (Version: 3.01.0000 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON XP-302 303 305 306 Series Printer Uninstall (HKLM\...\EPSON XP-302 303 305 306 Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
ETDWare PS/2-X64 8.0.5.3_WHQL (HKLM\...\Elantech) (Version: 8.0.5.3 - ELAN Microelectronic Corp.)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.9 - ASUS)
Filedrop version 1.1.4 (HKLM-x32\...\{3A309583-1B4A-4C90-85EA-124EB8DB331A}_is1) (Version: 1.1.4 - Filedrop)
Folienviewer2 (HKLM-x32\...\Folienviewer2) (Version: 1.01 - Imagon GmbH)
FormatFactory 3.2.1.0 (HKLM-x32\...\FormatFactory) (Version: 3.2.1.0 - Free Time)
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
Free YouTube to iPod Converter version 3.10.37.1212 (HKLM-x32\...\Free YouTube to iPod Converter_is1) (Version: 3.10.37.1212 - DVDVideoSoft Ltd.)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
HyperCam 2 (HKLM\...\HyperCam 2) (Version: 2.25.01 - Hyperionics Technology LLC)
iCloud (HKLM\...\{6096C0CC-7E19-4355-87F0-627EC5AA146D}) (Version: 4.0.3.56 - Apple Inc.)
iExplorer 2.2.1.3 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant, LLC)
iFunbox (v2.7.2386.747), iFunbox DevTeam (HKLM-x32\...\iFunbox_is1) (Version: v2.7.2386.747 - )
Image Resizer for Windows (64 bit) (Version: 3.0.4442.6002 - Brice Lambson) Hidden
Image Resizer for Windows (HKLM-x32\...\{9dfff2f7-5cd7-4fd4-9b75-7d53b042d94b}) (Version: 3.0.4442.6002 - Brice Lambson)
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{A0E106D2-4815-4B7A-BAA7-7E21B530CFB4}) (Version: 1.1.0.0157 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{006B5C65-3938-4246-B182-994A7E415EDE}) (Version: 1.1.0.0537 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH)
Join Air (HKLM-x32\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.1 - ZTE Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.31 - Logitech Inc.)
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
ManyCam 3.0.80 (remove only) (HKLM-x32\...\ManyCam) (Version: 3.0.80 - ManyCam LLC)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 33.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.1 (x86 de)) (Version: 33.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Netzwerkhandbuch EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Netg) (Version:  - )
Notebook Interactive Viewer (HKLM-x32\...\{24BA79B5-53F9-475C-9D49-EC4BDE8B09CF}) (Version: 9.5.126.5 - SMART Technologies Inc.)
Nuance PDF Reader (HKLM-x32\...\{B480904D-F73F-4673-B034-8A5F492C9184}) (Version: 6.00.0041 - Nuance Communications, Inc.)
Opera Stable 25.0.1614.68 (HKLM-x32\...\Opera 25.0.1614.68) (Version: 25.0.1614.68 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.0.11.77 - Electronic Arts, Inc.)
PC-WELT-TuneUpSuite 1.0 (HKLM-x32\...\{36B01464-5050-4492-BAA3-46E62551EEAB}_is1) (Version:  - IDG Magazine Media GmbH)
PDF Split And Merge Basic (HKLM\...\{C91B24F6-1629-11E2-B696-21676188709B}) (Version: 2.2.2 - Andrea Vacondio)
Politik transparent (HKLM-x32\...\{B8591E60-8A0E-43F9-A82D-7EAE368A8BBC}) (Version: 1.00.0000 - Bildungshaus Schulbuchverlage Westermann Schroedel Diesterweg Schöningh Winklers GmbH)
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.8 - ASUS)
Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
Software Updater (HKLM-x32\...\{A3B308B9-BE96-4334-816F-3D82B19A7DE2}) (Version: 4.1.7 - SEIKO EPSON CORPORATION)
Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
SopCast 3.8.3 (HKLM-x32\...\SopCast) (Version: 3.8.3 - www.sopcast.com)
Splashtop Software Updater (HKLM-x32\...\Splashtop Software Updater) (Version: 1.5.6.14 - Splashtop Inc.)
Splashtop Streamer (HKLM-x32\...\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.4.0.1 - Splashtop Inc.)
Spotify (HKU\S-1-5-21-1724138799-3868663929-1243099489-1000\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com)
StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version:  - )
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
syncables desktop SE (HKLM-x32\...\{341697D8-9923-445E-B42A-529E5A99CB7A}) (Version: 5.5.746.11492 - syncables)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.24482 - TeamViewer)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.1 - ASUS)
Wireless Console 3 (HKLM-x32\...\{8150221C-8F7E-4997-AD4E-AFDEE7F4B410}) (Version: 3.0.21 - ASUS)
Yahoo! Detect (HKLM-x32\...\YTdetect) (Version:  - )
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Hendrik\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1724138799-3868663929-1243099489-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Hendrik\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2014-11-10 21:05 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0DCC669E-305D-4490-A22A-DACF8ACDA332} - System32\Tasks\{2538AA23-41A8-46F9-A9B8-1600A487A194} => E:\Launch.exe
Task: {43C8FC67-FE7A-400D-B176-A7BA5670AAC8} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduamon.exe
Task: {4B1D4A33-E673-4903-9028-073F28635356} - System32\Tasks\Opera scheduled Autoupdate 1381916617 => C:\Program Files (x86)\Opera\launcher.exe [2014-10-29] (Opera Software)
Task: {4BD9B6A0-BF11-446B-8759-2ED56E4BF34D} - System32\Tasks\{86C211C5-1FA9-4FB3-AC24-7E9E7FB67409} => E:\Install.exe
Task: {4FEAFF65-7EAC-4AB6-B595-81CE32212A34} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-12] (Google Inc.)
Task: {5BCFBD93-1AF7-436D-A7B4-93DA8DB9ACE8} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS)
Task: {74A6AE27-5B37-403C-90E2-F82BD52EFD7C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {823355DA-B080-4C2E-8E9F-D7DF9F5AE4EF} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {845121B3-024E-43FD-9DDA-813E16664F90} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: {88A197AC-BAAA-491A-BB7B-74B5901A114B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-11] (Adobe Systems Incorporated)
Task: {A117D9B8-4DD6-41F5-8DF6-9B965A73444A} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-08-31] (ASUSTeK Computer Inc.)
Task: {B55C227F-8780-44C4-A6F6-D10F1B3D2A77} - System32\Tasks\ASUS Secure Delete => C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe [2011-01-24] ()
Task: {C1376A8C-6329-4AB1-A91F-09D10534B1E5} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS)
Task: {C5263A43-5637-4F45-A703-1D997E5E657A} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-05-30] (ASUS)
Task: {C86F9397-3A3B-42CA-8E8D-09C4EC4F269B} - System32\Tasks\{5E595A7B-3F2A-4C14-AE3D-C733F9915D0E} => E:\Launch.exe
Task: {DDEE7187-E174-496B-9B6A-6A10147BE6C6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-12] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2014-03-11 15:29 - 2009-08-31 10:43 - 00241664 _____ () C:\Program Files (x86)\Join Air\AssistantServices.exe
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2011-01-24 19:55 - 2011-01-24 19:55 - 00541696 _____ () C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-09-06 04:29 - 2011-05-24 01:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-03-11 15:29 - 2009-08-31 10:43 - 00132608 _____ () C:\PROGRAM FILES (X86)\JOIN AIR\UIEXEC.EXE
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-08-31 15:33 - 2011-08-31 15:33 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
2011-05-30 22:48 - 2011-05-30 22:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2011-06-10 19:49 - 2011-06-10 19:49 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2014-03-11 15:29 - 2009-08-31 10:43 - 00132608 _____ () C:\Program Files (x86)\Join Air\UIExec.exe
2014-11-10 18:59 - 2014-11-10 19:00 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: EEventManager => "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Hendrik\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: UIExec => "C:\Program Files (x86)\Join Air\UIExec.exe"
MSCONFIG\startupreg: Wisdom-soft AutoScreenRecorder 3.1 Free => 0

========================= Accounts: ==========================

Administrator (S-1-5-21-1724138799-3868663929-1243099489-500 - Administrator - Disabled)
Gast (S-1-5-21-1724138799-3868663929-1243099489-501 - Limited - Disabled)
Hendrik (S-1-5-21-1724138799-3868663929-1243099489-1000 - Administrator - Enabled) => C:\Users\Hendrik
HomeGroupUser$ (S-1-5-21-1724138799-3868663929-1243099489-1002 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/11/2014 03:53:40 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (11/11/2014 02:46:50 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (11/11/2014 02:46:48 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (11/11/2014 02:46:09 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (11/11/2014 00:04:47 PM) (Source: MsiInstaller) (EventID: 1002) (User: Hendrik-PC)
Description: Nicht erwarteter oder fehlender Wert (Name: "PackageName", Wert: "") für Schlüssel "HKLM\Software\Classes\Installer\Products\D139E7FE48CDB174D86B8A3385904547\SourceList".

Error: (11/11/2014 00:04:15 PM) (Source: MsiInstaller) (EventID: 1002) (User: Hendrik-PC)
Description: Nicht erwarteter oder fehlender Wert (Name: "PackageName", Wert: "") für Schlüssel "HKLM\Software\Classes\Installer\Products\D139E7FE48CDB174D86B8A3385904547\SourceList".

Error: (11/11/2014 00:03:34 PM) (Source: MsiInstaller) (EventID: 1002) (User: Hendrik-PC)
Description: Nicht erwarteter oder fehlender Wert (Name: "PackageName", Wert: "") für Schlüssel "HKLM\Software\Classes\Installer\Products\D139E7FE48CDB174D86B8A3385904547\SourceList".

Error: (11/11/2014 11:44:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ApplePhotoStreams.exe, Version: 7.15.7.3, Zeitstempel: 0x53d97094
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7
Ausnahmecode: 0xc0000374
Fehleroffset: 0x000ce753
ID des fehlerhaften Prozesses: 0x910
Startzeit der fehlerhaften Anwendung: 0xApplePhotoStreams.exe0
Pfad der fehlerhaften Anwendung: ApplePhotoStreams.exe1
Pfad des fehlerhaften Moduls: ApplePhotoStreams.exe2
Berichtskennung: ApplePhotoStreams.exe3

Error: (11/11/2014 10:34:34 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: PSIA.exe, Version: 3.0.0.9016, Zeitstempel: 0x52a1d50f
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000332b0
ID des fehlerhaften Prozesses: 0x15a8
Startzeit der fehlerhaften Anwendung: 0xPSIA.exe0
Pfad der fehlerhaften Anwendung: PSIA.exe1
Pfad des fehlerhaften Moduls: PSIA.exe2
Berichtskennung: PSIA.exe3

Error: (11/10/2014 09:49:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000000000
ID des fehlerhaften Prozesses: 0x1dd8
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3


System errors:
=============
Error: (11/11/2014 07:28:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WebcamMax, WDM Video Capture" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1058

Error: (11/11/2014 07:28:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "lxdu_device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (11/11/2014 04:06:29 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (11/11/2014 02:23:27 PM) (Source: iaStor) (EventID: 9) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (11/11/2014 02:19:32 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (11/11/2014 02:14:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WebcamMax, WDM Video Capture" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1058

Error: (11/11/2014 02:13:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "lxdu_device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (11/11/2014 02:11:37 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll

Error: (11/11/2014 02:11:37 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll

Error: (11/11/2014 02:11:37 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Windows\System32\IWMSSvc.dll


Microsoft Office Sessions:
=========================
Error: (08/26/2014 04:52:59 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6700.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1784 seconds with 960 seconds of active time.  This session ended with a crash.

Error: (04/06/2014 05:25:31 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 45 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (02/18/2014 07:27:55 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6690.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 64 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (05/16/2013 04:00:44 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1650 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (09/25/2012 03:45:57 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 904 seconds with 0 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2014-11-10 20:52:24.253
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-11-10 20:52:24.211
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-26 10:55:36.047
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-02-26 10:55:35.965
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz
Percentage of memory in use: 45%
Total physical RAM: 4008.17 MB
Available physical RAM: 2197.08 MB
Total Pagefile: 8014.52 MB
Available Pagefile: 6156.19 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:14.8 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:153.85 GB) (Free:22.95 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=119.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=153.9 GB) - (Type=07 NTFS)

==================== End Of Log ============================


deeprybka 11.11.2014 19:59

Kannst Du bitte noch die eine Datei checken lassen?

Anchovi 11.11.2014 20:38

Gesagt, getan, hier der link:

https://www.virustotal.com/de/file/f3e0c002cdfbfe519b7519225ce7b059e8f17ea09525c818c47ca17dcafd83ed/analysis/1415734595/

deeprybka 11.11.2014 21:02

Prima Mitarbeit von Dir! :daumenhoc

Schritt 1

http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...st/frstfix.png

Drücke bitte die http://deeprybka.trojaner-board.de/b...ne/revo/w7.png + R Taste und schreibe notepad in das Ausführen Fenster.
Klicke auf OK und kopiere nun den Text aus der Codebox in das leere Textdokument:
Code:

Folder: C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D}
C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D}

Speichere dieses bitte als Fixlist.txt in das Verzeichnis ab, in dem sich auch die FRST-Anwendung befindet.
  • Starte FRST und drücke auf den Fix-Button.
  • Das Tool erstellt eine "Fixlog.txt" -Datei.
  • Poste mir bitte deren Inhalt.

http://www.trojaner-board.de/extra/lesestoff.pngGibt es jetzt noch Probleme mit dem PC? Wenn ja, welche?

Anchovi 11.11.2014 21:07

Ich muss mich für deine Mitarbeit bzw. deine tolle Hilfe bedanken!:daumenhoc

Hier der Inhalt:

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-11-2014 01
Ran by Hendrik at 2014-11-11 21:06:33 Run:2
Running from C:\Users\Hendrik\Desktop
Loaded Profile: Hendrik (Available profiles: Hendrik & DefaultAppPool)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Folder: C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D}
C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D}
*****************


========================= Folder: C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D} ========================

2014-11-08 11:43 - 2014-11-08 11:43 - 0479232 ___SH () C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D}\api-ms-win-system-wmdrmnet-l1-1-0.dll

====== End of Folder: ======

C:\Windows\Installer\{64C21AC0-8CE4-49AF-8376-1A7A72D1819D} => Moved successfully.

==== End of Fixlog ====


deeprybka 11.11.2014 21:20

OK, malware-technisch sind wir durch. Seltsam, dass Emsisoft und Hitman die Datei beim Scan nicht gefunden haben. In den Signaturen ist sie enthalten.

Ganz wichtig: Wenn alles durch hast beim cleanup, Onlinepasswörter ändern falls noch nicht geschehen.

Jetzt spendierst Deinem PC erstmal noch ein schönes Java-Update und schmeißt die alte Version runter.
Code:

Java 7 Update 71
Das neueste Java von hier installieren:
Java installieren.

http://deeprybka.trojaner-board.de/b...cleanupneu.png
Cleanup:
(Die Reihenfolge ist hier entscheidend)

Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken.

http://deeprybka.trojaner-board.de/b...n/defogger.png


Falls Combofix verwendet wurde:
http://deeprybka.trojaner-board.de/b...s/combofix.png Combofix-Deinstallation.
  • Wichtig: Bitte Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke bitte die http://deeprybka.trojaner-board.de/b...ne/revo/w7.png + R Taste und schreibe Combofix /Uninstall in das Ausführen-Fenster.
  • Klicke auf OK.
    Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert.
  • Nun die eben deaktivierten Programme wieder aktivieren.






Alle Logs gepostet? Ja! Dann lade Dir bitte http://filepony.de/icon/delfix.pngDelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.

Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.




>>clean<<
Wir haben es geschafft! :abklatsch:
Die Logs sehen für mich im Moment sauber aus.

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...:dankeschoen:und/oder das Forum mit einer kleinen Spende http://www.trojaner-board.de/extra/spende.png unterstützen. :applaus:
Es bleibt mir nur noch, Dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen. ;)

http://www.trojaner-board.de/extra/lesestoff.pngWie kann ich mich in Zukunft besser schützen?

Tipps, Dos & Don'ts

http://deeprybka.trojaner-board.de/b...ast/schild.pngUpdates & Software
Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.

Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.



http://deeprybka.trojaner-board.de/b...ast/schild.pngFirewall, Antivirus & Co.
http://s1.directupload.net/images/140701/eivrliwa.pngCracks, Downloads & Co.


Neben unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert.
Der Besuch dubioser Websites kann bereits Risiken bergen. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
Illegale Cracks, Keygens und Serials sind ein ausgesprochen einfacher und beliebter Weg um Malware zu verbreiten.
Bei Dateien aus Peer-to-Peer- und Filesharingprogrammen oder von Filehostern kann man nie sicher sein, ob auch wirklich drin ist, was drauf steht. (Trojanisches Pferd^^)
Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden zu verleiten, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
  • Surfe daher mit Vorsicht und klicke mit Verstand.
  • Sei skeptisch bei unerwarteten E-Mails, insbesondere wenn sie Anhänge enthalten. Auch wenn sie auf den ersten Blick authentisch wirken, persönliche Daten von Dir enthalten oder vermeintlich von einem bekannten Absender stammen: Lieber nochmals in Ruhe überdenken oder nachfragen, anstatt einfach mal Links oder ausführbare Anhänge öffnen oder irgendwo Deine Daten eingeben.
  • Auch in sozialen Netzwerken oder über Instant Messaging Systeme können schädliche Links oder Dateien die Runde machen. Erhältst Du von einem Deiner Freunde eine Nachricht, die merkwürdig ist oder so sensationell interessant, dass man einfach draufklicken muss, dann hat bei ihm/ihr wahrscheinlich Neugier über Verstand gesiegt und Du solltest nicht denselben Fehler machen.

Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
  • Lade Software in erster Priorität immer direkt vom Hersteller herunter. Viele Softwareportale (z.B. Softonic) packen noch unnützes Zeug mit in die Installation. Alternativ dazu wähle ein sauberes Portal wie Filepony oder heise.
  • Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
  • Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwarecleaner .


Abschließend noch ein paar grundsätzliche Bemerkungen:
  • Erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
  • Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:55 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20