Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert (https://www.trojaner-board.de/173013-win-7-rechner-trojaner-tr-ad-gamarue-y-1144-infiziert.html)

nora.s 12.11.2015 12:50

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hallo!
Mein Win 7 Rechner ist mit dem Trojaner TR/AD.Gamarue.Y.1144 infiziert. Ich habe von der Universität Avira PC Cleaner erhalten, den ich jedes Mal für einen Durchlauf neu installieren muss. Dieser hat den Trojaner gefunden, kann ihn aber nicht löschen.
Meine Antivirensoftware Microsoft Security Essentials hat den Trojaner nicht gefunden.

Leider kenne ich mich nicht sehr gut mit Computern aus.. Ich hoffe, dass ich die richtigen Logfile Dateien kopiert habe. Die Ergebnisse von Gmer konnte ich nicht in einer Textdatei speichern (wenn ich diese aufrufen wollte kam: Fehlerhafte Verknüpfung). Ich habe jetzt den Text direkt aus Gmer kopiert und hier eingefügt.

Danke schon mal im Voraus für die Hilfe!

Hier die gewünschten Logfile Dateien:

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 11:17 on 12/11/2015 (Notebook)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-FRST Additions Logfile:
Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:07-11-2015
durchgeführt von Nora (2015-11-12 11:20:46)
Gestartet von C:\Users\Nora\Desktop\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2012-08-30 13:16:26)
Start-Modus: Normal
==========================================================
 
 
==================== Konten: =============================
 
Administrator (S-1-5-21-1146881843-1855949487-4122649668-500 - Administrator - Disabled)
Gast (S-1-5-21-1146881843-1855949487-4122649668-501 - Limited - Disabled)
Nora (S-1-5-21-1146881843-1855949487-4122649668-1001 - Limited - Enabled) => C:\Users\Nora
Notebook (S-1-5-21-1146881843-1855949487-4122649668-1000 - Administrator - Enabled) => C:\Users\Notebook
Uwelchen (S-1-5-21-1146881843-1855949487-4122649668-1003 - Limited - Enabled) => C:\Users\Uwelchen
 
==================== Sicherheits-Center ========================
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installierte Programme ======================
 
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.7.637 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
Benutzerhandbuch (x32 Version: 1.0.0.6 - Lenovo) Hidden
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CBR (HKLM\...\{A8305DB2-3F6A-43CF-8CE3-EFD3D0F1C352}) (Version: 0.7 - G.Waser)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.2.3442 - CDBurnerXP)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.4.51 - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DMUninstaller (HKLM-x32\...\DMUninstaller) (Version: - ) <==== ACHTUNG
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.0 - Lenovo)
Energy Management (x32 Version: 6.0.2.0 - Lenovo) Hidden
Free DWG Viewer 7.3 (HKLM-x32\...\{16CF668C-104D-479F-88A9-739137AEF3AD}) (Version: 7.3.0.176 - IGC)
GeoGebra 4.4 (HKLM-x32\...\GeoGebra 4.4) (Version: 4.4.6.0 - International GeoGebra Institute)
Google Chrome (HKLM-x32\...\{73187774-F274-39D6-80A4-33778B3CBBD4}) (Version: 65.51.16478 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
HP Deskjet 1000 J110 series - Grundlegende Software für das Gerät (HKLM\...\{CED47C99-8892-4956-BCA7-CC3123531371}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1000 J110 series Hilfe (HKLM-x32\...\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3341 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 9 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.10.1209.1 - Lenovo EasyCamera)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo Games Console (HKLM-x32\...\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3728 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden
Lexmark S410 Series Deinstallationsprogamm (HKLM\...\Lexmark S410 Series) (Version: - Lexmark International, Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
Mozilla Thunderbird 31.7.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 de)) (Version: 31.7.0 - Mozilla)
Mozilla Thunderbird 38.2.0 (x86 de) (HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\Mozilla Thunderbird 38.2.0 (x86 de)) (Version: 38.2.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.0 - Frank Heindörfer, Philip Chinery)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10003 - Realtek Semiconductor Corp.)
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Studie zur Verbesserung von HP Deskjet 1000 J110 series Produkten (HKLM\...\{28F4BC72-75AE-47DD-B5B3-2A027BCA48A7}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.0.0 - Synaptics Incorporated)
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.14563 - TeamViewer)
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo)
Verbindungsassistent (HKLM-x32\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent)
VeriFace (HKLM-x32\...\VeriFace) (Version: 4.0.0.1224 - Lenovo)
Video Downloader version 1.5 (HKLM-x32\...\Video Downloader_is1) (Version: 1.5 - )
VLC media player 2.0.4 (HKLM-x32\...\VLC media player) (Version: 2.0.4 - VideoLAN)
VO Package (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - ) <==== ACHTUNG
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)
 
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
 
 
==================== Wiederherstellungspunkte =========================
 
ACHTUNG: Systemwiederherstellung ist deaktiviert
Überprüfen Sie den "winmgmt" Dienst oder reparieren Sie den WMI.
 
 
==================== Hosts Inhalt: ===============================
 
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
 
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
 
 
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
 
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
 
Task: C:\windows\Tasks\Adobe Flash Player Updater.job =>
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job =>
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job =>
 
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
 
2012-05-23 12:03 - 2012-05-23 12:03 - 01508192 _____ () C:\windows\system32\IcnOvrly.dll
2008-12-20 04:20 - 2012-05-23 12:15 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2008-12-20 04:20 - 2012-05-23 12:15 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2012-05-23 11:36 - 2011-03-25 10:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
 
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
 
AlternateDataStreams: C:\ProgramData\Temp:373E1720
 
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
 
 
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
 
 
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
 
 
==================== Andere Bereiche ============================
 
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
 
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
 
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
 
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
 
 
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
 
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
 
FirewallRules: [{C06D5DF8-3461-4042-8F52-7EBCDE9FE5EB}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{A01CE26B-13D2-49C9-A92D-9B7D46120EAD}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{23CFB686-0B7E-4480-A9A3-CB0C2F765BAA}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{85C74DA7-449E-44C7-8E4E-1F4912152D42}] => (Allow) LPort=2869
FirewallRules: [{877B58CB-8D65-442A-8AF5-5FA372C19F10}] => (Allow) LPort=1900
FirewallRules: [{8D40A53C-4335-417B-9C4A-CB4692B6701D}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{17F942C8-12AD-4AA5-9463-4D84ED86C64F}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{494CA055-1977-42EC-B8BF-AE2174875BDB}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{7FB6858F-ED36-454A-8F9F-DF9A80AA76BF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{58AE4ECC-80E0-4F0D-BDC7-2CC30B8636BE}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{5C3FAB83-0355-4B03-8DC1-B8E0A07D7802}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{0C353832-0069-4E0E-9DC5-C406A89ED5BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C3FD3DA4-E429-4DDB-8AF6-37BB69E5EC76}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{DB0BA175-6DF7-49FB-BC0E-EB66246A1ACB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CD7CBA5A-1320-4B8A-86ED-D18730A7E38D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6DCD0473-2BF8-47E3-9577-F22D90E33E6C}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{1848B09C-A7F2-4E06-84AF-903D2D0CFCF1}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{600BE599-5822-48F3-B869-82DC5C62233C}] => (Allow) C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\USBSetup.exe
FirewallRules: [{795730CF-A64E-4915-8384-9C4A4D8606B1}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS0049\HPDiagnosticCoreUI.exe
FirewallRules: [{96963478-4C91-4FAA-A42F-C0519527DA88}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS0049\HPDiagnosticCoreUI.exe
FirewallRules: [{66F54DF8-0774-4E55-800F-073B4E8BB050}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS5C88\HPDiagnosticCoreUI.exe
FirewallRules: [{58ED8715-7D7E-4764-A2F4-1DC940D46FB9}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS5C88\HPDiagnosticCoreUI.exe
FirewallRules: [{2CF02080-21D3-4222-81D1-30FAE88FA2F6}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{E2CA7EE2-6A42-4951-B9E5-9C5E1FF1376A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A7998D86-49F1-4F44-886A-7F2D4CAE5C0A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{5488F4E7-619C-40F9-867A-5BE99F507EB9}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{4429A93B-8E63-407C-9B8A-3187FFC606B1}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{0F6DDD45-F3D6-43D5-B986-E7E4425ED8D6}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{6A2A115F-CFA8-4679-9084-9FDE758DE08E}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [{19F50F7A-F599-4734-A2C8-77C8CEEE3A54}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{364D57E1-9EF3-4CC4-AA8F-B0113BACBDBD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DCD7E537-A65D-45B1-A414-9576213BC1E8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
 
==================== Fehlerhafte Geräte im Gerätemanager =============
 
 
==================== Fehlereinträge in der Ereignisanzeige: =========================
 
Applikationsfehler:
==================
Error: (11/12/2015 10:48:02 AM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (11/12/2015 10:36:13 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/11/2015 08:12:19 PM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (11/11/2015 07:59:35 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/11/2015 05:55:49 PM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (11/11/2015 05:42:54 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/11/2015 05:16:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/11/2015 12:22:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/11/2015 09:15:21 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/10/2015 09:57:54 PM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
 
 
Systemfehler:
=============
Error: (11/12/2015 10:35:26 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Update Fortunitas" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
 
Error: (11/11/2015 08:09:54 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureCommand" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
 
Error: (11/11/2015 08:09:05 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
 
Error: (11/11/2015 07:59:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Update Fortunitas" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
 
Error: (11/11/2015 06:40:43 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
 
Error: (11/11/2015 05:55:08 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "FailureCommand" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
 
Error: (11/11/2015 05:51:28 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
 
Error: (11/11/2015 05:41:38 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
 
Error: (11/11/2015 05:41:38 PM) (Source: Microsoft Antimalware) (EventID: 3002) (User: )
Description: Vom Echtzeitschutz-Feature von %%860 wurde ein Fehler festgestellt
 
    Feature: %%886
 
    Fehlercode: 0x80070005
 
    Fehlerbeschreibung: Zugriff verweigert
 
    Grund: %%892
 
Error: (11/11/2015 05:41:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Update Fortunitas" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
 
 
==================== Speicherinformationen ===========================
 
Prozessor: Intel(R) Pentium(R) CPU B960 @ 2.20GHz
Prozentuale Nutzung des RAM: 31%
Installierter physikalischer RAM: 8135.86 MB
Verfügbarer physikalischer RAM: 5560.24 MB
Summe virtueller Speicher: 16269.93 MB
Verfügbarer virtueller Speicher: 13791.23 MB
 
==================== Laufwerke ================================
 
Drive c: () (Fixed) (Total:254.14 GB) (Free:171.33 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:26.82 GB) NTFS
 
==================== MBR & Partitionstabelle ==================
 
==================== Ende von Addition.txt ============================

--- --- ---
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
durchgeführt von Nora (ACHTUNG: der Benutzer ist kein Administrator) auf NOTEBOOK-PC (12-11-2015 11:19:33)
Gestartet von C:\Users\Nora\Desktop\Downloads
Geladene Profile: Notebook & Nora (Verfügbare Profile: Notebook & Nora & Uwelchen)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

konnte nicht auf den Prozess zugreifen -> smss.exe
konnte nicht auf den Prozess zugreifen -> csrss.exe
konnte nicht auf den Prozess zugreifen -> wininit.exe
konnte nicht auf den Prozess zugreifen -> csrss.exe
konnte nicht auf den Prozess zugreifen -> services.exe
konnte nicht auf den Prozess zugreifen -> winlogon.exe
konnte nicht auf den Prozess zugreifen -> lsass.exe
konnte nicht auf den Prozess zugreifen -> lsm.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> MsMpEng.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> spoolsv.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> armsvc.exe
konnte nicht auf den Prozess zugreifen -> AppleMobileDeviceService.exe
konnte nicht auf den Prozess zugreifen -> mDNSResponder.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> TeamViewer_Service.exe
konnte nicht auf den Prozess zugreifen -> WTGService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
konnte nicht auf den Prozess zugreifen -> NisSrv.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
konnte nicht auf den Prozess zugreifen -> SearchIndexer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
konnte nicht auf den Prozess zugreifen -> iPodService.exe
konnte nicht auf den Prozess zugreifen -> wmpnetwk.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
konnte nicht auf den Prozess zugreifen -> IAStorDataMgrSvc.exe
konnte nicht auf den Prozess zugreifen -> LMS.exe
konnte nicht auf den Prozess zugreifen -> WLIDSVC.EXE
konnte nicht auf den Prozess zugreifen -> WLIDSVCM.EXE
konnte nicht auf den Prozess zugreifen -> UNS.exe
konnte nicht auf den Prozess zugreifen -> TrustedInstaller.exe
konnte nicht auf den Prozess zugreifen -> svchost.exe
(Avira Operations GmbH & Co. KG) C:\Users\Nora\AppData\Local\Temp\cleaner\avwebloader.exe
(Avira Operations GmbH & Co. KG) C:\Users\Nora\AppData\Local\Temp\cleaner\pccleaner\setup\cleaner.exe
konnte nicht auf den Prozess zugreifen -> SeaPort.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Avira Operations GmbH & Co. KG) C:\Users\Nora\AppData\Local\Temp\cleaner\pccleaner\setup\avscan.exe
konnte nicht auf den Prozess zugreifen -> WmiPrvSE.exe
konnte nicht auf den Prozess zugreifen -> sppsvc.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2012-05-23] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2012-05-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2012-05-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-05-23] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM\...\RunOnce: [*WerKernelReporting] => C:\Windows\SYSTEM32\WerFault.exe [415232 2009-07-14] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\MountPoints2: {72c6dce6-520b-11e3-9d67-446d57e77fa7} - E:\LaunchU3.exe -a
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll [2012-05-23] ()
GroupPolicy: Beschränkung - Chrome <======= ACHTUNG

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0434AB00-3F7C-4291-91FB-BFB1A7FBC4E6}: [DhcpNameServer] 10.63.210.254
Tcpip\..\Interfaces\{0EA6BB07-2FF3-4059-B5F3-5A19971BFC92}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
URLSearchHook: [S-1-5-21-1146881843-1855949487-4122649668-1000] ACHTUNG => Standard URLSearchHook fehlt
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-10-21] (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-10-21] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)

FireFox:
========
FF ProfilePath: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\windows\system32\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-15] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\awesomehp.xml [2014-02-23]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\adblockpopups@jessehakanen.net.xpi [2015-05-29]
FF Extension: Ghostery - C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\firefox@ghostery.com.xpi [2015-11-05]
FF Extension: Google Analytics Opt-out Browser Add-on - C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\{6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}.xpi [2015-09-20]
FF Extension: NoScript - C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-10-26]
FF Extension: Adblock Plus - C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-25]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [296400 2009-03-03] ()
S2 Update Fortunitas; "C:\Program Files (x86)\Fortunitas\updateFortunitas.exe" [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
U3 BcmSqlStartupSvc; kein ImagePath
U2 CLKMSVC10_3A60B698; kein ImagePath
U2 CLKMSVC10_C3B3B687; kein ImagePath
U2 DriverService; kein ImagePath
U2 iATAgentService; kein ImagePath
U2 idealife Update Service; kein ImagePath
U3 IGRS; kein ImagePath
U2 IviRegMgr; kein ImagePath
U2 nvUpdatusService; kein ImagePath
U2 Oasis2Service; kein ImagePath
U2 PCCarerService; kein ImagePath
U2 ReadyComm.DirectRouter; kein ImagePath
U2 RichVideo; kein ImagePath
U2 RtLedService; kein ImagePath
U2 SoftwareService; kein ImagePath
U3 SQLWriter; kein ImagePath
U2 Stereo Service; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-12 11:18 - 2015-11-12 11:19 - 00000000 ____D C:\FRST
2015-11-12 11:17 - 2015-11-12 11:17 - 00000000 _____ C:\Users\Notebook\defogger_reenable
2015-11-11 17:49 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-11-11 17:49 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-11-11 17:49 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-11-11 17:49 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-11-11 17:49 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-11-11 17:49 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-11-11 17:49 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-11-11 17:49 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-11-11 17:49 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-11-11 17:49 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-11-11 17:49 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-11-11 17:49 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-11-11 17:49 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-11-11 17:49 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-11-11 17:49 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-11-11 17:49 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-11-11 17:49 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-11-11 17:49 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-11-11 17:49 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-11-11 17:49 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-11-11 17:49 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-11-11 17:49 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-11-11 17:49 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-11-11 17:49 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-11-11 17:49 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-11-11 17:49 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-11-11 17:49 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-11-11 17:48 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-11-11 17:48 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-11-11 17:48 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-11-11 17:48 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-11-11 17:48 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-11-11 17:48 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-11-11 17:48 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-11-11 17:48 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-11-11 17:48 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-11-11 17:48 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-11-11 17:48 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-11-11 17:48 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-11-11 17:48 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-11-11 17:48 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2015-11-11 17:48 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\jnwmon.dll
2015-11-11 17:46 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2015-11-11 17:45 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-11-11 17:45 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-11-11 17:40 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\windows\system32\aelupsvc.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-11-11 17:40 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-11-11 17:40 - 2015-10-17 17:56 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-11-11 17:39 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-11-06 21:49 - 2015-11-07 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-05 09:25 - 2015-11-05 09:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2015-10-15 12:58 - 2015-09-18 20:22 - 00025432 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-10-15 12:58 - 2015-09-18 20:19 - 01291264 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00766464 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00700416 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-10-15 12:58 - 2015-09-18 20:09 - 01163776 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-10-14 13:27 - 2015-08-06 19:04 - 14176768 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-10-14 13:27 - 2015-08-06 19:03 - 01866752 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2015-10-14 13:27 - 2015-08-06 18:44 - 12875776 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-10-14 13:27 - 2015-08-06 18:44 - 01498624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2015-10-14 13:26 - 2015-10-01 19:06 - 00692672 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2015-10-14 13:26 - 2015-10-01 19:04 - 00616360 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2015-10-14 13:26 - 2015-10-01 19:00 - 00147456 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2015-10-14 13:26 - 2015-10-01 19:00 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2015-10-14 13:26 - 2015-10-01 19:00 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-10-14 13:26 - 2015-10-01 19:00 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-10-14 13:26 - 2015-10-01 19:00 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2015-10-14 13:26 - 2015-10-01 18:50 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2015-10-14 13:26 - 2015-10-01 18:00 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2015-10-14 13:24 - 2015-07-18 14:08 - 00984448 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00901264 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-13 01:29 - 2015-10-13 01:29 - 00875720 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr120_clr0400.dll
2015-10-13 01:22 - 2015-10-13 01:22 - 00869568 _____ (Microsoft Corporation) C:\windows\system32\msvcr120_clr0400.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-12 11:17 - 2012-08-30 14:16 - 00000000 ____D C:\Users\Notebook
2015-11-12 11:14 - 2012-08-30 14:16 - 06947486 _____ C:\FaceProv.log
2015-11-12 11:06 - 2012-05-23 12:11 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-12 10:58 - 2012-05-23 11:17 - 01296118 _____ C:\windows\WindowsUpdate.log
2015-11-12 10:50 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-12 10:50 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-12 10:42 - 2012-10-21 11:18 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-11-12 10:41 - 2012-05-23 02:58 - 00699440 _____ C:\windows\system32\perfh007.dat
2015-11-12 10:41 - 2012-05-23 02:58 - 00149548 _____ C:\windows\system32\perfc007.dat
2015-11-12 10:41 - 2009-07-14 06:13 - 01619700 _____ C:\windows\system32\PerfStringBackup.INI
2015-11-12 10:36 - 2012-05-23 12:12 - 00195731 _____ C:\windows\system32\fastboot.set
2015-11-12 10:36 - 2012-05-23 12:03 - 00000000 ____D C:\ProgramData\VeriFace
2015-11-12 10:35 - 2012-10-24 14:24 - 00065536 _____ C:\windows\system32\Ikeext.etl
2015-11-12 10:35 - 2012-05-23 12:11 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-12 10:35 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-11-12 10:34 - 2014-03-19 12:38 - 40038037 _____ C:\windows\system32\PsBoot.log
2015-11-12 10:34 - 2014-03-19 12:38 - 00000000 _____ C:\windows\system32\defragLog.log
2015-11-12 10:34 - 2014-02-23 22:07 - 00108738 _____ C:\windows\setupact.log
2015-11-11 21:46 - 2009-07-14 04:20 - 00000000 ____D C:\windows\tracing
2015-11-11 19:58 - 2009-07-14 05:45 - 00337808 _____ C:\windows\system32\FNTCACHE.DAT
2015-11-11 18:49 - 2012-10-21 17:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 18:42 - 2012-10-21 11:18 - 00780488 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-11-11 18:42 - 2012-10-21 11:18 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-11 18:41 - 2011-09-29 04:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 17:41 - 2014-02-23 22:06 - 00154520 _____ C:\windows\PFRO.log
2015-11-11 17:32 - 2014-02-26 12:38 - 01593980 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2015-11-10 15:06 - 2014-07-24 11:21 - 00000000 ____D C:\windows\Minidump
2015-11-10 15:06 - 2014-07-24 11:20 - 445107906 _____ C:\windows\MEMORY.DMP
2015-11-09 22:24 - 2014-03-19 13:39 - 00000000 ____D C:\AdwCleaner
2015-11-07 17:43 - 2012-10-21 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-18 10:35 - 2014-01-31 14:51 - 00000000 ____D C:\Users\Nora\Desktop\Uni Praktikum
2015-10-17 18:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2015-10-15 15:01 - 2014-12-12 21:08 - 00000000 ____D C:\windows\system32\appraiser
2015-10-15 15:01 - 2014-05-06 22:49 - 00000000 ___SD C:\windows\system32\CompatTel
2015-10-14 16:27 - 2015-03-17 11:18 - 00000000 ____D C:\Users\Nora\Desktop\Uwe
2015-10-13 17:05 - 2014-03-14 12:58 - 00000000 ____D C:\Users\Nora\Desktop\Nora

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-01-29 13:34 - 2014-01-29 13:34 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


ACHTUNG: ==> Auf den BCD konnte nicht zugegriffen werden. der Benutzer ist kein Administrator

GMER Logfile:
Code:

GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-11-12 12:21:35
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST320LT0 rev.0003 298,09GB
Running: Gmer-19357.exe; Driver: C:\Users\Notebook\AppData\Local\Temp\kxtdikow.sys
 
 
---- User code sections - GMER 2.1 ----
 
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000758e1401 2 bytes JMP 7528b21b C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000758e1419 2 bytes JMP 7528b346 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000758e1431 2 bytes JMP 75308fd1 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000758e144a 2 bytes CALL 7526489d C:\windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758e14dd 2 bytes JMP 753088c4 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758e14f5 2 bytes JMP 75308aa0 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000758e150d 2 bytes JMP 753087ba C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000758e1525 2 bytes JMP 75308b8a C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000758e153d 2 bytes JMP 7527fca8 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000758e1555 2 bytes JMP 752868ef C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000758e156d 2 bytes JMP 75309089 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000758e1585 2 bytes JMP 75308bea C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000758e159d 2 bytes JMP 7530877e C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758e15b5 2 bytes JMP 7527fd41 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758e15cd 2 bytes JMP 7528b2dc C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758e16b2 2 bytes JMP 75308f4c C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758e16bd 2 bytes JMP 75308713 C:\windows\syswow64\kernel32.dll
 
---- Registry - GMER 2.1 ----
 
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076fc1a13
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076fc1a13 (not active ControlSet)
 
---- EOF - GMER 2.1 ----

--- --- ---

M-K-D-B 12.11.2015 13:19

:hallo:


Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen.


Bitte beachte folgende Hinweise:
  • Falls wir Hinweise auf illegal erworbene Software finden, werden wir den Support unterbrechen bis jegliche Art von illegaler Software vom Rechner entfernt wurde.
  • Lies dir die Anleitungen sorgfältig durch. Solltest du Probleme haben, stoppe mit deiner Bearbeitung und beschreibe mir dein Problem so gut es geht.
  • Solltest du mir nicht innerhalb von 3 Tagen antworten, gehe ich davon aus, dass du keine Hilfe mehr benötigst. Dann lösche ich dein Thema aus meinem Abo. Solltest du einmal länger abwesend sein, so gib mir bitte Bescheid!
  • Während der Bereinigung bitte nichts installieren oder deinstallieren, außer ich bitte dich darum!
  • Bitte beachten: Download bei filepony.de: So ladet Ihr unsere Tools richtig!
  • Alle zu verwendenen Programme sind auf dem Desktop abzuspeichern und von dort zu starten!


Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags:
So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke aauf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Danke für deine Mitarbeit!





Wo hat Avira einen Trojaner gefunden (Pfad + Dateiname angeben oder die ganze Logdatei von Avira posten).


Zudem musst du FRST als Administrator ausführen.

nora.s 13.11.2015 00:08

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hallo Matthias!
Erstmal danke für die schnelle Antwort :daumenhoc

Leider kann ich dir den Pfad wo Avira den Trojaner gefunden hat nicht genau mitteilen. Die Version von Avira PC Cleaner ist ganz einfach gehalten.. Während es den Scan ausführt kann ich sehen was er gerade durchsucht, aber wenn er etwas gefunden hat, kann man nicht einsehen wo und wann. Er war gerade bei: C:Users/Nora/Desktop/Downloads/... (wenn ich nicht zu langsam war.. Sorry! Aber die durchsuchten Dateien laufen so schnell weiter.)
Auf dem Bildschirm nach dem Scan steht nur "Trash-1 TR/AD.Gamarue.Y.1144" und ein Kästchen zum Abwählen da. Wenn ich auf den Namen TR/.. klicke, komme ich auf eine Website "Virus Summary", auf welcher das Virus näher erklärt wird: Zusammenfassung

Name
TR/AD.Gamarue.Y.1144
Entdeckt am
12.10.2015
VDF Version
7.12.17.252 (2015-10-12 07:04)
Leider sind auch keinerlei Buttons oder Bedienelemente bei diesem Avira zu finden; also kann ich auch keine Logdatei senden..

Außerdem habe ich festgestellt, dass ich als Administrator nicht mehr ins Internet komme. Allerdings kann ich nicht sagen seit wann das so ist. Nutze den Rechner eigentlich ausschließlich unter meinem Unterkonto.

Hier der FRST Report:

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
durchgeführt von Notebook (Administrator) auf NOTEBOOK-PC (12-11-2015 16:54:27)
Gestartet von C:\Users\Nora\Desktop\Downloads
Geladene Profile: Notebook & Nora (Verfügbare Profile: Notebook & Nora & Uwelchen)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
() C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2012-05-23] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2012-05-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2012-05-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-05-23] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\MountPoints2: G - G:\AutoRun.exe
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\MountPoints2: {4fd9a8e5-1d2b-11e2-8084-446d57e77fa7} - E:\AutoRun.exe
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\MountPoints2: {4fd9a8f2-1d2b-11e2-8084-446d57e77fa7} - G:\AutoRun.exe
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\MountPoints2: {4fd9a97e-1d2b-11e2-8084-dc0ea1f08c4d} - E:\AutoRun.exe
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\MountPoints2: {4fd9a981-1d2b-11e2-8084-dc0ea1f08c4d} - E:\AutoRun.exe
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\MountPoints2: {74eb9651-a4c3-11e1-94d8-806e6f6e6963} - F:\Setup.exe
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\MountPoints2: {72c6dce6-520b-11e3-9d67-446d57e77fa7} - E:\LaunchU3.exe -a
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll [2012-05-23] ()
Startup: C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2015-11-12]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2013-12-06]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Beschränkung - Chrome <======= ACHTUNG

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

ProxyEnable: [S-1-5-21-1146881843-1855949487-4122649668-1000] => Proxy ist aktiviert.
ProxyServer: [S-1-5-21-1146881843-1855949487-4122649668-1000] => http=127.0.0.1:13828
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0434AB00-3F7C-4291-91FB-BFB1A7FBC4E6}: [DhcpNameServer] 10.63.210.254
Tcpip\..\Interfaces\{0EA6BB07-2FF3-4059-B5F3-5A19971BFC92}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN_deDE506
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-10-21] (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-10-21] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> Kein Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  Keine Datei

FireFox:
========
FF ProfilePath: C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default
FF Session Restore: -> ist aktiviert.
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\windows\system32\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-15] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\awesomehp.xml [2014-02-23]

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [296400 2009-03-03] ()
S2 Update Fortunitas; "C:\Program Files (x86)\Fortunitas\updateFortunitas.exe" [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
U3 BcmSqlStartupSvc; kein ImagePath
U2 CLKMSVC10_3A60B698; kein ImagePath
U2 CLKMSVC10_C3B3B687; kein ImagePath
U2 DriverService; kein ImagePath
U2 iATAgentService; kein ImagePath
U2 idealife Update Service; kein ImagePath
U3 IGRS; kein ImagePath
U2 IviRegMgr; kein ImagePath
U2 nvUpdatusService; kein ImagePath
U2 Oasis2Service; kein ImagePath
U2 PCCarerService; kein ImagePath
U2 ReadyComm.DirectRouter; kein ImagePath
U2 RichVideo; kein ImagePath
U2 RtLedService; kein ImagePath
U2 SoftwareService; kein ImagePath
U3 SQLWriter; kein ImagePath
U2 Stereo Service; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-12 16:53 - 2015-11-12 16:53 - 00001260 _____ C:\Users\Nora\Desktop\FRST64 - Verknüpfung.lnk
2015-11-12 16:43 - 2015-11-12 16:43 - 00000000 ____D C:\Users\Notebook\AppData\Local\GWX
2015-11-12 12:29 - 2015-11-12 12:30 - 00007098 _____ C:\Users\Nora\Desktop\Gmer.odt
2015-11-12 12:28 - 2015-11-12 12:28 - 00000000 ____D C:\Users\Nora\Documents\OneNote-Notizbücher
2015-11-12 12:20 - 2015-11-12 12:21 - 00004120 _____ C:\Users\Notebook\Desktop\gmertxt.log
2015-11-12 12:06 - 2015-11-12 12:06 - 00280320 _____ C:\windows\Minidump\111215-26395-01.dmp
2015-11-12 11:27 - 2015-11-12 11:27 - 00000889 _____ C:\Users\Nora\Desktop\defogger_disable - Verknüpfung.lnk
2015-11-12 11:27 - 2015-11-12 11:27 - 00000884 _____ C:\Users\Nora\Desktop\defogger_enable - Verknüpfung.lnk
2015-11-12 11:22 - 2015-11-12 11:22 - 00058427 _____ C:\Users\Nora\Desktop\FRST.txt
2015-11-12 11:21 - 2015-11-12 11:21 - 00025844 _____ C:\Users\Nora\Desktop\Addition.txt
2015-11-12 11:18 - 2015-11-12 16:54 - 00000000 ____D C:\FRST
2015-11-12 11:17 - 2015-11-12 11:17 - 00000000 _____ C:\Users\Notebook\defogger_reenable
2015-11-12 10:52 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-11-11 17:49 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-11-11 17:49 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-11-11 17:49 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-11-11 17:49 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-11-11 17:49 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-11-11 17:49 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-11-11 17:49 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-11-11 17:49 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-11-11 17:49 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-11-11 17:49 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-11-11 17:49 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-11-11 17:49 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-11-11 17:49 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-11-11 17:49 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-11-11 17:49 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-11-11 17:49 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-11-11 17:49 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-11-11 17:49 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-11-11 17:49 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-11-11 17:49 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-11-11 17:49 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-11-11 17:49 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-11-11 17:49 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-11-11 17:49 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-11-11 17:49 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-11-11 17:49 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-11-11 17:49 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-11-11 17:48 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-11-11 17:48 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-11-11 17:48 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-11-11 17:48 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-11-11 17:48 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-11-11 17:48 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-11-11 17:48 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-11-11 17:48 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-11-11 17:48 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-11-11 17:48 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-11-11 17:48 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-11-11 17:48 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-11-11 17:48 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-11-11 17:48 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2015-11-11 17:48 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\jnwmon.dll
2015-11-11 17:46 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2015-11-11 17:45 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-11-11 17:45 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-11-11 17:40 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\windows\system32\aelupsvc.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-11-11 17:40 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-11-11 17:39 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-11-10 15:06 - 2015-11-10 15:06 - 00280320 _____ C:\windows\Minidump\111015-24726-01.dmp
2015-11-07 19:23 - 2015-11-07 19:23 - 00280320 _____ C:\windows\Minidump\110715-27315-01.dmp
2015-11-06 21:49 - 2015-11-07 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-05 09:25 - 2015-11-05 09:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2015-10-15 12:58 - 2015-09-18 20:22 - 00025432 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-10-15 12:58 - 2015-09-18 20:19 - 01291264 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00766464 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00700416 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-10-15 12:58 - 2015-09-18 20:09 - 01163776 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-10-14 13:27 - 2015-08-06 19:04 - 14176768 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-10-14 13:27 - 2015-08-06 19:03 - 01866752 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2015-10-14 13:27 - 2015-08-06 18:44 - 12875776 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-10-14 13:27 - 2015-08-06 18:44 - 01498624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2015-10-14 13:26 - 2015-10-01 19:06 - 00692672 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2015-10-14 13:26 - 2015-10-01 19:04 - 00616360 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2015-10-14 13:26 - 2015-10-01 19:00 - 00147456 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2015-10-14 13:26 - 2015-10-01 19:00 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2015-10-14 13:26 - 2015-10-01 19:00 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-10-14 13:26 - 2015-10-01 19:00 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-10-14 13:26 - 2015-10-01 19:00 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2015-10-14 13:26 - 2015-10-01 18:50 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2015-10-14 13:26 - 2015-10-01 18:00 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2015-10-14 13:24 - 2015-07-18 14:08 - 00984448 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00901264 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 13:24 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-13 01:29 - 2015-10-13 01:29 - 00875720 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr120_clr0400.dll
2015-10-13 01:22 - 2015-10-13 01:22 - 00869568 _____ (Microsoft Corporation) C:\windows\system32\msvcr120_clr0400.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-12 16:53 - 2012-08-30 14:16 - 06969521 _____ C:\FaceProv.log
2015-11-12 16:51 - 2012-05-23 12:12 - 00678977 _____ C:\windows\system32\fastboot.set
2015-11-12 16:51 - 2012-05-23 12:11 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-12 16:51 - 2012-05-23 12:03 - 00000000 ____D C:\ProgramData\VeriFace
2015-11-12 16:48 - 2014-02-23 22:07 - 00108906 _____ C:\windows\setupact.log
2015-11-12 16:48 - 2012-10-24 14:24 - 00065536 _____ C:\windows\system32\Ikeext.etl
2015-11-12 16:48 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-11-12 16:47 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-12 16:47 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-12 16:47 - 2009-07-14 04:20 - 00000000 ____D C:\windows\tracing
2015-11-12 16:46 - 2012-05-23 11:17 - 01340222 _____ C:\windows\WindowsUpdate.log
2015-11-12 16:46 - 2012-05-23 02:58 - 00699440 _____ C:\windows\system32\perfh007.dat
2015-11-12 16:46 - 2012-05-23 02:58 - 00149548 _____ C:\windows\system32\perfc007.dat
2015-11-12 16:46 - 2009-07-14 06:13 - 01619700 _____ C:\windows\system32\PerfStringBackup.INI
2015-11-12 16:42 - 2012-10-21 11:18 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-11-12 16:39 - 2009-07-14 05:45 - 00337808 _____ C:\windows\system32\FNTCACHE.DAT
2015-11-12 14:06 - 2012-05-23 12:11 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-12 13:46 - 2015-03-17 11:18 - 00000000 ____D C:\Users\Nora\Desktop\Uwe
2015-11-12 12:06 - 2014-07-24 11:21 - 00000000 ____D C:\windows\Minidump
2015-11-12 12:06 - 2014-07-24 11:20 - 1018855042 _____ C:\windows\MEMORY.DMP
2015-11-12 11:17 - 2012-08-30 14:16 - 00000000 ____D C:\Users\Notebook
2015-11-12 10:34 - 2014-03-19 12:38 - 40038037 _____ C:\windows\system32\PsBoot.log
2015-11-12 10:34 - 2014-03-19 12:38 - 00000000 _____ C:\windows\system32\defragLog.log
2015-11-11 18:49 - 2012-10-21 17:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 18:42 - 2012-10-21 11:18 - 00780488 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-11-11 18:42 - 2012-10-21 11:18 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-11 18:42 - 2012-10-21 11:18 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-11-11 18:41 - 2011-09-29 04:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 17:41 - 2014-02-23 22:06 - 00154520 _____ C:\windows\PFRO.log
2015-11-11 17:32 - 2014-02-26 12:38 - 01593980 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2015-11-09 22:24 - 2014-03-19 13:39 - 00000000 ____D C:\AdwCleaner
2015-11-07 17:43 - 2012-10-21 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-30 06:22 - 2015-07-10 18:40 - 00003886 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2015-10-18 10:35 - 2014-01-31 14:51 - 00000000 ____D C:\Users\Nora\Desktop\Uni Praktikum
2015-10-17 18:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2015-10-15 15:01 - 2014-12-12 21:08 - 00000000 ____D C:\windows\system32\appraiser
2015-10-15 15:01 - 2014-05-06 22:49 - 00000000 ___SD C:\windows\system32\CompatTel
2015-10-13 17:05 - 2014-03-14 12:58 - 00000000 ____D C:\Users\Nora\Desktop\Nora

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2013-04-05 17:01 - 2013-04-05 17:01 - 0002528 _____ () C:\Users\Notebook\AppData\Roaming\$_hpcst$.hpc
2014-01-29 13:34 - 2014-01-29 13:34 - 0000057 _____ () C:\ProgramData\Ament.ini

Einige Dateien in TEMP:
====================
C:\Users\Notebook\AppData\Local\Temp\install_flashplayer14x32_mssa_aaa_aih.exe
C:\Users\Notebook\AppData\Local\Temp\msvcm80.dll
C:\Users\Notebook\AppData\Local\Temp\msvcp80.dll
C:\Users\Notebook\AppData\Local\Temp\msvcr80.dll
C:\Users\Notebook\AppData\Local\Temp\nsc6606.exe
C:\Users\Notebook\AppData\Local\Temp\nsc6B35.exe
C:\Users\Notebook\AppData\Local\Temp\nsiE97C.exe
C:\Users\Notebook\AppData\Local\Temp\nsiEF95.exe
C:\Users\Notebook\AppData\Local\Temp\nsr6E11.exe
C:\Users\Notebook\AppData\Local\Temp\OSU.exe
C:\Users\Notebook\AppData\Local\Temp\Quarantine.exe
C:\Users\Notebook\AppData\Local\Temp\Uninstaller.exe
C:\Users\Notebook\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Notebook\AppData\Local\Temp\WtgDriverInstallX.dll
C:\Users\Notebook\AppData\Local\Temp\WTGXMLUtil.dll


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-11-02 09:59

==================== Ende von FRST.txt ============================

Hallo Matthias!
Noch ein kurzer Nachtrag: Habe mit "vollständigem Scan" jetzt auch mit Microsoft Security Essentials etwas gefunden -win32/SubTabBrowserMidifer -auch hier kann ich leider keine logdatei öffnen. Der Pfad wurde aber angezeigt:

- containerfile:C:/User/Notebook/AppData/local/Temp/fullpackage-temp1393149691/package1.zip
- file:C:User/Notebook/AppData/local/Temp/fullpackage-temp1393149691/package1.zip''zip.>QQBrowserFrame.dll

Als ich den Virus löschen wollte zeigte das Programm eine Fehlermeldung an:
Fehlercode:0x80070005.Zugriffverweigert

Hoffe meine Infos können behilflich sein.. Vielen Dank noch mal!!!!

Grüße Nora

M-K-D-B 13.11.2015 16:02

Servus,


alle Programme bitte zukünftig mit Rechtsklick > Als Administrator ausführen.




Zukünftig bitte beachten:
Zitat:

Gestartet von C:\Users\Nora\Desktop\Downloads
Leider hast du unsere Anleitung nicht richtig befolgt:
Bitte alle Tools direkt auf den Desktop downloaden bzw. dorthin verschieben und vom Desktop starten, da unsere Anleitungen daraufhin ausgelegt sind.
Zudem lassen sich dann am Ende der Bereinigung alle verwendeten Tools sehr einfach entfernen.
Alle Tools bis zum Ende der Bereinigung auf dem Desktop lassen, evtl. benötigen wir manche öfter.






Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


nora.s 13.11.2015 17:22

Hallo!
Combofix hat zuerst normal gescannt, doch nach dem Neustart ist der Programmbildschirm wie verückt auf dem Desktop "rumgeflattert". Ich konnte nichts mehr bedienen. Auch nach mehrmaligem Neustart - durch Stecker ziehen - keine Änderung. Habe dann versucht Combofix im abgesicherten Modus zu löschen, was zumindest dazu geführt hat, dass das Programm in seinen Bewegungen kurz angehalten hat. Dann konnte ich es schließen. (Auch bei den anderen Benutzern war es das Gleiche)

Bitte um schnelle Hilfe, habe Angst, dass ich gar nichts mehr mit dem Rechner machen kann..

M-K-D-B 13.11.2015 18:01

Servus,




Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST Download FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Ja und klicke Untersuchen
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).


nora.s 14.11.2015 11:05

Hallo!
Hier die Datei von FRST

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by SYSTEM on MININT-UI62CVN (14-11-2015 10:52:25)
Running from G:\
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Englisch (USA)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-07] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2012-05-23] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2012-05-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2012-05-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-29] (Microsoft Corporation)
HKLM\...\Run: [combofix] => C:\ComboFix\Combobatch.bat [8271 2015-11-13] ()
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-28] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-28] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-05-23] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-20] (Apple Inc.)
HKLM\...\RunOnce: [combofix] => C:\ComboFix\CF6796.3XE /c C:\ComboFixCombobatch.bat
HKLM\...\runonceex: [flags] => 8
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\Nora\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
Startup: C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2015-11-12]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2013-12-06]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction - Chrome <======= ATTENTION

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-29] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [296400 2009-03-03] ()
S2 Update Fortunitas; "C:\Program Files (x86)\Fortunitas\updateFortunitas.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S3 BcmSqlStartupSvc; no ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S2 CLKMSVC10_3A60B698; no ImagePath
S2 CLKMSVC10_C3B3B687; no ImagePath
S2 DriverService; no ImagePath
S2 iATAgentService; no ImagePath
S2 idealife Update Service; no ImagePath
S3 IGRS; no ImagePath
S2 IviRegMgr; no ImagePath
S2 nvUpdatusService; no ImagePath
S2 Oasis2Service; no ImagePath
S2 PCCarerService; no ImagePath
S2 ReadyComm.DirectRouter; no ImagePath
S2 RichVideo; no ImagePath
S2 RtLedService; no ImagePath
S2 SoftwareService; no ImagePath
S3 SQLWriter; no ImagePath
S2 Stereo Service; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-13 14:43 - 2015-11-13 14:55 - 00011964 _____ C:\Users\Nora\Desktop\anleitung frst.odt
2015-11-13 07:28 - 2015-11-13 07:38 - 00000000 ___SD C:\ComboFix
2015-11-13 07:28 - 2011-06-25 22:45 - 00256000 _____ C:\Windows\PEV.exe
2015-11-13 07:28 - 2010-11-07 09:20 - 00208896 _____ C:\Windows\MBR.exe
2015-11-13 07:28 - 2009-04-19 20:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-11-13 07:28 - 2000-08-30 16:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-11-13 07:28 - 2000-08-30 16:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-11-13 07:28 - 2000-08-30 16:00 - 00098816 _____ C:\Windows\sed.exe
2015-11-13 07:28 - 2000-08-30 16:00 - 00080412 _____ C:\Windows\grep.exe
2015-11-13 07:28 - 2000-08-30 16:00 - 00068096 _____ C:\Windows\zip.exe
2015-11-13 07:21 - 2015-11-13 07:22 - 00000000 ____D C:\Qoobox
2015-11-13 07:20 - 2015-11-13 07:38 - 00000000 ____D C:\Windows\erdnt
2015-11-12 08:01 - 2015-11-12 08:01 - 00059877 _____ C:\Users\Nora\Desktop\FRST.txt
2015-11-12 07:58 - 2015-11-12 07:58 - 00059877 _____ C:\Users\Notebook\Desktop\FRST.txt
2015-11-12 07:53 - 2015-11-12 07:53 - 00001260 _____ C:\Users\Nora\Desktop\FRST64 - Verknüpfung.lnk
2015-11-12 07:43 - 2015-11-12 07:43 - 00000000 ____D C:\Users\Notebook\AppData\Local\GWX
2015-11-12 03:29 - 2015-11-12 03:30 - 00007098 _____ C:\Users\Nora\Desktop\Gmer.odt
2015-11-12 03:28 - 2015-11-12 03:28 - 00000000 ____D C:\Users\Nora\Documents\OneNote-Notizbücher
2015-11-12 03:20 - 2015-11-12 03:21 - 00004120 _____ C:\Users\Notebook\Desktop\gmertxt.log
2015-11-12 03:06 - 2015-11-12 03:06 - 00280320 _____ C:\Windows\Minidump\111215-26395-01.dmp
2015-11-12 02:27 - 2015-11-12 02:27 - 00000889 _____ C:\Users\Nora\Desktop\defogger_disable - Verknüpfung.lnk
2015-11-12 02:27 - 2015-11-12 02:27 - 00000884 _____ C:\Users\Nora\Desktop\defogger_enable - Verknüpfung.lnk
2015-11-12 02:21 - 2015-11-12 02:21 - 00025844 _____ C:\Users\Nora\Desktop\Addition.txt
2015-11-12 02:18 - 2015-11-14 10:52 - 00000000 ____D C:\FRST
2015-11-12 02:17 - 2015-11-12 02:17 - 00000000 _____ C:\Users\Notebook\defogger_reenable
2015-11-12 01:52 - 2015-11-03 09:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2015-11-11 08:49 - 2015-11-03 14:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2015-11-11 08:49 - 2015-11-03 13:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-11-11 08:49 - 2015-10-30 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2015-11-11 08:49 - 2015-10-30 15:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2015-11-11 08:49 - 2015-10-30 15:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2015-11-11 08:49 - 2015-10-30 15:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2015-11-11 08:49 - 2015-10-30 15:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2015-11-11 08:49 - 2015-10-30 15:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2015-11-11 08:49 - 2015-10-30 15:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2015-11-11 08:49 - 2015-10-30 15:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2015-11-11 08:49 - 2015-10-30 15:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2015-11-11 08:49 - 2015-10-30 15:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2015-11-11 08:49 - 2015-10-30 15:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2015-11-11 08:49 - 2015-10-30 15:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2015-11-11 08:49 - 2015-10-30 15:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2015-11-11 08:49 - 2015-10-30 15:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2015-11-11 08:49 - 2015-10-30 15:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2015-11-11 08:49 - 2015-10-30 15:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2015-11-11 08:49 - 2015-10-30 15:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2015-11-11 08:49 - 2015-10-30 14:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-11-11 08:49 - 2015-10-30 14:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-11-11 08:49 - 2015-10-30 14:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-11 08:49 - 2015-10-30 14:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2015-11-11 08:49 - 2015-10-30 14:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-11 08:49 - 2015-10-30 14:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2015-11-11 08:49 - 2015-10-30 14:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-11-11 08:49 - 2015-10-30 14:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-11-11 08:49 - 2015-10-30 14:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-11-11 08:49 - 2015-10-30 14:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2015-11-11 08:49 - 2015-10-30 14:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-11-11 08:49 - 2015-10-30 14:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-11 08:49 - 2015-10-30 14:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-11-11 08:49 - 2015-10-30 14:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-11-11 08:49 - 2015-10-30 14:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-11-11 08:49 - 2015-10-30 14:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-11 08:49 - 2015-10-30 14:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-11-11 08:49 - 2015-10-30 14:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-11-11 08:49 - 2015-10-30 14:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2015-11-11 08:49 - 2015-10-30 14:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2015-11-11 08:49 - 2015-10-30 14:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2015-11-11 08:49 - 2015-10-30 14:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2015-11-11 08:49 - 2015-10-30 14:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2015-11-11 08:49 - 2015-10-30 14:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-11-11 08:49 - 2015-10-30 14:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 08:49 - 2015-10-30 14:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2015-11-11 08:49 - 2015-10-30 14:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-11-11 08:49 - 2015-10-30 14:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-11-11 08:49 - 2015-10-30 14:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-11-11 08:49 - 2015-10-30 14:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2015-11-11 08:49 - 2015-10-30 14:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-11-11 08:49 - 2015-10-30 14:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-11 08:49 - 2015-10-30 14:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-11-11 08:49 - 2015-10-30 14:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-11 08:49 - 2015-10-30 14:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-11 08:49 - 2015-10-30 14:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-11-11 08:49 - 2015-10-30 14:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-11-11 08:49 - 2015-10-30 14:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2015-11-11 08:49 - 2015-10-30 13:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2015-11-11 08:49 - 2015-10-30 13:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-11 08:49 - 2015-10-30 13:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-11 08:49 - 2015-10-30 13:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-11 08:49 - 2015-10-20 10:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2015-11-11 08:49 - 2015-10-20 10:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2015-11-11 08:49 - 2015-10-20 10:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2015-11-11 08:49 - 2015-10-20 10:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2015-11-11 08:49 - 2015-10-20 10:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2015-11-11 08:49 - 2015-10-20 10:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2015-11-11 08:49 - 2015-10-20 10:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2015-11-11 08:49 - 2015-10-20 10:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2015-11-11 08:49 - 2015-10-20 10:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll
2015-11-11 08:49 - 2015-10-20 10:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2015-11-11 08:49 - 2015-10-20 10:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll
2015-11-11 08:49 - 2015-10-20 09:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-11 08:49 - 2015-10-20 09:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-11 08:49 - 2015-10-20 09:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-11 08:49 - 2015-10-20 09:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-11-11 08:49 - 2015-10-20 09:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-11 08:48 - 2015-10-30 15:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2015-11-11 08:48 - 2015-10-30 15:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2015-11-11 08:48 - 2015-10-30 14:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2015-11-11 08:48 - 2015-10-19 17:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2015-11-11 08:48 - 2015-10-19 17:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2015-11-11 08:48 - 2015-10-19 17:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2015-11-11 08:48 - 2015-10-19 17:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2015-11-11 08:48 - 2015-10-19 17:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2015-11-11 08:48 - 2015-10-19 17:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2015-11-11 08:48 - 2015-10-19 17:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2015-11-11 08:48 - 2015-10-19 17:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2015-11-11 08:48 - 2015-10-19 17:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
2015-11-11 08:48 - 2015-10-19 17:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
2015-11-11 08:48 - 2015-10-19 17:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2015-11-11 08:48 - 2015-10-19 17:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe
2015-11-11 08:48 - 2015-10-19 17:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
2015-11-11 08:48 - 2015-10-19 17:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2015-11-11 08:48 - 2015-10-19 17:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
2015-11-11 08:48 - 2015-10-19 16:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-11-11 08:48 - 2015-10-19 16:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-11-11 08:48 - 2015-10-19 16:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-11-11 08:48 - 2015-10-19 16:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-11-11 08:48 - 2015-10-19 16:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-11-11 08:48 - 2015-10-19 16:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-11-11 08:48 - 2015-10-19 16:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-11-11 08:48 - 2015-10-19 16:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-11-11 08:48 - 2015-10-19 16:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-11-11 08:48 - 2015-10-19 16:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-11-11 08:48 - 2015-10-19 16:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-11-11 08:48 - 2015-10-19 16:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-11-11 08:48 - 2015-10-19 16:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 16:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 15:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2015-11-11 08:48 - 2015-10-19 15:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2015-11-11 08:48 - 2015-10-19 15:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2015-11-11 08:48 - 2015-10-19 15:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-11-11 08:48 - 2015-10-19 15:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-11-11 08:48 - 2015-10-19 15:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 15:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 15:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 08:48 - 2015-10-19 15:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 08:48 - 2015-09-23 05:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2015-11-11 08:48 - 2015-09-23 05:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\System32\bcryptprimitives.dll
2015-11-11 08:48 - 2015-09-23 05:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-11 08:46 - 2015-10-01 10:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\System32\InkEd.dll
2015-11-11 08:46 - 2015-10-01 10:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\jnwmon.dll
2015-11-11 08:46 - 2015-10-01 09:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-11-11 08:45 - 2015-10-13 08:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys
2015-11-11 08:45 - 2015-10-13 08:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tdx.sys
2015-11-11 08:40 - 2015-10-29 09:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\System32\apphelp.dll
2015-11-11 08:40 - 2015-10-29 09:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\System32\aelupsvc.dll
2015-11-11 08:40 - 2015-10-29 09:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\System32\sdbinst.exe
2015-11-11 08:40 - 2015-10-29 09:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\shimeng.dll
2015-11-11 08:40 - 2015-10-29 09:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-11-11 08:40 - 2015-10-29 09:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-11-11 08:40 - 2015-10-29 09:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-11-11 08:39 - 2015-10-12 20:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2015-11-10 06:06 - 2015-11-10 06:06 - 00280320 _____ C:\Windows\Minidump\111015-24726-01.dmp
2015-11-07 10:23 - 2015-11-07 10:23 - 00280320 _____ C:\Windows\Minidump\110715-27315-01.dmp
2015-11-06 12:49 - 2015-11-07 08:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-05 00:25 - 2015-11-05 00:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2015-10-15 03:58 - 2015-09-18 11:22 - 00025432 _____ (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
2015-10-15 03:58 - 2015-09-18 11:19 - 01291264 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
2015-10-15 03:58 - 2015-09-18 11:19 - 00766464 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
2015-10-15 03:58 - 2015-09-18 11:19 - 00700416 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
2015-10-15 03:58 - 2015-09-18 11:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
2015-10-15 03:58 - 2015-09-18 11:19 - 00073216 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll
2015-10-15 03:58 - 2015-09-18 11:09 - 01163776 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-14 01:45 - 2012-08-30 05:16 - 07025060 _____ C:\FaceProv.log
2015-11-14 01:45 - 2012-05-23 03:12 - 00145927 _____ C:\Windows\System32\fastboot.set
2015-11-14 01:45 - 2012-05-23 03:11 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-14 01:45 - 2012-05-23 03:03 - 00000000 ____D C:\ProgramData\VeriFace
2015-11-14 01:44 - 2014-02-23 13:07 - 00109802 _____ C:\Windows\setupact.log
2015-11-14 01:44 - 2012-10-24 05:24 - 00065536 _____ C:\Windows\System32\Ikeext.etl
2015-11-14 01:44 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-14 01:41 - 2012-05-23 02:17 - 01540853 _____ C:\Windows\WindowsUpdate.log
2015-11-14 01:06 - 2012-05-23 03:11 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-14 00:42 - 2012-10-21 02:18 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-14 00:39 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\tracing
2015-11-14 00:24 - 2009-07-13 20:45 - 00028704 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-14 00:24 - 2009-07-13 20:45 - 00028704 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-14 00:15 - 2012-05-22 17:58 - 00699440 _____ C:\Windows\System32\perfh007.dat
2015-11-14 00:15 - 2012-05-22 17:58 - 00149548 _____ C:\Windows\System32\perfc007.dat
2015-11-14 00:15 - 2009-07-13 21:13 - 01619700 _____ C:\Windows\System32\PerfStringBackup.INI
2015-11-14 00:08 - 2014-03-19 03:38 - 41414212 _____ C:\Windows\System32\PsBoot.log
2015-11-14 00:02 - 2014-03-19 03:38 - 00000000 _____ C:\Windows\System32\defragLog.log
2015-11-13 07:38 - 2014-02-23 13:06 - 00155260 _____ C:\Windows\PFRO.log
2015-11-13 07:37 - 2014-06-14 12:18 - 00000000 ____D C:\Users\Notebook\AppData\Local\Adobe
2015-11-13 00:03 - 2009-07-13 21:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-11-12 07:39 - 2009-07-13 20:45 - 00337808 _____ C:\Windows\System32\FNTCACHE.DAT
2015-11-12 04:46 - 2015-03-17 02:18 - 00000000 ____D C:\Users\Nora\Desktop\Uwe
2015-11-12 03:06 - 2014-07-24 02:21 - 00000000 ____D C:\Windows\Minidump
2015-11-12 03:06 - 2014-07-24 02:20 - 1018855042 _____ C:\Windows\MEMORY.DMP
2015-11-12 02:17 - 2012-08-30 05:16 - 00000000 ____D C:\users\Notebook
2015-11-11 09:49 - 2012-10-21 08:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 09:42 - 2012-10-21 02:18 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-11 09:42 - 2012-10-21 02:18 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-11 09:42 - 2012-10-21 02:18 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-11-11 09:41 - 2011-09-28 19:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 08:32 - 2014-02-26 03:38 - 01593980 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-11-09 13:24 - 2014-03-19 04:39 - 00000000 ____D C:\AdwCleaner
2015-11-07 08:43 - 2012-10-21 02:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-29 21:22 - 2015-07-10 09:40 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-10-18 01:35 - 2014-01-31 05:51 - 00000000 ____D C:\Users\Nora\Desktop\Uni Praktikum
2015-10-17 09:34 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2015-10-15 06:01 - 2014-12-12 12:08 - 00000000 ____D C:\Windows\System32\appraiser
2015-10-15 06:01 - 2014-05-06 13:49 - 00000000 ___SD C:\Windows\System32\CompatTel

==================== Known DLLs (Whitelisted) =========================


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE Association (Whitelisted) =============


==================== Restore Points =========================

Restore point date: 2015-11-01 10:01
Restore point date: 2015-11-02 11:50
Restore point date: 2015-11-06 06:28
Restore point date: 2015-11-08 11:32
Restore point date: 2015-11-09 13:01
Restore point date: 2015-11-11 03:42
Restore point date: 2015-11-11 08:23
Restore point date: 2015-11-11 09:40
Restore point date: 2015-11-12 05:53
Restore point date: 2015-11-13 13:05

==================== Memory info ===========================

Percentage of memory in use: 10%
Total physical RAM: 8135.86 MB
Available physical RAM: 7295.5 MB
Total Virtual: 8134.06 MB
Available Virtual: 7291.14 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:254.14 GB) (Free:171.42 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:26.82 GB) NTFS
Drive g: () (Removable) (Total:7.37 GB) (Free:4.51 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: () (Fixed) (Total:0.2 GB) (Free:0.16 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 68E1532F)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=254.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7.4 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7.4 GB) - (Type=0B)


LastRegBack: 2015-11-02 00:59

==================== End of FRST.txt ============================

--- --- ---

--- --- ---

M-K-D-B 14.11.2015 14:07

Servus,




Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:

start
HKLM\...\Run: [combofix] => C:\ComboFix\Combobatch.bat [8271 2015-11-13] ()
C:\ComboFix
HKLM-x32\...\Run: [] => [X]
HKLM\...\RunOnce: [combofix] => C:\ComboFix\CF6796.3XE /c C:\ComboFixCombobatch.bat
HKLM\...\runonceex: [flags] => 8
C:\ComboFixCombobatch.bat
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
Reboot
end

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.





Berichte mir, ob dein Rechner danach wieder normal startet.

nora.s 14.11.2015 14:38

Hey!
Der Rechner lässt sich wieder normal starten, Yippieh!
Hier die logdatei
Code:

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by SYSTEM (2015-11-14 14:29:53) Run:1
Running from G:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
start
HKLM\...\Run: [combofix] => C:\ComboFix\Combobatch.bat [8271 2015-11-13] ()
C:\ComboFix
HKLM-x32\...\Run: [] => [X]
HKLM\...\RunOnce: [combofix] => C:\ComboFix\CF6796.3XE /c C:\ComboFixCombobatch.bat
HKLM\...\runonceex: [flags] => 8
C:\ComboFixCombobatch.bat
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
Reboot
end
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\combofix => value removed successfully
C:\ComboFix => moved successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\combofix => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\runonceex\\flags => value removed successfully
"C:\ComboFixCombobatch.bat" => not found.
catchme => service removed successfully
Reboot => Error: No automatic fix found for this entry.

==== End of Fixlog 14:29:53 ====

Soll ich mit dem was ich von dir kopiert habe noch etwas machen?

M-K-D-B 14.11.2015 16:29

Servus,


klar, wir müssen die Adware ja noch entfernen. ;)






Schritt 1
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).





Schritt 2
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.







Schritt 3

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.







Schritt 4
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Scan.
  • FRST erstellt nun zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei von AdwCleaner,
  • die Logdatei von MBAM,
  • die Logdatei von JRT,
  • die beiden neuen Logdateien von FRST.

nora.s 14.11.2015 19:15

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hallo!
Habe alle Dateien außer die von JRT. Als ich die Textdatei auf dem Desktop speichern wollte, kam die Meldung dass diese schon existiere. Auf dem Desktop war jedoch nur das Programm an sich. Auch eine Suche blieb erfolglos.. Kann ich die Datei trotzdem noch irgendwo finden??:confused:

Hier die anderen Dateien:

Code:

# AdwCleaner v5.020 - Bericht erstellt am 14/11/2015 um 17:28:51
# Aktualisiert am 13/11/2015 von Xplode
# Datenbank : 2015-11-13.1 [Lokal]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Notebook - NOTEBOOK-PC
# Gestartet von : C:\Users\Nora\Desktop\AdwCleaner_5.020.exe
# Option : Suchlauf
# Unterstützung : hxxp://toolslib.net/forum

***** [ Dienste ] *****


***** [ Ordner ] *****

Ordner Gefunden : C:\Program Files (x86)\Fortunitas
Ordner Gefunden : C:\Program Files (x86)\Uninstaller
Ordner Gefunden : C:\Users\Notebook\AppData\Local\PCSpeedRepair
Ordner Gefunden : C:\Users\Notebook\Documents\PCSpeedRepair

***** [ Dateien ] *****

Datei Gefunden : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\awesomehp.xml
Datei Gefunden : C:\Users\Nora\daemonprocess.txt
Datei Gefunden : C:\Users\Notebook\daemonprocess.txt
Datei Gefunden : C:\Users\Notebook\Desktop\Continue VuuPC Installation.lnk

***** [ DLL ] *****


***** [ Verknüpfungen ] *****


***** [ Aufgabenplanung ] *****

Aufgabenplanung Gefunden : AmiUpdXp

***** [ Registrierungsdatenbank ] *****

Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginService
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gefunden : HKCU\Software\Mozilla\Extends
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [HQ-Video-Profession-1.3-bg.exe]
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{4E7F49ED-8C94-4AAA-A407-3010D099B11A}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{B8445FED-900C-4137-AD15-DDD2F6306B62}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{BB27DF2F-6F05-4A42-9FFD-14696D795750}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{C00F4B2B-A33C-40FC-8E47-4D18DCD4B01E}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{9989BC14-9B5B-4B3B-8040-478FD1685E34}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{42CB7963-EFE0-4737-A927-CE076FAA3BA0}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{4B8E39FD-ED07-4A41-9681-3D78DAFCEE66}
Schlüssel Gefunden : HKCU\Software\PCSpeedRepairLanguage
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Re_Markit
Schlüssel Gefunden : HKLM\SOFTWARE\awesomehpSoftware
Schlüssel Gefunden : HKLM\SOFTWARE\Taronja
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ValueApps
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DMUninstaller
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video Downloader_is1
Schlüssel Gefunden : HKU\.DEFAULT\Software\PCSpeedRepairLanguage
Schlüssel Gefunden : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKU\.DEFAULT\Software\AppDataLow\Software\MediaPlayerEnhance
Schlüssel Gefunden : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\MediaPlayerEnhance
Schlüssel Gefunden : HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKU\S-1-5-20\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\InstalledBrowserExtensions
Schlüssel Gefunden : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Optimizer Pro
Schlüssel Gefunden : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\systweak
Schlüssel Gefunden : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\AppDataLow\Software\Crossrider
Schlüssel Gefunden : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\AppDataLow\Software\MediaPlayerEnhance
Schlüssel Gefunden : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\AppDataLow\Software\Re_Markit
Schlüssel Gefunden : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\MediaPlayerEnhance

***** [ Internetbrowser ] *****


########## EOF - \AdwCleaner\AdwCleaner[S10].txt - [5156 Bytes] ##########

Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlaufdatum: 14.11.2015
Suchlaufzeit: 17:39
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.2.0.1024
Malware-Datenbank: v2015.11.14.03
Rootkit-Datenbank: v2015.11.13.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Notebook

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 425644
Abgelaufene Zeit: 21 Min., 22 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 133
PUP.Optional.SearchProtect, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [30bbd9a4662515210cb5340244bef50b],
PUP.Optional.HQVideoPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\HQ-Video-Profession-1.3-chromeinstaller, Löschen bei Neustart, [da11334a4c3fa096eb6f93e452b1cb35],
PUP.Optional.HQVideoPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\HQ-Video-Profession-1.3-codedownloader, Löschen bei Neustart, [d5167a032c5fca6c3624c1b6e71c1de3],
PUP.Optional.HQVideoPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\HQ-Video-Profession-1.3-enabler, Löschen bei Neustart, [01eaf8851b70f343cd8d7ff80201e020],
PUP.Optional.HQVideoPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\HQ-Video-Profession-1.3-firefoxinstaller, Löschen bei Neustart, [b833fd806823eb4b0456aacdee155fa1],
PUP.Optional.HQVideoPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\HQ-Video-Profession-1.3-updater, Löschen bei Neustart, [feed75088dfe69cda7b35720966d827e],
PUP.Optional.MediaPlayer, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\MediaPlayerEnhance-chromeinstaller, Löschen bei Neustart, [7d6e9de02b6083b3bd3c1964649f51af],
PUP.Optional.MediaPlayer, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\MediaPlayerEnhance-codedownloader, Löschen bei Neustart, [31bae796f09b73c39f5a275673909070],
PUP.Optional.MediaPlayer, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\MediaPlayerEnhance-enabler, Löschen bei Neustart, [edfe017c3b501521ab4e9ce140c3f10f],
PUP.Optional.MediaPlayer, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\MediaPlayerEnhance-firefoxinstaller, Löschen bei Neustart, [23c8532adcaf7fb728d13d404cb7cc34],
PUP.Optional.MediaPlayer, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\MediaPlayerEnhance-updater, Löschen bei Neustart, [8c5f98e59feccc6a36c35a23887b9e62],
PUP.Optional.Fortunitas, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Fortunitas, In Quarantäne, [1ad193ea7a115dd9c85b99d9986b38c8],
PUP.Optional.HQVideo, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\HQ-Video-Profession-1.3, In Quarantäne, [effc5c213358fd39f6407700d132d030],
PUP.Optional.PlusHD, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-7.5, In Quarantäne, [b03b2e4fc6c561d5c380b4d33dc69d63],
PUP.Optional.PlusHD, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-7.5, In Quarantäne, [76752954bbd00c2a370c6423976c1ee2],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10A805BD-F384-43CB-9727-E95487E0AEC0}, In Quarantäne, [5e8d522bb6d563d3178e70fb10f3f709],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33427DED-4717-4CB8-9DE5-1CB8F2F93E2E}, In Quarantäne, [b03bb5c8a9e27fb7b9ecce9d6f942cd4],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{51C5A230-E7CA-4DEC-B9E0-706C26E9B28B}, In Quarantäne, [cd1ede9f3b507fb7485d482322e141bf],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7FFDE8AF-B3CD-45B8-B2C9-CA13FF23B74A}, In Quarantäne, [dc0f9be2602b7abc2e7782e9b053d030],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{873DF054-B5E6-43BC-AF24-463810B52285}, In Quarantäne, [dd0ec0bdd3b823137530581332d139c7],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A03C007B-D099-4EC5-AE11-2E3E1DD5C8B5}, In Quarantäne, [09e2f5885c2f70c6554f5c0f0ef57e82],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A361279D-8FA6-44AD-9930-8DE86807BF54}, In Quarantäne, [27c4daa3068515214b5ab4b708fb9d63],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B4D1C8EC-F42B-4F43-8143-A0B9EC315299}, In Quarantäne, [f9f2532a266578be1e87452683807d83],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E751B068-5C0E-4744-AA8B-607928BCA15A}, In Quarantäne, [6685a1dc315a61d51390016aa26103fd],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB8B6AB1-CC6A-4ED9-A35D-3F2C4DF9306F}, In Quarantäne, [14d78cf19cefa096faabc2a9857e25db],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F75DB25F-84DB-4F7A-B7AD-6C839EDCDACD}, In Quarantäne, [6b807ffe5932280ed6cf66055ca755ab],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F93670D3-578B-440D-ACE8-64A80859A3F8}, In Quarantäne, [44a76b122269f73fb2f180ebe61d31cf],
PUP.Optional.HQVideo, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\APPDATALOW\SOFTWARE\HQ-Video-Profession-1.3, In Quarantäne, [b239de9f6e1d23133402ee8908fb7a86],
PUP.Optional.PlusHD, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-7.5, In Quarantäne, [c427136ad0bb3df9192a4344a45f8d73],
PUP.Optional.MindSpark, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\APPDATALOW\SOFTWARE\TelevisionFanatic, In Quarantäne, [f1fa90eda3e8f145a8022a557d8620e0],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10A805BD-F384-43CB-9727-E95487E0AEC0}, In Quarantäne, [feede39a2b608caab5f075f6ca39c838],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12B0149C-E6C6-46AF-8F45-DDBEDE5A9BEC}, In Quarantäne, [e209f18c8ffcc4721a8b96d55fa48d73],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{163E37F4-B963-4BF1-AAB4-5C257058E171}, In Quarantäne, [e10aaecf83080c2aecb898d39e65c23e],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{16F1C7D5-7B10-49D0-A1C5-379DC3C1EAFD}, In Quarantäne, [d01bdba22b6096a04b599dcec043a55b],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1FE88B2F-CB37-44E7-8E8F-85146F7B5A98}, In Quarantäne, [88633f3eff8cdc5ac6de422961a2ed13],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{20C80403-607E-4581-9052-5DBDD521DA81}, In Quarantäne, [40ab91ece5a61d1901a349226d96f010],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21123C3E-2475-462A-A2A3-13F76DFD1B56}, In Quarantäne, [d813601d810a58decbd95417c83b57a9],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{232C1473-CC07-44D0-A0C5-3A322EC08FF3}, In Quarantäne, [6d7e3b427f0cdf57daca115a31d20af6],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2653964D-905D-46BB-A692-AC3AD0923FDB}, In Quarantäne, [8e5d55286d1e4beb990cc5a6dd267888],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2914D42F-E917-4A9E-9258-F194C25DD62E}, In Quarantäne, [e605add091fab6806242303baf542bd5],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29C9A800-497D-42D7-8552-FB39C3BC2D25}, In Quarantäne, [24c72d50f992f5411d88cd9e34cff20e],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2B8B183A-75EB-443D-9E8D-C249526A817E}, In Quarantäne, [21ca94e9cdbe0e28fca84526a55e966a],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D3BDC41-CA60-4A62-802D-143D429688D3}, In Quarantäne, [8467abd2414a61d5f9ace18a897a7090],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2ED573AD-1077-4982-AA52-6D4FF8632038}, In Quarantäne, [886317662d5e95a10c995e0d768d46ba],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{316E9F90-433C-491E-89C1-3F7FAA34D9A3}, In Quarantäne, [c02ba1dc37548caa267e74f729dabc44],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{317735F9-DFDE-4DD3-8840-3EC3CA601AFE}, In Quarantäne, [78730b72acdf979f8b1a5912a063b24e],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{327671C5-4912-441D-B596-46D0DF2DE9A0}, In Quarantäne, [7c6fbebfdead80b63371f873937039c7],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33427DED-4717-4CB8-9DE5-1CB8F2F93E2E}, In Quarantäne, [e605b2cb355689ad683ddf8c857e8f71],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{383F8B47-654B-4D74-B868-3159CE8C63CA}, In Quarantäne, [1ecd9be25239fc3a188c78f3c3403ec2],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{39AC0CBE-1137-48F4-8552-A47A8D31B77E}, In Quarantäne, [6d7e15680883b680ecb9056613f0ca36],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3D2A1376-1820-441C-BEBA-88B931359DB9}, In Quarantäne, [b635007d860589ad8b19a4c7857ef808],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{418DC2B9-AA98-4A7C-BDEC-80F74B7B654F}, In Quarantäne, [2bc0f08d62291620bfe5d4973bc8966a],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{42401B7B-9FA1-48D7-BD18-D0A7E62F58C7}, In Quarantäne, [fcef48351873c571e1c46308ac5753ad],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{49D4990D-1749-4A9C-948F-FCC4EEF1B723}, In Quarantäne, [8962fd80602bb284f7ad1f4c0102f808],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EB5A94E-364B-4F87-B984-84EFE24A524F}, In Quarantäne, [43a8cfae3c4f0c2a1095f477bd467d83],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F025F2B-9FE9-45D9-A139-7077BB55C3A7}, In Quarantäne, [5695700dc8c344f2376dfc6f1ae94cb4],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5304C5FC-7F3A-4EAF-8B98-698CDE51D354}, In Quarantäne, [03e8621b8efddf57cbd9ef7cac578b75],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5583697E-866A-4C04-9A42-523C27F76331}, In Quarantäne, [c12af18c6328d75f9e078ddea85b25db],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{59119423-41FA-4BFE-921C-7CA541A28031}, In Quarantäne, [c7243845d4b7e155dec74b2004ffd12f],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{595C5139-791F-43B6-911C-7162D3479A43}, In Quarantäne, [29c255282a61ef475a4b80ebd42f36ca],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{60470B56-69B3-4554-A424-2F4B1B41B089}, In Quarantäne, [8863bac3038885b1752f3b30d52e3bc5],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63329885-C6DD-47F5-A747-355123F5BBD8}, In Quarantäne, [38b3d7a60a81b581079e88e3b0538080],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6574362D-F71C-4196-97A8-853A3FC05031}, In Quarantäne, [6f7ced9053389e98693ba5c628dbb44c],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6864A649-1432-4E5B-B487-3FAC43288118}, In Quarantäne, [4f9ce09dadde72c4aef6e784c3409a66],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{696E7000-C137-403F-B6AC-69246BA52DBC}, In Quarantäne, [6289423b761587af485d55160ff4867a],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{69963ACF-ECA0-424E-B758-EBC15E72B811}, In Quarantäne, [18d3314c404b36009f061952669db050],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A56C77A-F5F3-4E5A-BAAC-384EE46A225F}, In Quarantäne, [3caf2756fb90ad89f3b11754679cb34d],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B4392D7-4672-4E5E-B5AF-ABF47851B1DC}, In Quarantäne, [0be0b0cdaedd60d6733179f20cf7d729],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E53DC90-45CF-4D25-AFA0-F57DC224D361}, In Quarantäne, [c12a364789028caac7dec1aa18eb45bb],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73EC1B3A-5FF6-4548-A27E-CDA1DF74E49C}, In Quarantäne, [6a8119641a71b77f8e16501b54af7f81],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{751877D5-85B6-4399-B644-9F9457E99573}, In Quarantäne, [c12aa0dd414a6bcb574e204be122f30d],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{767A20E4-16F0-470E-A4F3-D7E8401632D8}, In Quarantäne, [1bd0126b305b2f079a0ba5c6fc076997],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7BD7E1E2-FE7B-443B-8AD9-59506D98F51A}, In Quarantäne, [7972cfaea7e4c86e7a2a7dee7c8744bc],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7CA845A3-B030-4631-B771-179A183F674F}, In Quarantäne, [56959edfaedd5fd76b392d3ec83ba060],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8162A781-80B9-4077-BB21-349282BACBD1}, In Quarantäne, [28c3106d4d3ec76facf872f951b214ec],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{83B1FCA3-42F4-4F00-8A4E-682C58335559}, In Quarantäne, [2bc017668ffc3402ddc71b506d963ec2],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84B51F27-92DC-43E6-AB81-87BAB023B98B}, In Quarantäne, [16d5433a7a11a294c1e47eed1ae9a45c],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8523E785-A9E0-4222-9FF7-8F4B11B82ED7}, In Quarantäne, [20cb4b3297f483b3267eed7e9e65c739],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87716C25-DB70-4526-A0BD-DA885046D126}, In Quarantäne, [2ebdb2cbc9c2f64003a26efdf1128a76],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8BD029C7-84A5-48DC-8CEE-97AE29B0A58E}, In Quarantäne, [36b53b42e3a89a9c8c18f07bd72cfb05],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{902B1082-2AD9-4162-A18A-E0782ED912EC}, In Quarantäne, [0fdc78053b50cc6a1d88066520e39c64],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{919477D6-5DCD-48C0-BB80-7EEDA6AFEFD4}, In Quarantäne, [d11ad9a4cbc02d091095d596778c42be],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{928B1970-929B-4155-A3E4-1B6626B9E1DE}, In Quarantäne, [9d4e4e2f513a5fd7d3d290dbac578878],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{977452B6-96F1-40B7-80C9-D7F92E8BF280}, In Quarantäne, [65867a0396f5c5710d985b1031d2ef11],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9C58D239-A13D-4270-B226-EA7E78BA227C}, In Quarantäne, [e506a4d9612a3ef83174e8837093b24e],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9C81B945-D6C6-4C9D-978D-FBBCA0618983}, In Quarantäne, [8c5fd0adfe8da98dbde7c1aaed16ab55],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9D077F6A-B5AC-4C25-8CB6-77652BC4836F}, In Quarantäne, [c7246d10e6a5082ea40193d8a95a8e72],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A03C007B-D099-4EC5-AE11-2E3E1DD5C8B5}, In Quarantäne, [5a910974a0ebf5415b4989e271922dd3],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A222DCE2-BCA6-457D-A25E-1A1C60F84B46}, In Quarantäne, [8665f08d39529b9bb4f06308fc071be5],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A41A3A39-2687-4E43-AA80-1971969FE3C9}, In Quarantäne, [87644d305437fd39b9ecf774d033fc04],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B20C1176-B708-4E0F-A533-26E588D5E1CC}, In Quarantäne, [14d7f28b494244f29213bfacdc27748c],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B30C1EE4-9321-4FF9-A734-295C32FB7CAC}, In Quarantäne, [569591ec880383b3adf74e1d8a79d927],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B4A3EA47-2A38-4189-B2E9-A59CA923BFA0}, In Quarantäne, [89628bf2206b38fe564ff774996a43bd],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B54C8A30-2690-45C1-817B-1D2DDB30AB37}, In Quarantäne, [de0d522b216a1b1b35709dced231a45c],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B622B54F-736A-42D0-87AA-6E194F7DBBE6}, In Quarantäne, [65867a03e5a63006099c2843a85be818],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7B16AEF-946D-4EAF-AD15-739EA1D2AF29}, In Quarantäne, [38b35a23becdfc3a545198d37093d828],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B84A4EC4-8B1B-41A9-BD7F-B027E194B310}, In Quarantäne, [0edd3a43107b0036d7ce25460af954ac],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B8F23660-E29E-41D8-8974-441829FC87C6}, In Quarantäne, [00ebb1ccdeadaf879f06f17a679c847c],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BE7D739F-3501-483E-9C2B-33D2D0343E27}, In Quarantäne, [5d8ed6a7c1ca58dea3027af1d23134cc],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C0F7F229-9D26-4EF1-9191-B3BE83E5EF44}, In Quarantäne, [7576245996f51d19168f72f9d92ad828],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C251887D-86A5-456D-A29C-CAD77AB0835A}, In Quarantäne, [9754df9e4843e94d9311b8b3966d20e0],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C2DA75E1-BBC6-468B-9C61-7C2EB1997063}, In Quarantäne, [a348562757341b1ba1042c3f7390ee12],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C546FAFF-6EB2-4AD2-BB97-38834772EB77}, In Quarantäne, [8368e19c0982d066c7ddec7fd52e28d8],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CA0F627C-951D-4500-961E-1F273BFFE18D}, In Quarantäne, [27c4bdc066256fc7d6cfabc00ff4936d],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D0211580-B1C9-410D-9BA0-D94C4CAC2386}, In Quarantäne, [e10af786375494a25d4787e429da17e9],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D2FC1B57-2E6D-4DFF-9232-BFCDBCC1AB3B}, In Quarantäne, [2fbc4538c6c582b413925b1055aeff01],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D3A2C82B-A9DD-4D03-AE1E-6F30689DA527}, In Quarantäne, [747775082f5c1323d7cd640749ba52ae],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4771DFC-AB52-45AB-B69F-DF276C96FE5F}, In Quarantäne, [3ab192eb9dee5cdaecb970fbaa599868],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DA58BF8C-3FBE-4AED-B5E6-1A488E1A8350}, In Quarantäne, [5299235a4546b086fda7f17a7390ae52],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DAD47ECE-52EB-4A69-BAE6-88FB4C17DCDA}, In Quarantäne, [44a71766b6d57bbb673d9ccf8f7445bb],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DB8B905D-5056-4615-9195-ED11231B41F7}, In Quarantäne, [f5f6f08d93f8e353079e76f55ba8f010],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DD286368-33E8-4892-A848-78E3D18B6B5C}, In Quarantäne, [8d5e5f1ec9c2e155b0f5da91cf34ed13],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE60CB5B-4DE4-4476-B885-ABF8851A47AE}, In Quarantäne, [de0dc6b74b4090a63d68abc01fe44ab6],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DFF56F4C-4634-4F34-B8D7-49798A70A19F}, In Quarantäne, [68830a73e8a3b482fea7016ab54e966a],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E3977D47-2C44-43BE-B713-FCD2681D2A75}, In Quarantäne, [9655a0dd3358d6604461e289e61d25db],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E485CBFF-6AF6-4A96-B95E-75DCDA1A7C2F}, In Quarantäne, [8d5e4d305932fc3a713482e9a16241bf],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6E9D63B-69B8-4732-9F8B-B307BB62DD73}, In Quarantäne, [8a617ffe8407979f8e1582e9d1320df3],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EAFB0BB1-FB99-4B12-9BBB-48EA65B4693B}, In Quarantäne, [ad3e4f2e46458caa822377f44bb8c53b],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB10B171-ECB2-410A-B17C-2B94CAA430EB}, In Quarantäne, [96552f4e6427b680386c422907fca858],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EC1B7CF9-1107-4726-A7C2-15D0E178FF6C}, In Quarantäne, [f0fb3a43c3c8f34314900b602cd720e0],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ECC03C00-7B4D-4735-9430-C7DEF0612A3F}, In Quarantäne, [d01b700d6e1de650b2f2abc0976c5fa1],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1A8C89F-2FC4-4A07-ACBD-45D33C11145F}, In Quarantäne, [73789ce1a4e7be78277d284321e26e92],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1D235FF-73C5-464A-9028-68C1C82D64D1}, In Quarantäne, [95561e5feaa174c2c0e4f675d62d22de],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F4313B68-316A-4BDC-AED7-DF884D2BC8BF}, In Quarantäne, [658664194c3f171faafaa8c341c2ad53],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F68F603E-CBD0-48EE-9934-FBF25B3341DB}, In Quarantäne, [c12a700d90fbe551089c70fb8380d729],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F91692C3-D64C-4A7C-922B-ED96EED63710}, In Quarantäne, [905b0f6e602b72c442632546798ae51b],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA4D9E4D-4651-4AFB-9A80-67F9889C5F9E}, In Quarantäne, [7f6c1c61880389ad4e564922996af50b],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB400239-C54B-4012-83FA-D193E575733C}, In Quarantäne, [1bd0324b0388db5b1e86d596897a38c8],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB5C80C3-BD67-44DD-A2B5-534EE1A82DAE}, In Quarantäne, [18d31a63365593a39d08a9c223e0619f],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBBE19FC-9113-4F9B-A4F9-3F3039A1FA48}, In Quarantäne, [1ad138452b60bb7bf2b21a510bf82dd3],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBE05101-32EA-41EC-8BEC-DD58974A38D5}, In Quarantäne, [29c2e39accbf48ee4d58c0ab0003a35d],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBFDCB04-DA71-410C-9E4C-1F4FED7C98B5}, In Quarantäne, [ba31daa3543755e1e4c008631fe44fb1],
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FE3C0383-D234-4653-BBEB-A8F97B3FE979}, In Quarantäne, [f6f5afcea5e6d95de5bf521939ca8e72],

Registrierungswerte: 116
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10A805BD-F384-43CB-9727-E95487E0AEC0}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [5e8d522bb6d563d3178e70fb10f3f709]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33427DED-4717-4CB8-9DE5-1CB8F2F93E2E}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [b03bb5c8a9e27fb7b9ecce9d6f942cd4]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{51c5a230-e7ca-4dec-b9e0-706c26e9b28b}|AppName, HQ-Video-Profession-1.3-codedownloader.exe, In Quarantäne, [cd1ede9f3b507fb7485d482322e141bf]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7FFDE8AF-B3CD-45B8-B2C9-CA13FF23B74A}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [dc0f9be2602b7abc2e7782e9b053d030]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{873DF054-B5E6-43BC-AF24-463810B52285}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [dd0ec0bdd3b823137530581332d139c7]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A03C007B-D099-4EC5-AE11-2E3E1DD5C8B5}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [09e2f5885c2f70c6554f5c0f0ef57e82]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a361279d-8fa6-44ad-9930-8de86807bf54}|AppName, MediaPlayerEnhance-codedownloader.exe, In Quarantäne, [27c4daa3068515214b5ab4b708fb9d63]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B4D1C8EC-F42B-4F43-8143-A0B9EC315299}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [f9f2532a266578be1e87452683807d83]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{e751b068-5c0e-4744-aa8b-607928bca15a}|AppName, MediaPlayerEnhance-bg.exe, In Quarantäne, [6685a1dc315a61d51390016aa26103fd]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB8B6AB1-CC6A-4ED9-A35D-3F2C4DF9306F}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [14d78cf19cefa096faabc2a9857e25db]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F75DB25F-84DB-4F7A-B7AD-6C839EDCDACD}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [6b807ffe5932280ed6cf66055ca755ab]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{f93670d3-578b-440d-ace8-64a80859a3f8}|AppName, HQ-Video-Profession-1.3-bg.exe, In Quarantäne, [44a76b122269f73fb2f180ebe61d31cf]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10A805BD-F384-43CB-9727-E95487E0AEC0}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [feede39a2b608caab5f075f6ca39c838]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12B0149C-E6C6-46AF-8F45-DDBEDE5A9BEC}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [e209f18c8ffcc4721a8b96d55fa48d73]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{163E37F4-B963-4BF1-AAB4-5C257058E171}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [e10aaecf83080c2aecb898d39e65c23e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{16F1C7D5-7B10-49D0-A1C5-379DC3C1EAFD}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [d01bdba22b6096a04b599dcec043a55b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1FE88B2F-CB37-44E7-8E8F-85146F7B5A98}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [88633f3eff8cdc5ac6de422961a2ed13]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{20C80403-607E-4581-9052-5DBDD521DA81}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [40ab91ece5a61d1901a349226d96f010]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21123C3E-2475-462A-A2A3-13F76DFD1B56}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [d813601d810a58decbd95417c83b57a9]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{232C1473-CC07-44D0-A0C5-3A322EC08FF3}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [6d7e3b427f0cdf57daca115a31d20af6]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2653964D-905D-46BB-A692-AC3AD0923FDB}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [8e5d55286d1e4beb990cc5a6dd267888]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2914D42F-E917-4A9E-9258-F194C25DD62E}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [e605add091fab6806242303baf542bd5]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29C9A800-497D-42D7-8552-FB39C3BC2D25}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [24c72d50f992f5411d88cd9e34cff20e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2B8B183A-75EB-443D-9E8D-C249526A817E}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [21ca94e9cdbe0e28fca84526a55e966a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D3BDC41-CA60-4A62-802D-143D429688D3}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [8467abd2414a61d5f9ace18a897a7090]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2ED573AD-1077-4982-AA52-6D4FF8632038}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [886317662d5e95a10c995e0d768d46ba]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{316E9F90-433C-491E-89C1-3F7FAA34D9A3}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [c02ba1dc37548caa267e74f729dabc44]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{317735F9-DFDE-4DD3-8840-3EC3CA601AFE}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [78730b72acdf979f8b1a5912a063b24e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{327671C5-4912-441D-B596-46D0DF2DE9A0}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [7c6fbebfdead80b63371f873937039c7]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33427DED-4717-4CB8-9DE5-1CB8F2F93E2E}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [e605b2cb355689ad683ddf8c857e8f71]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{383F8B47-654B-4D74-B868-3159CE8C63CA}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [1ecd9be25239fc3a188c78f3c3403ec2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{39AC0CBE-1137-48F4-8552-A47A8D31B77E}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [6d7e15680883b680ecb9056613f0ca36]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3D2A1376-1820-441C-BEBA-88B931359DB9}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [b635007d860589ad8b19a4c7857ef808]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{418DC2B9-AA98-4A7C-BDEC-80F74B7B654F}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [2bc0f08d62291620bfe5d4973bc8966a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{42401B7B-9FA1-48D7-BD18-D0A7E62F58C7}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [fcef48351873c571e1c46308ac5753ad]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{49D4990D-1749-4A9C-948F-FCC4EEF1B723}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [8962fd80602bb284f7ad1f4c0102f808]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EB5A94E-364B-4F87-B984-84EFE24A524F}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [43a8cfae3c4f0c2a1095f477bd467d83]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F025F2B-9FE9-45D9-A139-7077BB55C3A7}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [5695700dc8c344f2376dfc6f1ae94cb4]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5304C5FC-7F3A-4EAF-8B98-698CDE51D354}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [03e8621b8efddf57cbd9ef7cac578b75]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5583697E-866A-4C04-9A42-523C27F76331}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [c12af18c6328d75f9e078ddea85b25db]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{59119423-41FA-4BFE-921C-7CA541A28031}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [c7243845d4b7e155dec74b2004ffd12f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{595C5139-791F-43B6-911C-7162D3479A43}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [29c255282a61ef475a4b80ebd42f36ca]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{60470B56-69B3-4554-A424-2F4B1B41B089}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [8863bac3038885b1752f3b30d52e3bc5]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63329885-C6DD-47F5-A747-355123F5BBD8}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [38b3d7a60a81b581079e88e3b0538080]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6574362D-F71C-4196-97A8-853A3FC05031}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [6f7ced9053389e98693ba5c628dbb44c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6864A649-1432-4E5B-B487-3FAC43288118}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [4f9ce09dadde72c4aef6e784c3409a66]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{696E7000-C137-403F-B6AC-69246BA52DBC}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [6289423b761587af485d55160ff4867a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{69963ACF-ECA0-424E-B758-EBC15E72B811}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [18d3314c404b36009f061952669db050]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A56C77A-F5F3-4E5A-BAAC-384EE46A225F}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [3caf2756fb90ad89f3b11754679cb34d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B4392D7-4672-4E5E-B5AF-ABF47851B1DC}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [0be0b0cdaedd60d6733179f20cf7d729]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E53DC90-45CF-4D25-AFA0-F57DC224D361}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [c12a364789028caac7dec1aa18eb45bb]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73EC1B3A-5FF6-4548-A27E-CDA1DF74E49C}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [6a8119641a71b77f8e16501b54af7f81]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{751877D5-85B6-4399-B644-9F9457E99573}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [c12aa0dd414a6bcb574e204be122f30d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{767A20E4-16F0-470E-A4F3-D7E8401632D8}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [1bd0126b305b2f079a0ba5c6fc076997]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7BD7E1E2-FE7B-443B-8AD9-59506D98F51A}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [7972cfaea7e4c86e7a2a7dee7c8744bc]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7CA845A3-B030-4631-B771-179A183F674F}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [56959edfaedd5fd76b392d3ec83ba060]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8162A781-80B9-4077-BB21-349282BACBD1}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [28c3106d4d3ec76facf872f951b214ec]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{83B1FCA3-42F4-4F00-8A4E-682C58335559}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [2bc017668ffc3402ddc71b506d963ec2]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84B51F27-92DC-43E6-AB81-87BAB023B98B}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [16d5433a7a11a294c1e47eed1ae9a45c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8523E785-A9E0-4222-9FF7-8F4B11B82ED7}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [20cb4b3297f483b3267eed7e9e65c739]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87716C25-DB70-4526-A0BD-DA885046D126}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [2ebdb2cbc9c2f64003a26efdf1128a76]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8BD029C7-84A5-48DC-8CEE-97AE29B0A58E}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [36b53b42e3a89a9c8c18f07bd72cfb05]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{902B1082-2AD9-4162-A18A-E0782ED912EC}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [0fdc78053b50cc6a1d88066520e39c64]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{919477D6-5DCD-48C0-BB80-7EEDA6AFEFD4}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [d11ad9a4cbc02d091095d596778c42be]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{928B1970-929B-4155-A3E4-1B6626B9E1DE}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [9d4e4e2f513a5fd7d3d290dbac578878]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{977452B6-96F1-40B7-80C9-D7F92E8BF280}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [65867a0396f5c5710d985b1031d2ef11]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9C58D239-A13D-4270-B226-EA7E78BA227C}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [e506a4d9612a3ef83174e8837093b24e]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9C81B945-D6C6-4C9D-978D-FBBCA0618983}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [8c5fd0adfe8da98dbde7c1aaed16ab55]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9D077F6A-B5AC-4C25-8CB6-77652BC4836F}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [c7246d10e6a5082ea40193d8a95a8e72]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A03C007B-D099-4EC5-AE11-2E3E1DD5C8B5}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [5a910974a0ebf5415b4989e271922dd3]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A222DCE2-BCA6-457D-A25E-1A1C60F84B46}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [8665f08d39529b9bb4f06308fc071be5]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A41A3A39-2687-4E43-AA80-1971969FE3C9}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [87644d305437fd39b9ecf774d033fc04]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B20C1176-B708-4E0F-A533-26E588D5E1CC}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [14d7f28b494244f29213bfacdc27748c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B30C1EE4-9321-4FF9-A734-295C32FB7CAC}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [569591ec880383b3adf74e1d8a79d927]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B4A3EA47-2A38-4189-B2E9-A59CA923BFA0}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [89628bf2206b38fe564ff774996a43bd]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B54C8A30-2690-45C1-817B-1D2DDB30AB37}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [de0d522b216a1b1b35709dced231a45c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B622B54F-736A-42D0-87AA-6E194F7DBBE6}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [65867a03e5a63006099c2843a85be818]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7B16AEF-946D-4EAF-AD15-739EA1D2AF29}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [38b35a23becdfc3a545198d37093d828]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B84A4EC4-8B1B-41A9-BD7F-B027E194B310}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [0edd3a43107b0036d7ce25460af954ac]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B8F23660-E29E-41D8-8974-441829FC87C6}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [00ebb1ccdeadaf879f06f17a679c847c]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BE7D739F-3501-483E-9C2B-33D2D0343E27}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [5d8ed6a7c1ca58dea3027af1d23134cc]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C0F7F229-9D26-4EF1-9191-B3BE83E5EF44}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [7576245996f51d19168f72f9d92ad828]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C251887D-86A5-456D-A29C-CAD77AB0835A}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [9754df9e4843e94d9311b8b3966d20e0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C2DA75E1-BBC6-468B-9C61-7C2EB1997063}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [a348562757341b1ba1042c3f7390ee12]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C546FAFF-6EB2-4AD2-BB97-38834772EB77}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [8368e19c0982d066c7ddec7fd52e28d8]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CA0F627C-951D-4500-961E-1F273BFFE18D}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [27c4bdc066256fc7d6cfabc00ff4936d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D0211580-B1C9-410D-9BA0-D94C4CAC2386}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [e10af786375494a25d4787e429da17e9]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D2FC1B57-2E6D-4DFF-9232-BFCDBCC1AB3B}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [2fbc4538c6c582b413925b1055aeff01]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D3A2C82B-A9DD-4D03-AE1E-6F30689DA527}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [747775082f5c1323d7cd640749ba52ae]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4771DFC-AB52-45AB-B69F-DF276C96FE5F}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [3ab192eb9dee5cdaecb970fbaa599868]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DA58BF8C-3FBE-4AED-B5E6-1A488E1A8350}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [5299235a4546b086fda7f17a7390ae52]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DAD47ECE-52EB-4A69-BAE6-88FB4C17DCDA}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [44a71766b6d57bbb673d9ccf8f7445bb]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DB8B905D-5056-4615-9195-ED11231B41F7}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [f5f6f08d93f8e353079e76f55ba8f010]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DD286368-33E8-4892-A848-78E3D18B6B5C}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [8d5e5f1ec9c2e155b0f5da91cf34ed13]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE60CB5B-4DE4-4476-B885-ABF8851A47AE}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [de0dc6b74b4090a63d68abc01fe44ab6]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DFF56F4C-4634-4F34-B8D7-49798A70A19F}|AppName, MediaPlayerEnhance-enabler.exe-codedownloader.exe, In Quarantäne, [68830a73e8a3b482fea7016ab54e966a]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E3977D47-2C44-43BE-B713-FCD2681D2A75}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [9655a0dd3358d6604461e289e61d25db]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E485CBFF-6AF6-4A96-B95E-75DCDA1A7C2F}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [8d5e4d305932fc3a713482e9a16241bf]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{e6e9d63b-69b8-4732-9f8b-b307bb62dd73}|AppName, Plus-HD-7.5-bg.exe, In Quarantäne, [8a617ffe8407979f8e1582e9d1320df3]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{eafb0bb1-fb99-4b12-9bbb-48ea65b4693b}|AppName, Plus-HD-7.5-codedownloader.exe, In Quarantäne, [ad3e4f2e46458caa822377f44bb8c53b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB10B171-ECB2-410A-B17C-2B94CAA430EB}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [96552f4e6427b680386c422907fca858]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EC1B7CF9-1107-4726-A7C2-15D0E178FF6C}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [f0fb3a43c3c8f34314900b602cd720e0]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ECC03C00-7B4D-4735-9430-C7DEF0612A3F}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [d01b700d6e1de650b2f2abc0976c5fa1]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1A8C89F-2FC4-4A07-ACBD-45D33C11145F}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [73789ce1a4e7be78277d284321e26e92]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1D235FF-73C5-464A-9028-68C1C82D64D1}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [95561e5feaa174c2c0e4f675d62d22de]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F4313B68-316A-4BDC-AED7-DF884D2BC8BF}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [658664194c3f171faafaa8c341c2ad53]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F68F603E-CBD0-48EE-9934-FBF25B3341DB}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [c12a700d90fbe551089c70fb8380d729]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F91692C3-D64C-4A7C-922B-ED96EED63710}|AppName, HQ-Video-Profession-1.3-enabler.exe-codedownloader.exe, In Quarantäne, [905b0f6e602b72c442632546798ae51b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA4D9E4D-4651-4AFB-9A80-67F9889C5F9E}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [7f6c1c61880389ad4e564922996af50b]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB400239-C54B-4012-83FA-D193E575733C}|AppName, MediaPlayerEnhance-enabler.exe-buttonutil.exe, In Quarantäne, [1bd0324b0388db5b1e86d596897a38c8]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB5C80C3-BD67-44DD-A2B5-534EE1A82DAE}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [18d31a63365593a39d08a9c223e0619f]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBBE19FC-9113-4F9B-A4F9-3F3039A1FA48}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [1ad138452b60bb7bf2b21a510bf82dd3]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBE05101-32EA-41EC-8BEC-DD58974A38D5}|AppName, Plus-HD-7.5-enabler.exe-codedownloader.exe, In Quarantäne, [29c2e39accbf48ee4d58c0ab0003a35d]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBFDCB04-DA71-410C-9E4C-1F4FED7C98B5}|AppName, Plus-HD-7.5-enabler.exe-buttonutil.exe, In Quarantäne, [ba31daa3543755e1e4c008631fe44fb1]
PUP.Optional.CrossRider, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FE3C0383-D234-4653-BBEB-A8F97B3FE979}|AppName, HQ-Video-Profession-1.3-enabler.exe-buttonutil.exe, In Quarantäne, [f6f5afcea5e6d95de5bf521939ca8e72]
PUP.Optional.OptimizerPro, HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Optimizer Pro, C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe, In Quarantäne, [06e52459e9a2bc7ac48c9fe6a95ae61a]

Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[5497cab3503b62d416fd054cc044ff01]

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:07-11-2015
durchgeführt von Nora (2015-11-14 18:21:16)
Gestartet von E:\
Windows 7 Home Premium Service Pack 1 (X64) (2012-08-30 13:16:26)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-1146881843-1855949487-4122649668-500 - Administrator - Disabled)
Gast (S-1-5-21-1146881843-1855949487-4122649668-501 - Limited - Disabled)
Nora (S-1-5-21-1146881843-1855949487-4122649668-1001 - Limited - Enabled) => C:\Users\Nora
Notebook (S-1-5-21-1146881843-1855949487-4122649668-1000 - Administrator - Enabled) => C:\Users\Notebook
Uwelchen (S-1-5-21-1146881843-1855949487-4122649668-1003 - Limited - Enabled) => C:\Users\Uwelchen

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Microsoft Security Essentials (Disabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Disabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.7.637 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
Benutzerhandbuch (x32 Version: 1.0.0.6 - Lenovo) Hidden
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CBR (HKLM\...\{A8305DB2-3F6A-43CF-8CE3-EFD3D0F1C352}) (Version: 0.7 - G.Waser)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.2.3442 - CDBurnerXP)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.4.51 - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.0 - Lenovo)
Energy Management (x32 Version: 6.0.2.0 - Lenovo) Hidden
Free DWG Viewer 7.3 (HKLM-x32\...\{16CF668C-104D-479F-88A9-739137AEF3AD}) (Version: 7.3.0.176 - IGC)
GeoGebra 4.4 (HKLM-x32\...\GeoGebra 4.4) (Version: 4.4.6.0 - International GeoGebra Institute)
Google Chrome (HKLM-x32\...\{73187774-F274-39D6-80A4-33778B3CBBD4}) (Version: 65.51.16478 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
HP Deskjet 1000 J110 series - Grundlegende Software für das Gerät (HKLM\...\{CED47C99-8892-4956-BCA7-CC3123531371}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1000 J110 series Hilfe (HKLM-x32\...\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3341 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 9 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.10.1209.1 - Lenovo EasyCamera)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo Games Console (HKLM-x32\...\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3728 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden
Lexmark S410 Series Deinstallationsprogamm (HKLM\...\Lexmark S410 Series) (Version:  - Lexmark International, Inc.)
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
Mozilla Thunderbird 31.7.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 de)) (Version: 31.7.0 - Mozilla)
Mozilla Thunderbird 38.2.0 (x86 de) (HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\Mozilla Thunderbird 38.2.0 (x86 de)) (Version: 38.2.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.0 - Frank Heindörfer, Philip Chinery)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10003 - Realtek Semiconductor Corp.)
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version:  - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Studie zur Verbesserung von HP Deskjet 1000 J110 series Produkten (HKLM\...\{28F4BC72-75AE-47DD-B5B3-2A027BCA48A7}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.0.0 - Synaptics Incorporated)
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.14563 - TeamViewer)
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo)
Verbindungsassistent (HKLM-x32\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent)
VeriFace (HKLM-x32\...\VeriFace) (Version: 4.0.0.1224 - Lenovo)
VLC media player 2.0.4 (HKLM-x32\...\VLC media player) (Version: 2.0.4 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Wiederherstellungspunkte =========================

ACHTUNG: Systemwiederherstellung ist deaktiviert
Überprüfen Sie den "winmgmt" Dienst oder reparieren Sie den WMI.


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2015-11-13 16:38 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts

127.0.0.1      localhost

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job =>
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job =>
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job =>

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2012-05-23 12:03 - 2012-05-23 12:03 - 01508192 _____ () C:\windows\system32\IcnOvrly.dll
2012-05-23 12:03 - 2012-05-23 12:03 - 00628064 _____ () C:\windows\system32\SimpleExt.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\ProgramData\Temp:373E1720

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{C06D5DF8-3461-4042-8F52-7EBCDE9FE5EB}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{A01CE26B-13D2-49C9-A92D-9B7D46120EAD}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{23CFB686-0B7E-4480-A9A3-CB0C2F765BAA}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{85C74DA7-449E-44C7-8E4E-1F4912152D42}] => (Allow) LPort=2869
FirewallRules: [{877B58CB-8D65-442A-8AF5-5FA372C19F10}] => (Allow) LPort=1900
FirewallRules: [{8D40A53C-4335-417B-9C4A-CB4692B6701D}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{17F942C8-12AD-4AA5-9463-4D84ED86C64F}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{494CA055-1977-42EC-B8BF-AE2174875BDB}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{7FB6858F-ED36-454A-8F9F-DF9A80AA76BF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{58AE4ECC-80E0-4F0D-BDC7-2CC30B8636BE}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{5C3FAB83-0355-4B03-8DC1-B8E0A07D7802}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{0C353832-0069-4E0E-9DC5-C406A89ED5BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C3FD3DA4-E429-4DDB-8AF6-37BB69E5EC76}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{DB0BA175-6DF7-49FB-BC0E-EB66246A1ACB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CD7CBA5A-1320-4B8A-86ED-D18730A7E38D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6DCD0473-2BF8-47E3-9577-F22D90E33E6C}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{1848B09C-A7F2-4E06-84AF-903D2D0CFCF1}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{600BE599-5822-48F3-B869-82DC5C62233C}] => (Allow) C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\USBSetup.exe
FirewallRules: [{795730CF-A64E-4915-8384-9C4A4D8606B1}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS0049\HPDiagnosticCoreUI.exe
FirewallRules: [{96963478-4C91-4FAA-A42F-C0519527DA88}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS0049\HPDiagnosticCoreUI.exe
FirewallRules: [{66F54DF8-0774-4E55-800F-073B4E8BB050}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS5C88\HPDiagnosticCoreUI.exe
FirewallRules: [{58ED8715-7D7E-4764-A2F4-1DC940D46FB9}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS5C88\HPDiagnosticCoreUI.exe
FirewallRules: [{2CF02080-21D3-4222-81D1-30FAE88FA2F6}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{E2CA7EE2-6A42-4951-B9E5-9C5E1FF1376A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A7998D86-49F1-4F44-886A-7F2D4CAE5C0A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{5488F4E7-619C-40F9-867A-5BE99F507EB9}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{4429A93B-8E63-407C-9B8A-3187FFC606B1}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{0F6DDD45-F3D6-43D5-B986-E7E4425ED8D6}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{6A2A115F-CFA8-4679-9084-9FDE758DE08E}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [{364D57E1-9EF3-4CC4-AA8F-B0113BACBDBD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DCD7E537-A65D-45B1-A414-9576213BC1E8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{193C3EDE-369F-49A2-A07D-C92D79A23A67}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (11/14/2015 06:17:28 PM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (11/14/2015 06:06:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/14/2015 05:47:11 PM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (11/14/2015 05:33:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/14/2015 05:21:49 PM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (11/14/2015 05:10:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/14/2015 02:44:39 PM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127

Error: (11/14/2015 02:32:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/14/2015 02:23:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/14/2015 11:12:43 AM) (Source: MsiInstaller) (EventID: 1024) (User: Notebook-PC)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011013}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127


Systemfehler:
=============
Error: (11/14/2015 06:20:07 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (11/14/2015 06:20:07 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (11/14/2015 06:20:06 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (11/14/2015 06:20:06 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (11/14/2015 06:13:22 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/14/2015 06:13:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Management and Security Application User Notification Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/14/2015 06:13:22 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Live ID Sign-in Assistant" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/14/2015 06:13:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "iPod-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/14/2015 06:13:22 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/14/2015 06:13:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.


CodeIntegrity:
===================================
  Date: 2015-11-13 16:37:33.753
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-11-13 16:37:33.675
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Pentium(R) CPU B960 @ 2.20GHz
Prozentuale Nutzung des RAM: 18%
Installierter physikalischer RAM: 8135.86 MB
Verfügbarer physikalischer RAM: 6612.81 MB
Summe virtueller Speicher: 16269.93 MB
Verfügbarer virtueller Speicher: 14762.98 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:254.14 GB) (Free:173.09 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:26.82 GB) NTFS
Drive e: () (Removable) (Total:7.37 GB) (Free:4.51 GB) FAT32

==================== MBR & Partitionstabelle ==================

==================== Ende von Addition.txt ============================


nora.s 14.11.2015 21:54

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hier der Rest:

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
durchgeführt von Notebook (Administrator) auf NOTEBOOK-PC (14-11-2015 18:22:21)
Gestartet von E:\
Geladene Profile: Notebook & Nora (Verfügbare Profile: Notebook & Nora & Uwelchen)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2012-05-23] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2012-05-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2012-05-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-05-23] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-10-05] (Malwarebytes)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[C10].txt
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\MountPoints2: {72c6dce6-520b-11e3-9d67-446d57e77fa7} - E:\LaunchU3.exe -a
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll [2012-05-23] ()
Startup: C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2015-11-12]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2013-12-06]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0434AB00-3F7C-4291-91FB-BFB1A7FBC4E6}: [DhcpNameServer] 10.63.210.254
Tcpip\..\Interfaces\{0EA6BB07-2FF3-4059-B5F3-5A19971BFC92}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN_deDE506
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-10-21] (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-10-21] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> Kein Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  Keine Datei

FireFox:
========
FF ProfilePath: C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default
FF Session Restore: -> ist aktiviert.
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\windows\system32\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-15] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [296400 2009-03-03] ()

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-14] (Malwarebytes)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
U3 BcmSqlStartupSvc; kein ImagePath
U2 CLKMSVC10_3A60B698; kein ImagePath
U2 CLKMSVC10_C3B3B687; kein ImagePath
U2 DriverService; kein ImagePath
U2 iATAgentService; kein ImagePath
U2 idealife Update Service; kein ImagePath
U3 IGRS; kein ImagePath
U2 IviRegMgr; kein ImagePath
U2 nvUpdatusService; kein ImagePath
U2 Oasis2Service; kein ImagePath
U2 PCCarerService; kein ImagePath
U2 ReadyComm.DirectRouter; kein ImagePath
U2 RichVideo; kein ImagePath
U2 RtLedService; kein ImagePath
U2 SoftwareService; kein ImagePath
U3 SQLWriter; kein ImagePath
U2 Stereo Service; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-14 18:18 - 2015-10-05 23:26 - 01801288 _____ (Malwarebytes) C:\Users\Notebook\Desktop\JRT.exe
2015-11-14 18:16 - 2015-11-14 18:16 - 00001462 _____ C:\Users\Notebook\Desktop\JRT.txt
2015-11-14 18:11 - 2015-11-14 18:22 - 00013549 _____ C:\FaceProv.log
2015-11-14 18:10 - 2015-11-14 18:10 - 00064759 _____ C:\Users\Nora\Desktop\mbam.txt
2015-11-14 17:38 - 2015-11-14 17:39 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-14 17:38 - 2015-11-14 17:38 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-14 17:38 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2015-11-14 17:38 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-11-14 17:38 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2015-11-14 17:30 - 2015-11-14 17:30 - 00001852 _____ C:\Users\Nora\Desktop\Quarantine.log
2015-11-14 17:28 - 2015-11-14 17:29 - 00005266 _____ C:\Users\Nora\Desktop\AdwCleaner[S10].txt
2015-11-14 17:25 - 2015-11-14 17:25 - 01798976 _____ (Malwarebytes) C:\Users\Nora\Desktop\JRT.exe
2015-11-14 17:24 - 2015-11-14 17:25 - 22908888 _____ (Malwarebytes ) C:\Users\Nora\Desktop\mbam-setup-2.2.0.1024.exe
2015-11-14 17:18 - 2015-11-14 17:18 - 01729536 _____ C:\Users\Nora\Desktop\AdwCleaner_5.020.exe
2015-11-13 23:43 - 2015-11-13 23:55 - 00011964 _____ C:\Users\Nora\Desktop\anleitung frst.odt
2015-11-13 16:28 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe
2015-11-13 16:28 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe
2015-11-13 16:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe
2015-11-13 16:21 - 2015-11-13 16:22 - 00000000 ____D C:\Qoobox
2015-11-13 16:20 - 2015-11-13 16:38 - 00000000 ____D C:\windows\erdnt
2015-11-12 16:58 - 2015-11-12 16:58 - 00059877 _____ C:\Users\Notebook\Desktop\FRST.txt
2015-11-12 16:43 - 2015-11-12 16:43 - 00000000 ____D C:\Users\Notebook\AppData\Local\GWX
2015-11-12 12:29 - 2015-11-12 12:30 - 00007098 _____ C:\Users\Nora\Desktop\Gmer.odt
2015-11-12 12:28 - 2015-11-12 12:28 - 00000000 ____D C:\Users\Nora\Documents\OneNote-Notizbücher
2015-11-12 12:20 - 2015-11-12 12:21 - 00004120 _____ C:\Users\Notebook\Desktop\gmertxt.log
2015-11-12 12:06 - 2015-11-12 12:06 - 00280320 _____ C:\windows\Minidump\111215-26395-01.dmp
2015-11-12 11:18 - 2015-11-14 18:22 - 00000000 ____D C:\FRST
2015-11-12 11:17 - 2015-11-12 11:17 - 00000000 _____ C:\Users\Notebook\defogger_reenable
2015-11-12 10:52 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-11-11 17:49 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-11-11 17:49 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-11-11 17:49 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-11-11 17:49 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-11-11 17:49 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-11-11 17:49 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-11-11 17:49 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-11-11 17:49 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-11-11 17:49 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-11-11 17:49 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-11-11 17:49 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-11-11 17:49 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-11-11 17:49 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-11-11 17:49 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-11-11 17:49 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-11-11 17:49 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-11-11 17:49 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-11-11 17:49 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-11-11 17:49 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-11-11 17:49 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-11-11 17:49 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-11-11 17:49 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-11-11 17:49 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-11-11 17:49 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-11-11 17:49 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-11-11 17:49 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-11-11 17:49 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-11-11 17:48 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-11-11 17:48 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-11-11 17:48 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-11-11 17:48 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-11-11 17:48 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-11-11 17:48 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-11-11 17:48 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-11-11 17:48 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-11-11 17:48 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-11-11 17:48 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-11-11 17:48 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-11-11 17:48 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-11-11 17:48 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-11-11 17:48 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2015-11-11 17:48 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\jnwmon.dll
2015-11-11 17:46 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2015-11-11 17:45 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-11-11 17:45 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-11-11 17:40 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\windows\system32\aelupsvc.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-11-11 17:40 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-11-11 17:39 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-11-10 15:06 - 2015-11-10 15:06 - 00280320 _____ C:\windows\Minidump\111015-24726-01.dmp
2015-11-07 19:23 - 2015-11-07 19:23 - 00280320 _____ C:\windows\Minidump\110715-27315-01.dmp
2015-11-06 21:49 - 2015-11-07 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-05 09:25 - 2015-11-05 09:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2015-10-15 12:58 - 2015-09-18 20:22 - 00025432 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-10-15 12:58 - 2015-09-18 20:19 - 01291264 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00766464 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00700416 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-10-15 12:58 - 2015-09-18 20:19 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-10-15 12:58 - 2015-09-18 20:09 - 01163776 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-14 18:21 - 2012-05-23 02:58 - 00699440 _____ C:\windows\system32\perfh007.dat
2015-11-14 18:21 - 2012-05-23 02:58 - 00149548 _____ C:\windows\system32\perfc007.dat
2015-11-14 18:21 - 2009-07-14 06:13 - 01619700 _____ C:\windows\system32\PerfStringBackup.INI
2015-11-14 18:20 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-14 18:20 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-14 18:11 - 2012-05-23 11:17 - 01595534 _____ C:\windows\WindowsUpdate.log
2015-11-14 18:09 - 2012-08-30 14:16 - 07060863 _____ C:\Users\Nora\Desktop\FaceProv.log
2015-11-14 18:07 - 2009-07-14 04:20 - 00000000 ____D C:\windows\tracing
2015-11-14 18:06 - 2012-05-23 12:11 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-14 18:06 - 2012-05-23 12:03 - 00000000 ____D C:\ProgramData\VeriFace
2015-11-14 18:05 - 2012-10-24 14:24 - 00065536 _____ C:\windows\system32\Ikeext.etl
2015-11-14 18:05 - 2012-05-23 12:12 - 00100787 _____ C:\windows\system32\fastboot.set
2015-11-14 18:05 - 2012-05-23 12:11 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-14 18:04 - 2014-02-23 22:07 - 00110194 _____ C:\windows\setupact.log
2015-11-14 18:04 - 2014-02-23 22:06 - 00155636 _____ C:\windows\PFRO.log
2015-11-14 18:04 - 2009-07-14 06:32 - 00000000 ____D C:\windows\addins
2015-11-14 18:04 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-11-14 17:42 - 2012-10-21 11:18 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-11-14 17:35 - 2014-03-19 13:39 - 00000000 ____D C:\AdwCleaner
2015-11-14 17:30 - 2013-12-18 12:54 - 00000000 ____D C:\Users\Nora
2015-11-14 17:30 - 2012-08-30 14:16 - 00000000 ____D C:\Users\Notebook
2015-11-14 14:47 - 2015-03-17 11:18 - 00000000 ____D C:\Users\Nora\Desktop\Uwe
2015-11-14 09:08 - 2014-03-19 12:38 - 41414212 _____ C:\windows\system32\PsBoot.log
2015-11-14 09:02 - 2014-03-19 12:38 - 00000000 _____ C:\windows\system32\defragLog.log
2015-11-13 16:37 - 2014-06-14 21:18 - 00000000 ____D C:\Users\Notebook\AppData\Local\Adobe
2015-11-13 09:03 - 2009-07-14 06:08 - 00032632 _____ C:\windows\Tasks\SCHEDLGU.TXT
2015-11-12 16:39 - 2009-07-14 05:45 - 00337808 _____ C:\windows\system32\FNTCACHE.DAT
2015-11-12 12:06 - 2014-07-24 11:21 - 00000000 ____D C:\windows\Minidump
2015-11-12 12:06 - 2014-07-24 11:20 - 1018855042 _____ C:\windows\MEMORY.DMP
2015-11-11 18:49 - 2012-10-21 17:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 18:42 - 2012-10-21 11:18 - 00780488 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-11-11 18:42 - 2012-10-21 11:18 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-11 18:42 - 2012-10-21 11:18 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-11-11 18:41 - 2011-09-29 04:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 17:32 - 2014-02-26 12:38 - 01593980 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2015-11-07 17:43 - 2012-10-21 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-30 06:22 - 2015-07-10 18:40 - 00003886 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2015-10-18 10:35 - 2014-01-31 14:51 - 00000000 ____D C:\Users\Nora\Desktop\Uni Praktikum
2015-10-17 18:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2015-10-15 15:01 - 2014-12-12 21:08 - 00000000 ____D C:\windows\system32\appraiser
2015-10-15 15:01 - 2014-05-06 22:49 - 00000000 ___SD C:\windows\system32\CompatTel

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2013-04-05 17:01 - 2013-04-05 17:01 - 0002528 _____ () C:\Users\Notebook\AppData\Roaming\$_hpcst$.hpc
2014-01-29 13:34 - 2014-01-29 13:34 - 0000057 _____ () C:\ProgramData\Ament.ini

Einige Dateien in TEMP:
====================
C:\Users\Notebook\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-11-02 09:59

==================== Ende von FRST.txt ============================

Danke für deine Geduld! :lach:

Gruß Nora

Habe jetzt noch zwei Mal JRT durchlaufen lassen. Beim ersten Mal habe ich nach der Meldung, die Textdatei wäre schon auf dem Desktop, die "angeblich" schon vorhandene Datei, ersetzt. Allerdings war sie wieder nicht auf dem Desktop zu finden. Eine Suche war erfolgreich, jedoch konnte die Datei wegen "fehlender Verknüpfung" nicht geöffnet werden.

Nach dem zweiten Durchlauf habe ich die Datei direkt aus dem Fenster, welches sich nach dem Scan automatisch öffnet, kopiert.

Hier das Ergebnis:
Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 7 Home Premium x64
Ran by Notebook on 14.11.2015 at 21:43:11,49
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Chrome


[C:\Users\Notebook\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Notebook\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Notebook\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Notebook\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.11.2015 at 21:46:19,22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


M-K-D-B 15.11.2015 13:05

Servus,



Zitat:

# Option : Suchlauf
Hast du die Funde von AdwCleaner auch entfernen lassen? :wtf:

Du hast die Logdatei des Suchlaufs gepostet, aber nicht die von der Entfernung...

nora.s 15.11.2015 13:41

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hallo!
Ja habe ich. Hoffe das ist die richtige Logdatei:
Code:

C:\Program Files (x86)\Uninstaller\Uninstall.exe->\AdwCleaner\Quarantine\C\Program Files (x86)\Uninstaller\Uninstall.exe.vir
C:\Program Files (x86)\Uninstaller\Uninstall.xml->\AdwCleaner\Quarantine\C\Program Files (x86)\Uninstaller\Uninstall.xml.vir
C:\Users\Notebook\AppData\Local\PCSpeedRepair\PCSpeedRepair.exe_Url_esiei4fbuzo1q3onjfpcyjsjh1ex5vji\2.4.7.0\user.config->\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\PCSpeedRepair\PCSpeedRepair.exe_Url_esiei4fbuzo1q3onjfpcyjsjh1ex5vji\2.4.7.0\user.config.vir
C:\Users\Notebook\Documents\PCSpeedRepair\errors->\AdwCleaner\Quarantine\C\Users\Notebook\Documents\PCSpeedRepair\errors.vir
C:\Users\Notebook\Documents\PCSpeedRepair\errors_data->\AdwCleaner\Quarantine\C\Users\Notebook\Documents\PCSpeedRepair\errors_data.vir
C:\Users\Notebook\Documents\PCSpeedRepair\fileerrors->\AdwCleaner\Quarantine\C\Users\Notebook\Documents\PCSpeedRepair\fileerrors.vir
C:\Users\Notebook\Documents\PCSpeedRepair\fileerrors_data->\AdwCleaner\Quarantine\C\Users\Notebook\Documents\PCSpeedRepair\fileerrors_data.vir
C:\Users\Notebook\Documents\PCSpeedRepair\logerror.txt->\AdwCleaner\Quarantine\C\Users\Notebook\Documents\PCSpeedRepair\logerror.txt.vir
C:\Users\Notebook\Documents\PCSpeedRepair\registry.reg->\AdwCleaner\Quarantine\C\Users\Notebook\Documents\PCSpeedRepair\registry.reg.vir
C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\awesomehp.xml->\AdwCleaner\Quarantine\C\Program Files (x86)\Mozilla Firefox\browser\searchplugins\awesomehp.xml.vir
C:\Users\Nora\daemonprocess.txt->\AdwCleaner\Quarantine\C\Users\Nora\daemonprocess.txt.vir
C:\Users\Notebook\daemonprocess.txt->\AdwCleaner\Quarantine\C\Users\Notebook\daemonprocess.txt.vir
C:\Users\Notebook\Desktop\Continue VuuPC Installation.lnk->\AdwCleaner\Quarantine\C\Users\Notebook\Desktop\Continue VuuPC Installation.lnk.vir

Glaube eben die Datei war falsch. Hatte schon vorher eine andere Version von AdwareCleaner.. Habe aber noch etwas gefunden, was gestern erstellt worden ist. Die Datei heißt C10:

Code:

# AdwCleaner v5.020 - Bericht erstellt am 14/11/2015 um 17:30:37
# Aktualisiert am 13/11/2015 von Xplode
# Datenbank : 2015-11-13.1 [Lokal]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Notebook - NOTEBOOK-PC
# Gestartet von : C:\Users\Nora\Desktop\AdwCleaner_5.020.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum

***** [ Dienste ] *****


***** [ Ordner ] *****

[-] Ordner Gelöscht : C:\Program Files (x86)\Fortunitas
[-] Ordner Gelöscht : C:\Program Files (x86)\Uninstaller
[-] Ordner Gelöscht : C:\Users\Notebook\AppData\Local\PCSpeedRepair
[-] Ordner Gelöscht : C:\Users\Notebook\Documents\PCSpeedRepair

***** [ Dateien ] *****

[-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\awesomehp.xml
[-] Datei Gelöscht : C:\Users\Nora\daemonprocess.txt
[-] Datei Gelöscht : C:\Users\Notebook\daemonprocess.txt
[-] Datei Gelöscht : C:\Users\Notebook\Desktop\Continue VuuPC Installation.lnk

***** [ DLLs ] *****


***** [ Verknüpfungen ] *****


***** [ Aufgabenplanung ] *****

[-] Aufgabenplanung Gelöscht : AmiUpdXp

***** [ Registrierungsdatenbank ] *****

[-] Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginService
[-] Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
[-] Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [HQ-Video-Profession-1.3-bg.exe]
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E7F49ED-8C94-4AAA-A407-3010D099B11A}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B8445FED-900C-4137-AD15-DDD2F6306B62}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BB27DF2F-6F05-4A42-9FFD-14696D795750}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C00F4B2B-A33C-40FC-8E47-4D18DCD4B01E}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9989BC14-9B5B-4B3B-8040-478FD1685E34}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{42CB7963-EFE0-4737-A927-CE076FAA3BA0}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4B8E39FD-ED07-4A41-9681-3D78DAFCEE66}
[-] Schlüssel Gelöscht : HKCU\Software\PCSpeedRepairLanguage
[-] Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Re_Markit
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\awesomehpSoftware
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Taronja
[-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ValueApps
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DMUninstaller
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video Downloader_is1
[-] Schlüssel Gelöscht : HKU\.DEFAULT\Software\PCSpeedRepairLanguage
[-] Schlüssel Gelöscht : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Schlüssel Gelöscht : HKU\.DEFAULT\Software\AppDataLow\Software\MediaPlayerEnhance
[-] Schlüssel Gelöscht : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\MediaPlayerEnhance
[-] Schlüssel Gelöscht : HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Schlüssel Gelöscht : HKU\S-1-5-20\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Schlüssel Gelöscht : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\InstalledBrowserExtensions
[-] Schlüssel Gelöscht : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Optimizer Pro
[-] Schlüssel Gelöscht : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\systweak
[-] Schlüssel Gelöscht : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Schlüssel Gelöscht : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\AppDataLow\Software\Crossrider
[-] Schlüssel Gelöscht : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\AppDataLow\Software\MediaPlayerEnhance
[-] Schlüssel Gelöscht : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\AppDataLow\Software\Re_Markit
[-] Schlüssel Gelöscht : HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\MediaPlayerEnhance

***** [ Internetbrowser ] *****


*************************

:: "Tracing" Schlüssel gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht

########## EOF - \AdwCleaner\AdwCleaner[C10].txt - [5625 Bytes] ##########

Ach nein. Ich sehe gerade die ist schon am 13.11.15 erstellt worden.. Verstehe jetzt gar nix mehr. Habe AdwareCleaner doch nur/erst gestern durchlaufen lassen:confused:

M-K-D-B 15.11.2015 13:42

Servus,


ok, danke für die Logdateien.


Wir entfernen die letzten Reste und kontrollieren nochmal alles.


Hinweis: Der Suchlauf mit ESET kann länger dauern.





Schritt 1
Bitte deaktiviere dein Anti-Viren-Programm, da es das Ergebnis beeinflussen oder ggf. die Bereinigung stören kann.
Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/ und speichere die Datei auf deinem Desktop.
  • Starte Zoek.exe mit einem Doppelklick. Es wird etwas dauern, bis sich das Programm öffnet.
  • Kopiere den Text der folgenden Box in das Skriptfenster von zoek:
    Code:

    iedefaults;
    resetIEproxy;
    shortcutfix;
    resethosts;
    resetWMI;
    FFdefaults;
    CHRdefaults;
    emptyclsid;

  • Nun klicke auf "Run script" und sei geduldig bis das Skript durchgelaufen ist. Dies kann einige Zeit in Anspruch nehmen.
  • Wenn das Tool fertig ist, wird sich eine Logdatei öffnen (ggf. erst nach einem Neustart).
  • Bitte poste mir die Logdatei von Zoek mit deiner nächsten Antwort.






Schritt 2
Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
  • Starte die HitmanPro.exe
  • Klicke auf
  • Entferne den Haken bei
  • Klicke auf
    und
  • Akzeptiere die Lizenzbedingungen und klicke auf
  • Klicke auf

    und auf
  • Wenn der Scan beendet wurde, nichts löschen lassen etc. sondern wähle unten links auf der Button-Leiste
    und speichere die Logdatei auf Deinem Desktop.
  • Schließe HitmanPro und poste mir das Log.

 







Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset








Bitte poste mit deiner nächsten Antwort
  • die Logdatei des Zoek,
  • die Logdatei von HitmanPro,
  • die Logdatei von ESET.

nora.s 15.11.2015 13:46

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Sorry, sorry, sorry!!!
War doch die richtige Datei. Sie wurde wohl nur vorgestern aktualisiert, aber gestern erstellt...:crazy:

M-K-D-B 15.11.2015 13:54

Zitat:

Zitat von nora.s (Beitrag 1535342)
Sorry, sorry, sorry!!!
War doch die richtige Datei. Sie wurde wohl nur vorgestern aktualisiert, aber gestern erstellt...:crazy:

Ich weiß, dass es die richtige Datei war. :)

Vielen Dank dafür!


Bitte sieh dir nochmal meinen letzten Post an und führe die nächsten Schritte aus.
Vielen Dank. :daumenhoc

nora.s 15.11.2015 18:23

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hallo!
Habe alle Programme durchlaufen lassen. Während zoek gelaufen ist, kam folgende Fehlermeldung:
Zitat:

Zeile 68; Zeichen 6; Fehler: Der Pfad wude nicht gefunden; Code: 0; URL: file:///C:/Users/Notebook/AppData/local/temp/zoekrun.hta
Nach HitmanPro ist der PC abgestürzt; lief aber nach erneutem Hochfahren wieder.

Bei HitmanPro bin ich mir auch wieder nicht sicher ob es die richtige Logdatei ist..
Hier die Dateien:

Code:

18:11:32 = Process Attach
18:11:32 = end process attach

18:11:32 = ***** NULL == SampleProvider *****

18:11:32 = hWnd = 0x0003032e; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=145, width=466, height=378
18:11:32 = hWnd = 0x000403a0; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:11:32 = hWnd = 0x000403aa; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:11:32 = hWnd = 0x000403ea; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=11b, y=84, width=800, height=560
18:11:32 = hWnd = 0x000403a4; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:11:32 = hWnd = 0x00050324; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:11:32 = hWnd = 0x00030328; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:11:32 = hWnd = 0x000203d2; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:11:32 = hWnd = 0x000602ca; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:32 = hWnd = 0x000a0396; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:11:32 = hWnd = 0x000403a8; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:32 = hWnd = 0x0003032a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:32 = Need to re-create objects.

18:11:32 = s1.

18:11:32 = s2.

18:11:32 = find user name
18:11:32 = Start show animate
18:11:33 = Shell Excutute VerifyHost
18:11:33 = find user name
18:11:33 = find user name
18:11:33 = find user name
18:11:33 = begin close Process
18:11:33 = Terminate Process
18:11:34 = end close Process
18:11:34 = DLL_PROCESS_DETACH

18:11:43 = Process Attach
18:11:43 = end process attach

18:11:43 = ##### Begin waiting Mutex to release process #####

18:11:43 = ***** NULL == SampleProvider *****

18:11:43 = hWnd = 0x0004032c; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:11:43 = hWnd = 0x0004032a; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:11:43 = hWnd = 0x00040364; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x0004036c; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000503e4; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000603a6; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
18:11:43 = hWnd = 0x000503a0; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
18:11:43 = hWnd = 0x000503aa; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:11:43 = hWnd = 0x000503a4; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:11:43 = hWnd = 0x000403dc; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:11:43 = hWnd = 0x000503a8; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000403ec; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000b0396; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000603ac; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:43 = Need to re-create objects.

18:11:43 = s1.

18:11:43 = s2.

18:11:43 = find user name
18:11:43 = Start show animate
18:11:45 = Shell Excutute VerifyHost
18:11:45 = find user name
18:11:46 = find user name
18:11:47 = begin close Process
18:11:47 = Terminate Process
18:11:48 = end close Process
18:11:48 = DLL_PROCESS_DETACH

18:11:51 = Process Attach
18:11:51 = end process attach

18:11:51 = ***** NULL == SampleProvider *****

18:11:51 = hWnd = 0x000503ee; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:11:51 = hWnd = 0x000d0396; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:11:51 = hWnd = 0x000603a8; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
18:11:51 = hWnd = 0x00050328; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
18:11:51 = hWnd = 0x000403fa; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000403da; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000503dc; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:11:51 = hWnd = 0x0005032c; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:11:51 = hWnd = 0x0007036c; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:11:51 = hWnd = 0x000703e0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000703ac; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000503ec; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000c0324; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:51 = Need to re-create objects.

18:11:51 = s1.

18:11:51 = s2.

18:11:51 = find user name
18:11:51 = Start show animate
18:11:52 = Shell Excutute VerifyHost
18:11:52 = find user name
18:11:53 = begin close Process
18:11:53 = Terminate Process
18:11:54 = end close Process
18:11:54 = DLL_PROCESS_DETACH

18:17:39 = Process Attach
18:17:39 = end process attach

18:17:39 = ##### Begin waiting Mutex to release process #####

18:17:39 = ***** NULL == SampleProvider *****

18:17:39 = hWnd = 0x00d103fa; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:17:39 = hWnd = 0x000902f6; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:17:39 = hWnd = 0x00060326; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x000a0388; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x000603b4; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x0004017e; ClassName: #32770; Title: Benutzerkontensteuerung.
x=4, y=271, width=466, height=378
18:17:39 = hWnd = 0x00060312; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=252, width=491, height=476
18:17:39 = hWnd = 0x00090322; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:17:39 = hWnd = 0x00040176; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:17:39 = hWnd = 0x000502e2; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:17:39 = hWnd = 0x000502d8; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x000602e8; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x000502e6; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x00090320; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:17:39 = Need to re-create objects.

18:17:39 = s1.

18:17:39 = s2.

18:17:39 = find user name
18:17:39 = Start show animate
18:17:40 = Shell Excutute VerifyHost
18:17:40 = find user name
18:17:42 = find user name
18:17:42 = begin close Process
18:17:42 = Terminate Process
18:17:43 = end close Process
18:17:43 = DLL_PROCESS_DETACH

18:18:45 = Process Attach
18:18:45 = end process attach

18:18:45 = ***** NULL == SampleProvider *****

18:18:45 = hWnd = 0x000702e2; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:18:45 = hWnd = 0x000d033c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:18:45 = hWnd = 0x00080312; ClassName: #32770; Title: Benutzerkontensteuerung.
x=23f, y=245, width=216, height=238
18:18:45 = hWnd = 0x000b02f6; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
18:18:45 = hWnd = 0x000b0320; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:18:45 = hWnd = 0x00100324; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:18:45 = hWnd = 0x0007026e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:18:45 = hWnd = 0x000b0322; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:18:45 = hWnd = 0x000702ea; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:45 = hWnd = 0x000b036c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:45 = hWnd = 0x00090326; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:45 = Need to re-create objects.

18:18:45 = s1.

18:18:45 = s2.

18:18:45 = find user name
18:18:45 = Start show animate
18:18:46 = Shell Excutute VerifyHost
18:18:46 = find user name
18:18:47 = find user name
18:18:47 = begin close Process
18:18:47 = Terminate Process
18:18:48 = end close Process
18:18:48 = DLL_PROCESS_DETACH

18:18:51 = Process Attach
18:18:51 = end process attach

18:18:51 = ***** NULL == SampleProvider *****

18:18:51 = hWnd = 0x000f0388; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:18:51 = hWnd = 0x000d036c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:18:51 = hWnd = 0x000c02f6; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
18:18:51 = hWnd = 0x000902e6; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
18:18:51 = hWnd = 0x0008026e; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:18:51 = hWnd = 0x000802e2; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:18:51 = hWnd = 0x000802d6; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:18:51 = hWnd = 0x000802f0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:18:51 = hWnd = 0x000c0320; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:51 = hWnd = 0x00100380; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:18:51 = hWnd = 0x000a0326; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:51 = hWnd = 0x00100344; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:51 = Need to re-create objects.

18:18:51 = s1.

18:18:51 = s2.

18:18:51 = find user name
18:18:51 = Start show animate
18:18:53 = Shell Excutute VerifyHost
18:18:53 = begin close Process
18:18:53 = Terminate Process
18:18:54 = end close Process
18:18:54 = DLL_PROCESS_DETACH

18:22:14 = Process Attach
18:22:14 = end process attach

18:22:14 = ##### Begin waiting Mutex to release process #####

18:22:14 = ***** NULL == SampleProvider *****

18:22:14 = hWnd = 0x0015035c; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:22:14 = hWnd = 0x001c036c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:22:14 = hWnd = 0x000401f4; ClassName: #32770; Title: Benutzerkontensteuerung.
x=23b, y=195, width=466, height=399
18:22:14 = hWnd = 0x000a03bc; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=1a2, y=180, width=788, height=489
18:22:14 = hWnd = 0x00070352; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x00040254; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x000b0336; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:22:14 = hWnd = 0x000a0338; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:22:14 = hWnd = 0x001d02e2; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:22:14 = hWnd = 0x00040160; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x00100350; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x000401ae; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x000f0176; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:22:14 = Need to re-create objects.

18:22:14 = s1.

18:22:14 = s2.

18:22:14 = find user name
18:22:14 = Start show animate
18:22:16 = Shell Excutute VerifyHost
18:22:16 = find user name
18:22:16 = begin close Process
18:22:16 = Terminate Process
18:22:17 = end close Process
18:22:17 = DLL_PROCESS_DETACH

18:38:19 = Process Attach
18:38:19 = end process attach

18:38:19 = ***** NULL == SampleProvider *****

18:38:19 = ##### Begin waiting Mutex to release process #####

18:38:19 = hWnd = 0x00150354; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
18:38:19 = hWnd = 0x000f03f8; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:38:19 = hWnd = 0x0006025e; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:38:19 = hWnd = 0x00100394; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:38:21 = Process Attach
18:38:21 = ## ERR ## Setevent

18:38:21 = ***** NULL == SampleProvider *****

18:38:21 = begin close Process
18:38:21 = end close Process
18:38:21 = ##### Get event and release process end #####

18:38:21 = hWnd = 0x0062009e; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1024, height=768
18:38:21 = hWnd = 0x00160084; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:38:21 = hWnd = 0x00030044; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:38:21 = hWnd = 0x001b007c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:39:14 = Process Attach
18:39:14 = end process attach

18:39:14 = ***** NULL == SampleProvider *****

18:39:14 = ##### Begin waiting Mutex to release process #####

18:39:14 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
18:39:14 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:39:14 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:39:14 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:39:23 = Need to re-create objects.

18:39:23 = s1.

18:39:23 = s2.

18:39:23 = find user name
18:39:23 = Start show animate
18:39:25 = Shell Excutute VerifyHost
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:30 = find user name
18:39:30 = find user name
18:39:30 = find user name
18:39:41 = begin close Process
18:39:41 = Terminate Process
18:39:42 = end close Process
18:39:42 = DLL_PROCESS_DETACH

18:40:44 = Process Attach
18:40:44 = end process attach

18:40:44 = ##### Begin waiting Mutex to release process #####

18:40:44 = ***** NULL == SampleProvider *****

18:40:44 = hWnd = 0x000302d6; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:40:44 = hWnd = 0x000202da; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:40:44 = hWnd = 0x000103a2; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=145, width=466, height=378
18:40:44 = hWnd = 0x0002039a; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=11b, y=84, width=800, height=560
18:40:44 = hWnd = 0x000103c2; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x000103c6; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x00040394; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:40:44 = hWnd = 0x0001039e; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:40:44 = hWnd = 0x000602d2; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:40:44 = hWnd = 0x0001039c; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x00020398; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x000103a0; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x000502ce; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:40:44 = Need to re-create objects.

18:40:44 = s1.

18:40:44 = s2.

18:40:44 = find user name
18:40:44 = Start show animate
18:40:45 = Shell Excutute VerifyHost
18:40:45 = find user name
18:40:46 = begin close Process
18:40:46 = Terminate Process
18:40:47 = end close Process
18:40:47 = DLL_PROCESS_DETACH

18:59:2 = Process Attach
18:59:2 = end process attach

18:59:2 = ***** NULL == SampleProvider *****

18:59:2 = hWnd = 0x000403ba; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
18:59:2 = hWnd = 0x000a039c; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:59:2 = hWnd = 0x000403b0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:59:2 = hWnd = 0x000403bc; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:59:6 = Process Attach
18:59:6 = ## ERR ## Setevent

18:59:6 = ##### Get event and release process #####

18:59:6 = begin close Process
18:59:6 = end close Process
18:59:6 = ##### Get event and release process end #####

18:59:49 = Process Attach
18:59:49 = end process attach

18:59:49 = ***** NULL == SampleProvider *****

18:59:49 = ##### Begin waiting Mutex to release process #####

18:59:49 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
18:59:49 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:59:49 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:59:49 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:59:56 = Need to re-create objects.

18:59:56 = s1.

18:59:56 = s2.

18:59:56 = find user name
18:59:56 = Start show animate
18:59:58 = Shell Excutute VerifyHost
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:59 = find user name
18:59:59 = find user name
18:59:59 = find user name
18:59:59 = find user name
18:59:59 = find user name
19:0:1 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:3 = find user name
19:0:3 = find user name
19:0:3 = find user name
21:37:14 = Process Attach
21:37:14 = end process attach

21:37:14 = ##### Begin waiting Mutex to release process #####

21:37:14 = hWnd = 0x0008034c; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
21:37:14 = hWnd = 0x000602c6; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
21:37:14 = hWnd = 0x00020352; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:14 = hWnd = 0x0002032e; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:14 = hWnd = 0x0005036a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:14 = Need to re-create objects.

21:37:14 = s1.

21:37:14 = s2.

21:37:14 = find user name
21:37:14 = Start show animate
21:37:16 = Shell Excutute VerifyHost
21:37:16 = begin close Process
21:37:16 = Terminate Process
21:37:17 = end close Process
21:37:17 = DLL_PROCESS_DETACH

21:37:28 = Process Attach
21:37:28 = end process attach

21:37:28 = ##### Begin waiting Mutex to release process #####

21:37:28 = ***** NULL == SampleProvider *****

21:37:28 = hWnd = 0x0006036a; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
21:37:28 = hWnd = 0x0009034c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
21:37:28 = hWnd = 0x0003038e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x00030378; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x00030374; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x000702c6; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
21:37:28 = hWnd = 0x0009035c; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
21:37:28 = hWnd = 0x00080392; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
21:37:28 = hWnd = 0x0003033c; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
21:37:28 = hWnd = 0x0005032e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
21:37:28 = hWnd = 0x00030346; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x000b03fe; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x00030352; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x0007039c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:28 = Need to re-create objects.

21:37:28 = s1.

21:37:28 = s2.

21:37:28 = find user name
21:37:28 = Start show animate
21:37:29 = Shell Excutute VerifyHost
21:37:29 = find user name
21:37:34 = begin close Process
21:37:34 = Terminate Process
21:37:35 = end close Process
21:37:35 = DLL_PROCESS_DETACH

21:43:3 = Process Attach
21:43:3 = end process attach

21:43:3 = ***** NULL == SampleProvider *****

21:43:3 = hWnd = 0x00110378; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
21:43:3 = hWnd = 0x000603ae; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
21:43:3 = hWnd = 0x000403da; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:43:3 = ##### Begin waiting Mutex to release process #####

21:43:3 = hWnd = 0x000603e0; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x000502c8; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x00060154; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
21:43:3 = hWnd = 0x00080394; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
21:43:3 = hWnd = 0x000a0354; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
21:43:3 = hWnd = 0x0008036a; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
21:43:3 = hWnd = 0x000502d2; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
21:43:3 = hWnd = 0x000a0352; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x000c032c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x000a0392; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x00070320; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:43:3 = Need to re-create objects.

21:43:3 = s1.

21:43:3 = s2.

21:43:3 = find user name
21:43:3 = Start show animate
21:43:4 = Shell Excutute VerifyHost
21:43:4 = find user name
21:43:5 = begin close Process
21:43:5 = Terminate Process
21:43:6 = end close Process
21:43:6 = DLL_PROCESS_DETACH

0:11:53 = Process Attach
0:11:53 = end process attach

0:11:53 = ##### Begin waiting Mutex to release process #####

0:11:53 = hWnd = 0x00110352; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
0:11:53 = hWnd = 0x000c02fe; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
0:11:53 = hWnd = 0x000902f8; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
0:11:53 = hWnd = 0x000e033c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
0:11:56 = Process Attach
0:11:56 = ## ERR ## Setevent

0:11:56 = ##### Get event and release process #####

0:11:56 = begin close Process
0:11:56 = end close Process
0:11:56 = ##### Get event and release process end #####

0:11:56 = ***** NULL == SampleProvider *****

0:11:56 = hWnd = 0x00cf0072; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1024, height=768
0:11:56 = hWnd = 0x00cf005a; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
0:11:56 = hWnd = 0x00030078; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
0:11:56 = hWnd = 0x00980038; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
9:11:39 = Process Attach
9:11:39 = end process attach

9:11:39 = ***** NULL == SampleProvider *****

9:11:39 = ##### Begin waiting Mutex to release process #####

9:11:39 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
9:11:39 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
9:11:39 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
9:11:39 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
9:11:39 = Need to re-create objects.

9:11:39 = s1.

9:11:39 = s2.

9:11:39 = find user name
9:11:39 = Start show animate
9:11:41 = Shell Excutute VerifyHost
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:11 = find user name
9:15:11 = find user name
9:15:11 = find user name
9:15:18 = begin close Process
9:15:18 = Terminate Process
9:15:19 = end close Process
9:15:19 = DLL_PROCESS_DETACH

12:31:1 = Process Attach
12:31:1 = end process attach

12:31:1 = ##### Begin waiting Mutex to release process #####

12:31:1 = hWnd = 0x0002041a; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
12:31:1 = hWnd = 0x00040440; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
12:31:1 = hWnd = 0x000203c0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
12:31:1 = hWnd = 0x000803b0; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
12:31:1 = Need to re-create objects.

12:31:1 = s1.

12:31:1 = s2.

12:31:1 = find user name
12:31:1 = Start show animate
12:31:3 = Is Black Sceen wait
12:31:3 = black wait1
12:31:4 = Is Black Sceen wait
12:31:4 = black wait2
12:31:6 = Is Black Sceen wait
12:31:6 = black wait3
12:37:11 = Shell Excutute VerifyHost
12:37:14 = find user name
12:37:14 = find user name
12:37:14 = find user name
12:37:16 = find user name
12:37:16 = find user name
12:37:16 = find user name
12:37:16 = find user name
12:37:16 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:35 = begin close Process
12:37:35 = Terminate Process
12:37:36 = end close Process
12:37:36 = DLL_PROCESS_DETACH

13:26:50 = Process Attach
13:26:50 = end process attach

13:26:50 = ***** NULL == SampleProvider *****

13:26:50 = hWnd = 0x000b0434; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
13:26:50 = hWnd = 0x000a0472; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
13:26:50 = hWnd = 0x000b03f6; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x00070490; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x000f0432; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x001003ec; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=154, width=466, height=399
13:26:50 = hWnd = 0x0004046c; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
13:26:50 = hWnd = 0x001003fa; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
13:26:50 = hWnd = 0x000a045a; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
13:26:50 = hWnd = 0x000b033a; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
13:26:50 = hWnd = 0x002203d0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x00100428; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x000f03bc; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x00100476; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:50 = Need to re-create objects.

13:26:50 = s1.

13:26:50 = s2.

13:26:50 = find user name
13:26:50 = Start show animate
13:26:52 = Shell Excutute VerifyHost
13:26:52 = begin close Process
13:26:52 = end close Process
13:26:52 = DLL_PROCESS_DETACH

13:26:55 = Process Attach
13:26:55 = end process attach

13:26:55 = ***** NULL == SampleProvider *****

13:26:55 = hWnd = 0x000503a6; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
13:26:55 = ##### Begin waiting Mutex to release process #####

13:26:55 = hWnd = 0x000b0454; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
13:26:55 = hWnd = 0x00110428; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=154, width=466, height=399
13:26:55 = hWnd = 0x001103d8; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
13:26:55 = hWnd = 0x00110412; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x000e044e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x000c033a; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
13:26:55 = hWnd = 0x000c0434; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
13:26:55 = hWnd = 0x001203bc; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
13:26:55 = hWnd = 0x000d03e4; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x00110476; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x0005046c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x00080398; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:55 = Need to re-create objects.

13:26:55 = s1.

13:26:55 = s2.

13:26:55 = find user name
13:26:55 = Start show animate
13:26:57 = Shell Excutute VerifyHost
13:26:57 = find user name
13:26:58 = begin close Process
13:26:58 = Terminate Process
13:26:59 = end close Process
13:26:59 = DLL_PROCESS_DETACH

14:11:3 = Process Attach
14:11:3 = end process attach

14:11:3 = ##### Begin waiting Mutex to release process #####

14:11:3 = ***** NULL == SampleProvider *****

14:11:3 = hWnd = 0x000703b2; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:11:3 = hWnd = 0x0005031e; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:11:3 = hWnd = 0x000403a8; ClassName: #32770; Title: Benutzerkontensteuerung.
x=c5, y=42, width=466, height=399
14:11:3 = hWnd = 0x000303ac; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=64, y=100, width=677, height=342
14:11:3 = hWnd = 0x001803a0; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x002d03ce; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x00030324; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:11:3 = hWnd = 0x00030310; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:11:3 = hWnd = 0x0003032e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:11:3 = hWnd = 0x0006032c; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x00030326; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x0004035a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x0003031c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:3 = Need to re-create objects.

14:11:3 = s1.

14:11:3 = s2.

14:11:3 = find user name
14:11:3 = Start show animate
14:11:4 = Shell Excutute VerifyHost
14:11:4 = find user name
14:11:4 = find user name
14:11:5 = begin close Process
14:11:5 = end close Process
14:11:5 = DLL_PROCESS_DETACH

14:11:5 = Process Attach
14:11:5 = end process attach

14:11:5 = ##### Begin waiting Mutex to release process #####

14:11:5 = ***** NULL == SampleProvider *****

14:11:5 = hWnd = 0x0006031e; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:11:5 = hWnd = 0x001a03ea; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:11:5 = hWnd = 0x0016046c; ClassName: #32770; Title: Benutzerkontensteuerung.
x=c5, y=42, width=466, height=399
14:11:5 = hWnd = 0x000403ac; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=64, y=100, width=677, height=342
14:11:5 = hWnd = 0x00040320; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x00030322; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x001c03a0; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:11:5 = hWnd = 0x00040324; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:11:5 = hWnd = 0x00060334; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:11:5 = hWnd = 0x0007032c; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x000803b2; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x00140476; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x0004032e; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:5 = Need to re-create objects.

14:11:5 = s1.

14:11:5 = s2.

14:11:5 = find user name
14:11:5 = Start show animate
14:11:6 = Shell Excutute VerifyHost
14:11:6 = find user name
14:11:7 = find user name
14:11:7 = begin close Process
14:11:7 = Terminate Process
14:11:8 = end close Process
14:11:8 = DLL_PROCESS_DETACH

14:11:8 = Process Attach
14:11:8 = end process attach

14:11:8 = ##### Begin waiting Mutex to release process #####

14:11:8 = ***** NULL == SampleProvider *****

14:11:8 = hWnd = 0x00070334; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:11:8 = hWnd = 0x002303bc; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:11:8 = hWnd = 0x00050326; ClassName: #32770; Title: Benutzerkontensteuerung.
x=c5, y=42, width=466, height=399
14:11:8 = hWnd = 0x001b03ea; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=64, y=100, width=677, height=342
14:11:8 = hWnd = 0x0005018e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x000703aa; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x0005032e; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:11:8 = hWnd = 0x001d03a0; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:11:8 = hWnd = 0x00160476; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:11:8 = hWnd = 0x0007031e; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x0005031c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x0008032c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x00070318; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:8 = Need to re-create objects.

14:11:8 = s1.

14:11:8 = s2.

14:11:8 = find user name
14:11:8 = Start show animate
14:11:10 = Shell Excutute VerifyHost
14:11:10 = find user name
14:11:11 = find user name
14:11:11 = begin close Process
14:11:11 = Terminate Process
14:11:12 = end close Process
14:11:12 = DLL_PROCESS_DETACH

14:11:19 = Process Attach
14:11:19 = end process attach

14:11:19 = ##### Begin waiting Mutex to release process #####

14:11:19 = ***** NULL == SampleProvider *****

14:11:19 = hWnd = 0x00060310; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:11:19 = hWnd = 0x0007035a; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:11:19 = hWnd = 0x00110396; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x00190480; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x00080318; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=154, width=466, height=399
14:11:19 = hWnd = 0x002403e0; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
14:11:19 = hWnd = 0x003203ce; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:11:19 = hWnd = 0x00080324; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:11:19 = hWnd = 0x000e047a; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:11:19 = hWnd = 0x00180476; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x002003a0; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x000a03aa; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x0007033c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:19 = Need to re-create objects.

14:11:19 = s1.

14:11:19 = s2.

14:11:19 = find user name
14:11:19 = Start show animate
14:11:20 = Shell Excutute VerifyHost
14:11:20 = find user name
14:11:21 = begin close Process
14:11:21 = Terminate Process
14:11:22 = end close Process
14:11:22 = DLL_PROCESS_DETACH

14:15:45 = Process Attach
14:15:45 = end process attach

14:15:45 = ***** NULL == SampleProvider *****

14:15:45 = hWnd = 0x001b03ca; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
14:15:45 = hWnd = 0x001c0480; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:15:45 = hWnd = 0x00090340; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:15:45 = hWnd = 0x000b0324; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:15:49 = Process Attach
14:15:49 = ## ERR ## Setevent

14:15:49 = ##### Get event and release process #####

14:15:49 = begin close Process
14:15:49 = end close Process
14:15:49 = ##### Get event and release process end #####

14:15:49 = ***** NULL == SampleProvider *****

14:15:49 = hWnd = 0x0002010e; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1024, height=768
14:15:49 = hWnd = 0x0002012a; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:15:49 = hWnd = 0x000200b0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:15:49 = hWnd = 0x00020128; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:17:17 = Process Attach
14:17:17 = end process attach

14:17:17 = ***** NULL == SampleProvider *****

14:17:17 = ##### Begin waiting Mutex to release process #####

14:17:17 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
14:17:17 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:17:17 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:17:17 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:17:20 = Need to re-create objects.

14:17:20 = s1.

14:17:20 = s2.

14:17:20 = find user name
14:17:20 = Start show animate
14:17:21 = Shell Excutute VerifyHost
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:18:10 = begin close Process
14:18:10 = Terminate Process
14:18:11 = end close Process
14:18:11 = DLL_PROCESS_DETACH

14:20:6 = Process Attach
14:20:6 = end process attach

14:20:6 = ##### Begin waiting Mutex to release process #####

14:20:6 = ***** NULL == SampleProvider *****

14:20:6 = hWnd = 0x00050324; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:20:6 = hWnd = 0x00050322; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:20:6 = hWnd = 0x00010342; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x00010346; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x0001034a; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x0006031e; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
14:20:6 = hWnd = 0x00050330; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
14:20:6 = hWnd = 0x0005031a; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:20:6 = hWnd = 0x000302d8; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:20:6 = hWnd = 0x0005032e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:20:6 = hWnd = 0x000302d6; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x00050316; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x0006032c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x0005031c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:6 = Need to re-create objects.

14:20:6 = s1.

14:20:6 = s2.

14:20:6 = find user name
14:20:6 = Start show animate
14:20:7 = Shell Excutute VerifyHost
14:20:7 = find user name
14:20:8 = find user name
14:20:8 = begin close Process
14:20:8 = Terminate Process
14:20:9 = end close Process
14:20:9 = DLL_PROCESS_DETACH

14:20:13 = Process Attach
14:20:13 = end process attach

14:20:13 = ##### Begin waiting Mutex to release process #####

14:20:13 = ***** NULL == SampleProvider *****

14:20:13 = hWnd = 0x00060314; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:20:13 = hWnd = 0x0008032c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:20:13 = hWnd = 0x0002033e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x0002033a; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x0004030e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x00030348; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
14:20:13 = hWnd = 0x00060320; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
14:20:13 = hWnd = 0x0006032e; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:20:13 = hWnd = 0x00030356; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:20:13 = hWnd = 0x00040346; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:20:13 = hWnd = 0x0008031e; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x0006031c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x00060322; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x000d002a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:13 = Need to re-create objects.

14:20:13 = s1.

14:20:13 = s2.

14:20:13 = find user name
14:20:13 = Start show animate
14:20:15 = Shell Excutute VerifyHost
14:20:15 = find user name
14:20:16 = begin close Process
14:20:16 = Terminate Process
14:20:17 = end close Process
14:20:17 = DLL_PROCESS_DETACH

14:39:11 = Process Attach
14:39:11 = end process attach

14:39:11 = ***** NULL == SampleProvider *****

14:39:11 = ##### Begin waiting Mutex to release process #####

14:39:11 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
14:39:11 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:39:11 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:39:11 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:39:35 = Need to re-create objects.

14:39:35 = s1.

14:39:35 = s2.

14:39:37 = find user name
14:39:37 = Start show animate
14:39:38 = Shell Excutute VerifyHost
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:39 = find user name
14:39:39 = find user name
14:39:39 = find user name
14:39:39 = find user name
14:39:39 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:55 = begin close Process
14:39:55 = Terminate Process
14:39:56 = end close Process
14:39:56 = DLL_PROCESS_DETACH

14:41:18 = Process Attach
14:41:18 = end process attach

14:41:18 = ***** NULL == SampleProvider *****

14:41:18 = hWnd = 0x000202d2; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:41:18 = hWnd = 0x000302d0; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:41:18 = hWnd = 0x00020322; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x00020326; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x0002031e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x00030316; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=127, width=466, height=378
14:41:18 = hWnd = 0x000202d8; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=19a, y=164, width=546, height=363
14:41:18 = hWnd = 0x000202d4; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:41:18 = hWnd = 0x000202de; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:41:18 = hWnd = 0x0003013e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:41:18 = hWnd = 0x000202dc; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x000202d6; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x00030300; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x00060372; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:18 = Need to re-create objects.

14:41:18 = s1.

14:41:18 = s2.

14:41:19 = find user name
14:41:19 = Start show animate
14:41:20 = Shell Excutute VerifyHost
14:41:20 = find user name
14:41:22 = find user name
14:41:22 = begin close Process
14:41:22 = Terminate Process
14:41:23 = end close Process
14:41:23 = DLL_PROCESS_DETACH

14:41:30 = Process Attach
14:41:30 = end process attach

14:41:30 = ***** NULL == SampleProvider *****

14:41:30 = ##### Begin waiting Mutex to release process #####

14:41:30 = hWnd = 0x000402c8; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:41:30 = hWnd = 0x000302ec; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:41:30 = hWnd = 0x0004013e; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
14:41:30 = hWnd = 0x000402de; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
14:41:30 = hWnd = 0x00030344; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x0004031a; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x0003033c; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x000302cc; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:41:30 = hWnd = 0x00040326; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:41:30 = hWnd = 0x000700e0; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:41:30 = hWnd = 0x00050324; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x000302ca; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x000302b2; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x000602ee; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:30 = Need to re-create objects.

14:41:30 = s1.

14:41:30 = s2.

14:41:30 = find user name
14:41:30 = Start show animate
14:41:32 = Shell Excutute VerifyHost
14:41:32 = find user name
14:41:33 = begin close Process
14:41:33 = Terminate Process
14:41:34 = end close Process
14:41:34 = DLL_PROCESS_DETACH

15:45:40 = Process Attach
15:45:40 = end process attach

15:45:40 = ***** NULL == SampleProvider *****

15:45:40 = ##### Begin waiting Mutex to release process #####

15:45:40 = hWnd = 0x00030498; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
15:45:40 = hWnd = 0x00050450; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
15:45:40 = hWnd = 0x0002042c; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
15:45:40 = hWnd = 0x000b027c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
15:45:40 = Need to re-create objects.

15:45:40 = s1.

15:45:40 = s2.

15:45:41 = find user name
15:45:41 = Start show animate
15:45:42 = Is Black Sceen wait
15:45:42 = black wait1
15:45:44 = Is Black Sceen wait
15:45:44 = black wait2
15:45:45 = Is Black Sceen wait
15:45:45 = black wait3
15:45:47 = Shell Excutute VerifyHost
15:45:47 = find user name
15:45:47 = find user name
15:45:47 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
17:25:38 = Bypass the object creation.

17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:43 = begin close Process
17:25:43 = Terminate Process
17:25:44 = end close Process
17:25:44 = DLL_PROCESS_DETACH

17:29:51 = Process Attach
17:29:51 = end process attach

17:29:51 = ##### Begin waiting Mutex to release process #####

17:29:51 = ***** NULL == SampleProvider *****

17:29:51 = hWnd = 0x0003053c; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
17:29:51 = hWnd = 0x00030528; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
17:29:51 = hWnd = 0x000304e2; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x00030522; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x0002054e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x0003054a; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=145, width=466, height=378
17:29:51 = hWnd = 0x0003053a; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=11b, y=84, width=800, height=560
17:29:51 = hWnd = 0x00040520; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
17:29:51 = hWnd = 0x00030546; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
17:29:51 = hWnd = 0x00060496; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
17:29:51 = hWnd = 0x00030542; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x00030538; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x0003053e; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x0003052a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
17:29:51 = Need to re-create objects.

17:29:51 = s1.

17:29:51 = s2.

17:29:51 = find user name
17:29:51 = Start show animate
17:29:53 = Shell Excutute VerifyHost
17:29:53 = find user name
17:29:54 = begin close Process
17:29:54 = Terminate Process
17:29:55 = end close Process
17:29:55 = DLL_PROCESS_DETACH

18:3:25 = Process Attach
18:3:25 = end process attach

18:3:25 = ***** NULL == SampleProvider *****

18:3:25 = hWnd = 0x001302d4; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:3:25 = hWnd = 0x000602dc; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:3:25 = hWnd = 0x0008030e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:3:25 = hWnd = 0x00050320; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1c6, y=158, width=466, height=378
18:3:25 = hWnd = 0x000a03b2; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=1e7, y=276, width=416, height=201
18:3:25 = hWnd = 0x000902d6; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:3:25 = hWnd = 0x00060342; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:3:25 = hWnd = 0x0006033e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:3:25 = hWnd = 0x00060390; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:3:25 = hWnd = 0x000a02d2; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:25 = hWnd = 0x000b02c0; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:25 = hWnd = 0x00070322; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:25 = Need to re-create objects.

18:3:25 = s1.

18:3:25 = s2.

18:3:25 = find user name
18:3:25 = Start show animate
18:3:26 = Shell Excutute VerifyHost
18:3:30 = begin close Process
18:3:30 = Terminate Process
18:3:31 = end close Process
18:3:31 = DLL_PROCESS_DETACH

18:3:58 = Process Attach
18:3:58 = end process attach

18:3:58 = ##### Begin waiting Mutex to release process #####

18:3:58 = hWnd = 0x00070538; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:3:58 = hWnd = 0x000802dc; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:3:58 = hWnd = 0x00090316; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:3:58 = hWnd = 0x000902c6; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:58 = hWnd = 0x001502d4; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:58 = hWnd = 0x000802da; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:58 = Need to re-create objects.

18:3:58 = s1.

18:3:58 = s2.

18:3:58 = find user name
18:3:58 = Start show animate
18:4:0 = Shell Excutute VerifyHost
18:4:0 = find user name
18:4:0 = find user name
18:4:0 = find user name
18:4:0 = find user name
18:4:0 = begin close Process
18:4:0 = Terminate Process
18:4:1 = end close Process
18:4:1 = DLL_PROCESS_DETACH


nora.s 15.11.2015 18:26

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=b75d2d59c3df484a8ddc2bb9b66f8c76
# end=init
# utc_time=2015-11-15 01:41:51
# local_time=2015-11-15 02:41:51 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 26734
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=b75d2d59c3df484a8ddc2bb9b66f8c76
# end=updated
# utc_time=2015-11-15 01:44:45
# local_time=2015-11-15 02:44:45 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=b75d2d59c3df484a8ddc2bb9b66f8c76
# engine=26734
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-11-15 05:00:05
# local_time=2015-11-15 06:00:05 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 16138546 118900427 0 0
# scanned=216325
# found=194
# cleaned=0
# scan_time=11719
sh=E262DCB663133609DD976740F886911FD404FEE1 ft=1 fh=a04ae9518bd8f7b0 vn="Win64/Toolbar.Conduit.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Conduit\ValueApps\IE\ValueAppsLoader.dll.vir"
sh=E7E22E069654E96CE83A7BA14826DB9E48FE4CEC ft=1 fh=3873ea48b069cf5e vn="Win32/Toolbar.Conduit.AK evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll.vir"
sh=CCED9635A96A9FF586CDA03341A195E3563F1816 ft=1 fh=5fee560ec51f2e7b vn="Variante von Win32/Toolbar.CrossRider.BP evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\HQ-Video-Profession-1.3\Uninstall.exe.vir"
sh=84D88BC618D3ED9F3071C1285CFEB81756A7DF11 ft=1 fh=72d006dbb95d55bd vn="Variante von Win32/Toolbar.CrossRider.BP evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerEnhance\Uninstall.exe.vir"
sh=B992ED7A1B4DF30F6AF8A911FBFDE92ED9F77519 ft=1 fh=5dac4dde3cd39976 vn="Variante von MSIL/DomaIQ.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Uninstaller\Uninstall.exe.vir"
sh=87CE4C851AB95A41CE5CAB57300AA5E2913272C7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\xhr.js.vir"
sh=F9709950DC71343BD5C33FA36E7E22E527609C93 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\102_dealply_m.js.vir"
sh=01D69135EE92DAC22B8061E1BDD909E2C88CEA69 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\103_intext_5_m.js.vir"
sh=3C02C1198777BE5BA10D93C67F6CD34557EC171B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\104_jollywallet_m.js.vir"
sh=F4868E75E21D37FCBC9A5871B6B120EB3E4600DF ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\14_CrossriderUtils.js.vir"
sh=A23A6416D40CB6EBCEEC06D43DD6DDC09BD8E066 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\155_ibario_pops_m.js.vir"
sh=1F6B9CD423C9C689D5D398B846CCDACFB33B568E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\184_noproblemppc_m.js.vir"
sh=D88BC1DC06D849820DF1C3783159BE2E5424E5F7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\190_pops_5_m.js.vir"
sh=AF4A89350A672268D320B32859AFCD17170BB977 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\191_ciuvo_m.js.vir"
sh=C1EB6A69219A2338DF815E20D227C1BBA07AC67D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\195_icm_convertmedia_m.js.vir"
sh=080E5E5C347490C5936B8ABEF9FA7CEB5AD28E22 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\211_revizer_ws_dynamic_b2b_light_m.js.vir"
sh=3D8FEB274B1F910633E0EE3966A82AE9DCBD406A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\21_debug.js.vir"
sh=49045AFF4B791A0C85C789ECFA9C91904A1297E4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\220_icm_base_m.js.vir"
sh=40FDDFD7B9412D5BDAC1D0E2440E655C7A8FC33E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\226_set_campaign_id_m.js.vir"
sh=0E3E976A397422B55CAC2E8F3F1AFEFB5044F4CB ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js.vir"
sh=D93B8416BAAD22FE24D8CD082468986BECDBCC03 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\242_price_gong_m.js.vir"
sh=FD07E13CB435AA4328D85C2C272EC291679C0940 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\246_setup.js.vir"
sh=A61F2AB2BDA3DF4EA26FB96BFA4BAA4BEFA99E6A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\28_initializer.js.vir"
sh=D0C91B4ACE84473BFACA534FF1542F34C843F213 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\47_resources_background.js.vir"
sh=BDCFA8379825B1BC17A13BDF73B7384DE46E7C3B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\64_appApiMessage.js.vir"
sh=A944448CDA1CE5AA918107104D3B42C171DC810C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\91_monetizationLoader.js.js.vir"
sh=3D1C513C1AF6190E264097710C145E9D6A3A4060 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\93_superfish_no_coupons_m.js.vir"
sh=954331290B6C48813BEDEFECAC563EFF7C806002 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\xhr.js.vir"
sh=F9709950DC71343BD5C33FA36E7E22E527609C93 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\102_dealply_m.js.vir"
sh=01D69135EE92DAC22B8061E1BDD909E2C88CEA69 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\103_intext_5_m.js.vir"
sh=3C02C1198777BE5BA10D93C67F6CD34557EC171B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\104_jollywallet_m.js.vir"
sh=2C5C97A4EDD53CE4333EEF27A9DB5FA4400143C6 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\119_similar_web_m.js.vir"
sh=22BD87991B5507F18DF5B51B9650946541B67C6E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\123_intext_adv_m.js.vir"
sh=F4868E75E21D37FCBC9A5871B6B120EB3E4600DF ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\14_CrossriderUtils.js.vir"
sh=0DF5B53F31A1EBEBBBC42168DCB3C2190F1B7D62 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\178_revizer_ws_dynamic_m.js.vir"
sh=A57430022E6623D30ACFDFB82F013060C324FCD4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\179_revizer_p_dynamic_m.js.vir"
sh=F8FCF109D3E526F0B98BDB2BD01174AF9A902A8C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\180_bpo_serp_m.js.vir"
sh=2871C7281499607657F7CD4EE3D2F99F9DEC9A4C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\184_noproblemppc_m.js.vir"
sh=D88BC1DC06D849820DF1C3783159BE2E5424E5F7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\190_pops_5_m.js.vir"
sh=AF4A89350A672268D320B32859AFCD17170BB977 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\191_ciuvo_m.js.vir"
sh=C1EB6A69219A2338DF815E20D227C1BBA07AC67D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\195_icm_convertmedia_m.js.vir"
sh=3D8FEB274B1F910633E0EE3966A82AE9DCBD406A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\21_debug.js.vir"
sh=49045AFF4B791A0C85C789ECFA9C91904A1297E4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\220_icm_base_m.js.vir"
sh=82CF3E1378FCB28417B1652D9F27AAD6DB128AF3 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\221_icm_downloads_m.js.vir"
sh=B6DC2CB64CD0031FC35CFE317013F77A5FDCCA90 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\223_imonomy_m.js.vir"
sh=CDD822AC5D369DB85D02E74F74D964BD7243C5F7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\226_set_campaign_id_m.js.vir"
sh=4649E23E28ABB2E1A073CB68F9F4E6DE40F4D5F4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\232_revizer_p_dynamic_2_m.js.vir"
sh=B8DCC1355AF30C027794D10BC8FD83670866BA2A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\242_price_gong_m.js.vir"
sh=096360E528F6964EAA30051DDE841A0C8E63849B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\246_setup.js.vir"
sh=A61F2AB2BDA3DF4EA26FB96BFA4BAA4BEFA99E6A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\28_initializer.js.vir"
sh=D0C91B4ACE84473BFACA534FF1542F34C843F213 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\47_resources_background.js.vir"
sh=BDCFA8379825B1BC17A13BDF73B7384DE46E7C3B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\64_appApiMessage.js.vir"
sh=A944448CDA1CE5AA918107104D3B42C171DC810C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\91_monetizationLoader.js.js.vir"
sh=3D1C513C1AF6190E264097710C145E9D6A3A4060 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\93_superfish_no_coupons_m.js.vir"
sh=7E476CBC20B540F11239EC2A5C617FF221BF52CC ft=1 fh=80c7b6f3be1d69d2 vn="Variante von Win32/Toolbar.MyWebSearch.AI evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\Extensions\64ffxtbr@TelevisionFanatic.com\plugins\FF-NativeMessagingDispatcher.dll.vir"
sh=3B0392ADB64821DAD5347AA89CA7ADA85D4AD5C9 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.2.2.zip.vir"
sh=65DBF1D094F3C63AD12C8F034D8D132A962FA46E ft=1 fh=073c304ffb9fa3a8 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\aapt.exe.vir"
sh=A2D473E09F7C019315030A2124DCED3B90CB4F87 ft=1 fh=37fc42c7c433ae0f vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\DaemonProcess.exe.vir"
sh=696BBC67FDCC9EC26CB95C2DDADC0F636541320A ft=1 fh=6b009b9250ad1e65 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\DCR.dll.vir"
sh=9E2C3D7CDEDE2543CC0F7960D9837D1B6D2BE75F ft=1 fh=7a481a0f621bd9cc vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\devcon_x64.exe.vir"
sh=E54955407B312B936C2873446E59355F0EA5CA73 ft=1 fh=d287fe18b11aa882 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\devcon_x86.exe.vir"
sh=4CA3AC424922EB725D3366835CEDEC4CDC4C9A7C ft=1 fh=9b99a692c8d56cf1 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\Device.dll.vir"
sh=77FF724EA6530E24FBD9EA8C2D59B1B291796874 ft=1 fh=d2ee2046d07ae837 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\DriverInstall_x64.exe.vir"
sh=1A8B4BA11E613DE010E51F03D89B513527846AA4 ft=1 fh=95b4c8bc1ea46e9e vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\DriverInstall_x86.exe.vir"
sh=8EE77C3EA732059837B316BEEE37A0809CD68F0B ft=1 fh=77f6a6fe09a20461 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\lsusb.exe.vir"
sh=F62E24423D06DDAF273DFFBA831C25EBC13B82EE ft=1 fh=9b120be6f077dc20 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mgadb.exe.vir"
sh=084D52BAC823AF36668193C643454F2F03752552 ft=1 fh=3670662d05fa4882 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\MgAssist.exe.vir"
sh=02D365A799FDCBF8C8A507FCFC69946B402FEA53 ft=1 fh=92f3782890b0d44b vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mgusb.exe.vir"
sh=5454230820B9172472548B91677FA99352A16A35 ft=1 fh=83c1a584ac14f3e4 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\Mobogenie.exe.vir"
sh=5BC0BBC3AC54D016E4C7878598350F9BE2A134F9 ft=0 fh=0000000000000000 vn="Variante von Android/Mobserv.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\MUServer.apk.vir"
sh=04DF5DA720E5E531F57BD14454EAF99E750D8BED ft=1 fh=f3c242e732b4b342 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\New_UpdateMoboGenie.exe.vir"
sh=8C6F55634ADBCA6FAA8101C1B2FB024B4855499D ft=1 fh=2876557c9c75ac21 vn="Variante von Win32/Adware.Mobogenie.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\OutlookOperatorC.exe.vir"
sh=87CE4C851AB95A41CE5CAB57300AA5E2913272C7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\xhr.js.vir"
sh=9EFDE89A61BAAA7D5D5D4B08214BE3D2EE505248 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\102_dealply_m.js.vir"
sh=57F445259F179510FE1EACAAD27A82E87305756C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\103_intext_5_m.js.vir"
sh=30630D311A124BA372D209C02247D8A4238E3610 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\104_jollywallet_m.js.vir"
sh=DD6FCCEDC3FD751B163389DB9F1C3BC91CFDADC0 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\14_CrossriderUtils.js.vir"
sh=84CA9AA694BCAE4779C18F493E7083124A3126C5 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\155_ibario_pops_m.js.vir"
sh=D9DF0722882055C5C11AFD602D505B2E7EA9AFC6 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\184_noproblemppc_m.js.vir"
sh=9E450F6FAC72A5A25FD4EDECE0CF5D3885230235 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\190_pops_5_m.js.vir"
sh=39D85F60370A7E5065A9BDC9D83216476D768A60 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\191_ciuvo_m.js.vir"
sh=5902FC10054355A5B8B9CC41620445BAA0F1D0AB ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\21_debug.js.vir"
sh=DE138BFD2293B4197712198C41377CE6A89E6200 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js.vir"
sh=E0F8250FB3FFBCB394862C11971C43A7B3B6BD17 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js.vir"
sh=57F2136CD86B69E88017E3346CF16BE0C2A51A2B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\28_initializer.js.vir"
sh=2EBC101982648313FFE20510A6C6754410F9D89B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\47_resources_background.js.vir"
sh=148CA44D7C0A3E2F5E2A3D38EFC5D999D2701A84 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\64_appApiMessage.js.vir"
sh=2C1383206E28E330BBC4DAA4BD9C8D7F942B2AE4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\91_monetizationLoader.js.js.vir"
sh=0C5AC30A082628E85A9A8B68EF5E5EAFA46F0CC7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\93_superfish_no_coupons_m.js.vir"
sh=954331290B6C48813BEDEFECAC563EFF7C806002 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\xhr.js.vir"
sh=911D715A45EB01135064E312F2DA7D76CEDF6746 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\102_dealply_m.js.vir"
sh=7FB2B410D7A3C932D5B739BEAEFD74BBBB94FE44 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\103_intext_5_m.js.vir"
sh=E934EE3FC237791859497C7F8AAA6F8C256346B4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\104_jollywallet_m.js.vir"
sh=0DE16E47E0B42A63F7F0DF9BBA6594069FE73EA2 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\119_similar_web_m.js.vir"
sh=2AB513C899C8CE89EADAEA73603AE1287BB402BC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\123_intext_adv_m.js.vir"
sh=DD6FCCEDC3FD751B163389DB9F1C3BC91CFDADC0 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\14_CrossriderUtils.js.vir"
sh=0DF5B53F31A1EBEBBBC42168DCB3C2190F1B7D62 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\178_revizer_ws_dynamic_m.js.vir"
sh=A57430022E6623D30ACFDFB82F013060C324FCD4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\179_revizer_p_dynamic_m.js.vir"
sh=F8FCF109D3E526F0B98BDB2BD01174AF9A902A8C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\180_bpo_serp_m.js.vir"
sh=211F78C0A16338FBA3CE14136AA745B8631C597A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\184_noproblemppc_m.js.vir"
sh=06107E2CB2818761C26753E71FE096DFDE882F3F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\190_pops_5_m.js.vir"
sh=5E6DA81E252435703C45D89C99D05227F3388CAC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\191_ciuvo_m.js.vir"
sh=8C66C849E2B66D44E4FCCDB719301AEE905D55DB ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\195_icm_convertmedia_m.js.vir"
sh=5902FC10054355A5B8B9CC41620445BAA0F1D0AB ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\21_debug.js.vir"
sh=B5550E48B8BB427EB378D645149E299D5102B262 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\220_icm_base_m.js.vir"
sh=C5AE3C95C6683373E987FE389219569F01C8FBB5 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\221_icm_downloads_m.js.vir"
sh=B6DC2CB64CD0031FC35CFE317013F77A5FDCCA90 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\223_imonomy_m.js.vir"
sh=B8DCC1355AF30C027794D10BC8FD83670866BA2A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\242_price_gong_m.js.vir"
sh=096360E528F6964EAA30051DDE841A0C8E63849B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\246_setup.js.vir"
sh=57F2136CD86B69E88017E3346CF16BE0C2A51A2B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\28_initializer.js.vir"
sh=2EBC101982648313FFE20510A6C6754410F9D89B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\47_resources_background.js.vir"
sh=148CA44D7C0A3E2F5E2A3D38EFC5D999D2701A84 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\64_appApiMessage.js.vir"
sh=202C1899F9B92EF86E40333C701C620BB16CE1F2 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\91_monetizationLoader.js.js.vir"
sh=4590C71E92C3067BEE6D3C17C915C49A90151A01 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\93_superfish_no_coupons_m.js.vir"
sh=476063885747EDD774A6B8CB2790703503A75A55 ft=1 fh=d7bb79193adaee2e vn="Win32/Systweak.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\Systweak\ssd\SSDPTstub.exe.vir"
sh=B71B34CA7E24EA96B507598C9BCB8F10A4BEB9C8 ft=1 fh=d252c90d8aa94121 vn="Variante von Win32/VOPackage.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Notebook\AppData\Roaming\VOPackage\VOsrv.exe.vir"
sh=87CE4C851AB95A41CE5CAB57300AA5E2913272C7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\xhr.js.vir"
sh=F9709950DC71343BD5C33FA36E7E22E527609C93 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\102_dealply_m.js.vir"
sh=01D69135EE92DAC22B8061E1BDD909E2C88CEA69 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\103_intext_5_m.js.vir"
sh=3C02C1198777BE5BA10D93C67F6CD34557EC171B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\104_jollywallet_m.js.vir"
sh=F4868E75E21D37FCBC9A5871B6B120EB3E4600DF ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\14_CrossriderUtils.js.vir"
sh=32C8CBB62AD3975B8330D63C5FD4B1F2B4328F63 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\155_ibario_pops_m.js.vir"
sh=9FFB696D07A9CF2E00AF98D436CB043D4B1988B5 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\184_noproblemppc_m.js.vir"
sh=D88BC1DC06D849820DF1C3783159BE2E5424E5F7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\190_pops_5_m.js.vir"
sh=AF4A89350A672268D320B32859AFCD17170BB977 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\191_ciuvo_m.js.vir"
sh=C1EB6A69219A2338DF815E20D227C1BBA07AC67D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\195_icm_convertmedia_m.js.vir"
sh=3E7E2E38627C3567488363D1F658A7F23259CC80 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\211_revizer_ws_dynamic_b2b_light_m.js.vir"
sh=3D8FEB274B1F910633E0EE3966A82AE9DCBD406A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\21_debug.js.vir"
sh=49045AFF4B791A0C85C789ECFA9C91904A1297E4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\220_icm_base_m.js.vir"
sh=40FDDFD7B9412D5BDAC1D0E2440E655C7A8FC33E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\226_set_campaign_id_m.js.vir"
sh=4660A1966307DD0EA8F91FB8E845DE17C42C3ADA ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js.vir"
sh=2784746F1B5974CCF87AAA4E2827D3417099BCDB ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js.vir"
sh=D93B8416BAAD22FE24D8CD082468986BECDBCC03 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\242_price_gong_m.js.vir"
sh=FD07E13CB435AA4328D85C2C272EC291679C0940 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\246_setup.js.vir"
sh=A61F2AB2BDA3DF4EA26FB96BFA4BAA4BEFA99E6A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\28_initializer.js.vir"
sh=D0C91B4ACE84473BFACA534FF1542F34C843F213 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\47_resources_background.js.vir"
sh=BDCFA8379825B1BC17A13BDF73B7384DE46E7C3B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\64_appApiMessage.js.vir"
sh=A944448CDA1CE5AA918107104D3B42C171DC810C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\91_monetizationLoader.js.js.vir"
sh=3D1C513C1AF6190E264097710C145E9D6A3A4060 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\93_superfish_no_coupons_m.js.vir"
sh=954331290B6C48813BEDEFECAC563EFF7C806002 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.G evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\chrome\content\core\xhr.js.vir"
sh=F9709950DC71343BD5C33FA36E7E22E527609C93 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\102_dealply_m.js.vir"
sh=01D69135EE92DAC22B8061E1BDD909E2C88CEA69 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\103_intext_5_m.js.vir"
sh=3C02C1198777BE5BA10D93C67F6CD34557EC171B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\104_jollywallet_m.js.vir"
sh=2C5C97A4EDD53CE4333EEF27A9DB5FA4400143C6 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\119_similar_web_m.js.vir"
sh=22BD87991B5507F18DF5B51B9650946541B67C6E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\123_intext_adv_m.js.vir"
sh=F4868E75E21D37FCBC9A5871B6B120EB3E4600DF ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.O evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\14_CrossriderUtils.js.vir"
sh=F2E2857032DA39E7AFC7C88C2F821892B24CB356 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\178_revizer_ws_dynamic_m.js.vir"
sh=8553AF9879AAA88E75213647561CE17BFE811201 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\179_revizer_p_dynamic_m.js.vir"
sh=08588E3F12EF6CBFECEF803A5B9305227E2CDA47 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\180_bpo_serp_m.js.vir"
sh=D4AA12D5B3D4840135960BFF4F898E7F3F7CD735 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\184_noproblemppc_m.js.vir"
sh=D88BC1DC06D849820DF1C3783159BE2E5424E5F7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\190_pops_5_m.js.vir"
sh=AF4A89350A672268D320B32859AFCD17170BB977 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\191_ciuvo_m.js.vir"
sh=C1EB6A69219A2338DF815E20D227C1BBA07AC67D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\195_icm_convertmedia_m.js.vir"
sh=3D8FEB274B1F910633E0EE3966A82AE9DCBD406A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\21_debug.js.vir"
sh=49045AFF4B791A0C85C789ECFA9C91904A1297E4 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\220_icm_base_m.js.vir"
sh=82CF3E1378FCB28417B1652D9F27AAD6DB128AF3 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\221_icm_downloads_m.js.vir"
sh=D69389DD5BACEE18D79EB06C4CEB331FE47FDE17 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\223_imonomy_m.js.vir"
sh=D93B8416BAAD22FE24D8CD082468986BECDBCC03 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\242_price_gong_m.js.vir"
sh=FD07E13CB435AA4328D85C2C272EC291679C0940 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\246_setup.js.vir"
sh=A61F2AB2BDA3DF4EA26FB96BFA4BAA4BEFA99E6A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\28_initializer.js.vir"
sh=D0C91B4ACE84473BFACA534FF1542F34C843F213 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\47_resources_background.js.vir"
sh=BDCFA8379825B1BC17A13BDF73B7384DE46E7C3B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.P evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\64_appApiMessage.js.vir"
sh=A944448CDA1CE5AA918107104D3B42C171DC810C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\91_monetizationLoader.js.js.vir"
sh=3D1C513C1AF6190E264097710C145E9D6A3A4060 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\13c471d9-6cbb-4c08-9dd1-8dc16c66bb1f@cf5065af-ca24-464a-a637-af7582a82514.com\extensionData\plugins\93_superfish_no_coupons_m.js.vir"
sh=7E476CBC20B540F11239EC2A5C617FF221BF52CC ft=1 fh=80c7b6f3be1d69d2 vn="Variante von Win32/Toolbar.MyWebSearch.AI evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Uwe\AppData\Roaming\Mozilla\Firefox\Profiles\xfnq8589.default\Extensions\64ffxtbr@TelevisionFanatic.com\plugins\FF-NativeMessagingDispatcher.dll.vir"
sh=BA39F8C9886EF4AABD72262B192DB8A177C7E206 ft=1 fh=078180abaf06d010 vn="Variante von Win64/Systweak.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\windows\System32\roboot64.exe.vir"
sh=784BBF10F11D28C7FB53EB20625A029CB74869B5 ft=1 fh=be0ca9fdc8c6a53a vn="Variante von Win32/Bundlore.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Nora\Desktop\Downloads\setup(4).exe"
sh=705F7674C554A2BDA26E88C6776C54FDBF379002 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PUA7UQY\icm_convertmedia_m[1].js"
sh=D767D39DA00E1507AB72DF2BBF0DF984E5F67F87 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PUA7UQY\icm_downloads_m[1].js"
sh=A03BE69557ACE9F739D7DF72BC9F39126C50AF12 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PUA7UQY\monetizationLoader[1].js"
sh=09E41DAB84A351A234F471879A1C5FC682957ABA ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PUA7UQY\revizer_p_dynamic_m[1].js"
sh=57F74C3FAF6723290F6FA3341542A17948A76BCD ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PUA7UQY\revizer_ws_dynamic_m[1].js"
sh=BFD0F29067CAE71544784708FE5554D6518AD6AD ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PUA7UQY\superfish_no_coupons_m[1].js"
sh=B683C210045A4133B80E4ECC0C23BC3196B66514 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9443JU77\bpo_serp_m[1].js"
sh=C403B988AF2EFC2B9DD070F5C5A3070244B7DEE2 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9443JU77\dealply_m[1].js"
sh=115081E9037F5D63F69BC5CA19ECC1ACC8F61896 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9443JU77\imonomy_m[1].js"
sh=066D67D3C0F4110A52C2843171BCB750FA7A6E6B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9443JU77\intext_5_m[1].js"
sh=B4853CCBF4F400FB3A12155815CFFD0D74C8EEAC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9443JU77\noproblemppc_m[1].js"
sh=B531261EF0F4945E9E5B2642CB63C74D404DF63C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9443JU77\noproblemppc_ppi_m[1].js"
sh=B8B5897BC3983B6CE75447868BDAE3EB1441E61C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CCSC3WG5\ibario_pops_m[1].js"
sh=9832E303AF1F020C6DD37DB8D8E7A0FF40979142 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CCSC3WG5\intext_adv_m[1].js"
sh=431AC6F8406F059B0E9126386C40A2EE543E5EC3 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.M evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CCSC3WG5\resources_background[1].js"
sh=089CC10FABD94FCFF67B2C2A2A0FE6437CC67E5C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.P evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GWZ8QB6R\appApiMessage[1].js"
sh=BD99029E3E064DE3BDC009BED86CE5F9F6556130 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GWZ8QB6R\ciuvo_m[1].js"
sh=FF68239BA1F9AFA35E039DEB47E536BF1DA6217B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.O evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GWZ8QB6R\CrossriderUtils[1].js"
sh=BA13B61D2A823E7CBBDC85CD5CE511946BC86E65 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GWZ8QB6R\debug[1].js"
sh=4666A52D4EEF9AD0B5BEF9DFF1A9163C17D03398 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GWZ8QB6R\initializer[1].js"
sh=CC9B5D471D8C379CBAA0E63FE16033287F90F82D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GWZ8QB6R\jollywallet_m[1].js"
sh=8C65267C1AADD4AB670D6D979C4A686D16A86869 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GWZ8QB6R\similar_web_m[1].js"
sh=202C1899F9B92EF86E40333C701C620BB16CE1F2 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Mozilla\Firefox\Profiles\kr5q6a4y.default\Cache.Trash30735\0\65\96228d01"
sh=B5550E48B8BB427EB378D645149E299D5102B262 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Local\Mozilla\Firefox\Profiles\kr5q6a4y.default\Cache.Trash30735\8\8C\4FEA3d01"
sh=3BC89FB51E2295B5D2757976B5F376F3A2ADA833 ft=1 fh=34db28551978ddd0 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Roaming\ShieldApps\PC Speed Repair 2.4.7\install\6387ED6\Helper.dll"
sh=3AFA859F03A613886C791F93CBEA94180BE0B1EE ft=1 fh=afc315597b9244c5 vn="Variante von MSIL/Rebrand.LittleRegClean.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Roaming\ShieldApps\PC Speed Repair 2.4.7\install\6387ED6\PCSpeedRepair.exe"
sh=D395DCBDDD8EF4E896E937766BA29DC64F4A0238 ft=1 fh=b15955de4672c120 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Notebook\AppData\Roaming\ShieldApps\PC Speed Repair 2.4.7\install\6387ED6\Uninst000.CA.dll"


nora.s 15.11.2015 18:29

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Code:

18:11:32 = Process Attach
18:11:32 = end process attach

18:11:32 = ***** NULL == SampleProvider *****

18:11:32 = hWnd = 0x0003032e; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=145, width=466, height=378
18:11:32 = hWnd = 0x000403a0; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:11:32 = hWnd = 0x000403aa; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:11:32 = hWnd = 0x000403ea; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=11b, y=84, width=800, height=560
18:11:32 = hWnd = 0x000403a4; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:11:32 = hWnd = 0x00050324; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:11:32 = hWnd = 0x00030328; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:11:32 = hWnd = 0x000203d2; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:11:32 = hWnd = 0x000602ca; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:32 = hWnd = 0x000a0396; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:11:32 = hWnd = 0x000403a8; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:32 = hWnd = 0x0003032a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:32 = Need to re-create objects.

18:11:32 = s1.

18:11:32 = s2.

18:11:32 = find user name
18:11:32 = Start show animate
18:11:33 = Shell Excutute VerifyHost
18:11:33 = find user name
18:11:33 = find user name
18:11:33 = find user name
18:11:33 = begin close Process
18:11:33 = Terminate Process
18:11:34 = end close Process
18:11:34 = DLL_PROCESS_DETACH

18:11:43 = Process Attach
18:11:43 = end process attach

18:11:43 = ##### Begin waiting Mutex to release process #####

18:11:43 = ***** NULL == SampleProvider *****

18:11:43 = hWnd = 0x0004032c; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:11:43 = hWnd = 0x0004032a; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:11:43 = hWnd = 0x00040364; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x0004036c; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000503e4; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000603a6; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
18:11:43 = hWnd = 0x000503a0; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
18:11:43 = hWnd = 0x000503aa; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:11:43 = hWnd = 0x000503a4; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:11:43 = hWnd = 0x000403dc; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:11:43 = hWnd = 0x000503a8; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000403ec; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000b0396; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:43 = hWnd = 0x000603ac; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:43 = Need to re-create objects.

18:11:43 = s1.

18:11:43 = s2.

18:11:43 = find user name
18:11:43 = Start show animate
18:11:45 = Shell Excutute VerifyHost
18:11:45 = find user name
18:11:46 = find user name
18:11:47 = begin close Process
18:11:47 = Terminate Process
18:11:48 = end close Process
18:11:48 = DLL_PROCESS_DETACH

18:11:51 = Process Attach
18:11:51 = end process attach

18:11:51 = ***** NULL == SampleProvider *****

18:11:51 = hWnd = 0x000503ee; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:11:51 = hWnd = 0x000d0396; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:11:51 = hWnd = 0x000603a8; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
18:11:51 = hWnd = 0x00050328; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
18:11:51 = hWnd = 0x000403fa; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000403da; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000503dc; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:11:51 = hWnd = 0x0005032c; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:11:51 = hWnd = 0x0007036c; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:11:51 = hWnd = 0x000703e0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000703ac; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000503ec; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:51 = hWnd = 0x000c0324; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:11:51 = Need to re-create objects.

18:11:51 = s1.

18:11:51 = s2.

18:11:51 = find user name
18:11:51 = Start show animate
18:11:52 = Shell Excutute VerifyHost
18:11:52 = find user name
18:11:53 = begin close Process
18:11:53 = Terminate Process
18:11:54 = end close Process
18:11:54 = DLL_PROCESS_DETACH

18:17:39 = Process Attach
18:17:39 = end process attach

18:17:39 = ##### Begin waiting Mutex to release process #####

18:17:39 = ***** NULL == SampleProvider *****

18:17:39 = hWnd = 0x00d103fa; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:17:39 = hWnd = 0x000902f6; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:17:39 = hWnd = 0x00060326; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x000a0388; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x000603b4; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x0004017e; ClassName: #32770; Title: Benutzerkontensteuerung.
x=4, y=271, width=466, height=378
18:17:39 = hWnd = 0x00060312; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=252, width=491, height=476
18:17:39 = hWnd = 0x00090322; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:17:39 = hWnd = 0x00040176; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:17:39 = hWnd = 0x000502e2; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:17:39 = hWnd = 0x000502d8; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x000602e8; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x000502e6; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:17:39 = hWnd = 0x00090320; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:17:39 = Need to re-create objects.

18:17:39 = s1.

18:17:39 = s2.

18:17:39 = find user name
18:17:39 = Start show animate
18:17:40 = Shell Excutute VerifyHost
18:17:40 = find user name
18:17:42 = find user name
18:17:42 = begin close Process
18:17:42 = Terminate Process
18:17:43 = end close Process
18:17:43 = DLL_PROCESS_DETACH

18:18:45 = Process Attach
18:18:45 = end process attach

18:18:45 = ***** NULL == SampleProvider *****

18:18:45 = hWnd = 0x000702e2; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:18:45 = hWnd = 0x000d033c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:18:45 = hWnd = 0x00080312; ClassName: #32770; Title: Benutzerkontensteuerung.
x=23f, y=245, width=216, height=238
18:18:45 = hWnd = 0x000b02f6; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
18:18:45 = hWnd = 0x000b0320; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:18:45 = hWnd = 0x00100324; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:18:45 = hWnd = 0x0007026e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:18:45 = hWnd = 0x000b0322; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:18:45 = hWnd = 0x000702ea; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:45 = hWnd = 0x000b036c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:45 = hWnd = 0x00090326; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:45 = Need to re-create objects.

18:18:45 = s1.

18:18:45 = s2.

18:18:45 = find user name
18:18:45 = Start show animate
18:18:46 = Shell Excutute VerifyHost
18:18:46 = find user name
18:18:47 = find user name
18:18:47 = begin close Process
18:18:47 = Terminate Process
18:18:48 = end close Process
18:18:48 = DLL_PROCESS_DETACH

18:18:51 = Process Attach
18:18:51 = end process attach

18:18:51 = ***** NULL == SampleProvider *****

18:18:51 = hWnd = 0x000f0388; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:18:51 = hWnd = 0x000d036c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:18:51 = hWnd = 0x000c02f6; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
18:18:51 = hWnd = 0x000902e6; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
18:18:51 = hWnd = 0x0008026e; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:18:51 = hWnd = 0x000802e2; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:18:51 = hWnd = 0x000802d6; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:18:51 = hWnd = 0x000802f0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:18:51 = hWnd = 0x000c0320; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:51 = hWnd = 0x00100380; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:18:51 = hWnd = 0x000a0326; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:51 = hWnd = 0x00100344; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:18:51 = Need to re-create objects.

18:18:51 = s1.

18:18:51 = s2.

18:18:51 = find user name
18:18:51 = Start show animate
18:18:53 = Shell Excutute VerifyHost
18:18:53 = begin close Process
18:18:53 = Terminate Process
18:18:54 = end close Process
18:18:54 = DLL_PROCESS_DETACH

18:22:14 = Process Attach
18:22:14 = end process attach

18:22:14 = ##### Begin waiting Mutex to release process #####

18:22:14 = ***** NULL == SampleProvider *****

18:22:14 = hWnd = 0x0015035c; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:22:14 = hWnd = 0x001c036c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:22:14 = hWnd = 0x000401f4; ClassName: #32770; Title: Benutzerkontensteuerung.
x=23b, y=195, width=466, height=399
18:22:14 = hWnd = 0x000a03bc; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=1a2, y=180, width=788, height=489
18:22:14 = hWnd = 0x00070352; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x00040254; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x000b0336; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:22:14 = hWnd = 0x000a0338; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:22:14 = hWnd = 0x001d02e2; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:22:14 = hWnd = 0x00040160; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x00100350; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x000401ae; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:22:14 = hWnd = 0x000f0176; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:22:14 = Need to re-create objects.

18:22:14 = s1.

18:22:14 = s2.

18:22:14 = find user name
18:22:14 = Start show animate
18:22:16 = Shell Excutute VerifyHost
18:22:16 = find user name
18:22:16 = begin close Process
18:22:16 = Terminate Process
18:22:17 = end close Process
18:22:17 = DLL_PROCESS_DETACH

18:38:19 = Process Attach
18:38:19 = end process attach

18:38:19 = ***** NULL == SampleProvider *****

18:38:19 = ##### Begin waiting Mutex to release process #####

18:38:19 = hWnd = 0x00150354; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
18:38:19 = hWnd = 0x000f03f8; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:38:19 = hWnd = 0x0006025e; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:38:19 = hWnd = 0x00100394; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:38:21 = Process Attach
18:38:21 = ## ERR ## Setevent

18:38:21 = ***** NULL == SampleProvider *****

18:38:21 = begin close Process
18:38:21 = end close Process
18:38:21 = ##### Get event and release process end #####

18:38:21 = hWnd = 0x0062009e; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1024, height=768
18:38:21 = hWnd = 0x00160084; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:38:21 = hWnd = 0x00030044; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:38:21 = hWnd = 0x001b007c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:39:14 = Process Attach
18:39:14 = end process attach

18:39:14 = ***** NULL == SampleProvider *****

18:39:14 = ##### Begin waiting Mutex to release process #####

18:39:14 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
18:39:14 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:39:14 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:39:14 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:39:23 = Need to re-create objects.

18:39:23 = s1.

18:39:23 = s2.

18:39:23 = find user name
18:39:23 = Start show animate
18:39:25 = Shell Excutute VerifyHost
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:25 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:29 = find user name
18:39:30 = find user name
18:39:30 = find user name
18:39:30 = find user name
18:39:41 = begin close Process
18:39:41 = Terminate Process
18:39:42 = end close Process
18:39:42 = DLL_PROCESS_DETACH

18:40:44 = Process Attach
18:40:44 = end process attach

18:40:44 = ##### Begin waiting Mutex to release process #####

18:40:44 = ***** NULL == SampleProvider *****

18:40:44 = hWnd = 0x000302d6; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:40:44 = hWnd = 0x000202da; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:40:44 = hWnd = 0x000103a2; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=145, width=466, height=378
18:40:44 = hWnd = 0x0002039a; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=11b, y=84, width=800, height=560
18:40:44 = hWnd = 0x000103c2; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x000103c6; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x00040394; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:40:44 = hWnd = 0x0001039e; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:40:44 = hWnd = 0x000602d2; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:40:44 = hWnd = 0x0001039c; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x00020398; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x000103a0; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:40:44 = hWnd = 0x000502ce; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:40:44 = Need to re-create objects.

18:40:44 = s1.

18:40:44 = s2.

18:40:44 = find user name
18:40:44 = Start show animate
18:40:45 = Shell Excutute VerifyHost
18:40:45 = find user name
18:40:46 = begin close Process
18:40:46 = Terminate Process
18:40:47 = end close Process
18:40:47 = DLL_PROCESS_DETACH

18:59:2 = Process Attach
18:59:2 = end process attach

18:59:2 = ***** NULL == SampleProvider *****

18:59:2 = hWnd = 0x000403ba; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
18:59:2 = hWnd = 0x000a039c; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:59:2 = hWnd = 0x000403b0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:59:2 = hWnd = 0x000403bc; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:59:6 = Process Attach
18:59:6 = ## ERR ## Setevent

18:59:6 = ##### Get event and release process #####

18:59:6 = begin close Process
18:59:6 = end close Process
18:59:6 = ##### Get event and release process end #####

18:59:49 = Process Attach
18:59:49 = end process attach

18:59:49 = ***** NULL == SampleProvider *****

18:59:49 = ##### Begin waiting Mutex to release process #####

18:59:49 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
18:59:49 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:59:49 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:59:49 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:59:56 = Need to re-create objects.

18:59:56 = s1.

18:59:56 = s2.

18:59:56 = find user name
18:59:56 = Start show animate
18:59:58 = Shell Excutute VerifyHost
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:58 = find user name
18:59:59 = find user name
18:59:59 = find user name
18:59:59 = find user name
18:59:59 = find user name
18:59:59 = find user name
19:0:1 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:2 = find user name
19:0:3 = find user name
19:0:3 = find user name
19:0:3 = find user name
21:37:14 = Process Attach
21:37:14 = end process attach

21:37:14 = ##### Begin waiting Mutex to release process #####

21:37:14 = hWnd = 0x0008034c; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
21:37:14 = hWnd = 0x000602c6; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
21:37:14 = hWnd = 0x00020352; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:14 = hWnd = 0x0002032e; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:14 = hWnd = 0x0005036a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:14 = Need to re-create objects.

21:37:14 = s1.

21:37:14 = s2.

21:37:14 = find user name
21:37:14 = Start show animate
21:37:16 = Shell Excutute VerifyHost
21:37:16 = begin close Process
21:37:16 = Terminate Process
21:37:17 = end close Process
21:37:17 = DLL_PROCESS_DETACH

21:37:28 = Process Attach
21:37:28 = end process attach

21:37:28 = ##### Begin waiting Mutex to release process #####

21:37:28 = ***** NULL == SampleProvider *****

21:37:28 = hWnd = 0x0006036a; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
21:37:28 = hWnd = 0x0009034c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
21:37:28 = hWnd = 0x0003038e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x00030378; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x00030374; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x000702c6; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
21:37:28 = hWnd = 0x0009035c; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
21:37:28 = hWnd = 0x00080392; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
21:37:28 = hWnd = 0x0003033c; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
21:37:28 = hWnd = 0x0005032e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
21:37:28 = hWnd = 0x00030346; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x000b03fe; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x00030352; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:28 = hWnd = 0x0007039c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:37:28 = Need to re-create objects.

21:37:28 = s1.

21:37:28 = s2.

21:37:28 = find user name
21:37:28 = Start show animate
21:37:29 = Shell Excutute VerifyHost
21:37:29 = find user name
21:37:34 = begin close Process
21:37:34 = Terminate Process
21:37:35 = end close Process
21:37:35 = DLL_PROCESS_DETACH

21:43:3 = Process Attach
21:43:3 = end process attach

21:43:3 = ***** NULL == SampleProvider *****

21:43:3 = hWnd = 0x00110378; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
21:43:3 = hWnd = 0x000603ae; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
21:43:3 = hWnd = 0x000403da; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:43:3 = ##### Begin waiting Mutex to release process #####

21:43:3 = hWnd = 0x000603e0; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x000502c8; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x00060154; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
21:43:3 = hWnd = 0x00080394; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
21:43:3 = hWnd = 0x000a0354; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
21:43:3 = hWnd = 0x0008036a; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
21:43:3 = hWnd = 0x000502d2; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
21:43:3 = hWnd = 0x000a0352; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x000c032c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x000a0392; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:43:3 = hWnd = 0x00070320; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
21:43:3 = Need to re-create objects.

21:43:3 = s1.

21:43:3 = s2.

21:43:3 = find user name
21:43:3 = Start show animate
21:43:4 = Shell Excutute VerifyHost
21:43:4 = find user name
21:43:5 = begin close Process
21:43:5 = Terminate Process
21:43:6 = end close Process
21:43:6 = DLL_PROCESS_DETACH

0:11:53 = Process Attach
0:11:53 = end process attach

0:11:53 = ##### Begin waiting Mutex to release process #####

0:11:53 = hWnd = 0x00110352; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
0:11:53 = hWnd = 0x000c02fe; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
0:11:53 = hWnd = 0x000902f8; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
0:11:53 = hWnd = 0x000e033c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
0:11:56 = Process Attach
0:11:56 = ## ERR ## Setevent

0:11:56 = ##### Get event and release process #####

0:11:56 = begin close Process
0:11:56 = end close Process
0:11:56 = ##### Get event and release process end #####

0:11:56 = ***** NULL == SampleProvider *****

0:11:56 = hWnd = 0x00cf0072; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1024, height=768
0:11:56 = hWnd = 0x00cf005a; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
0:11:56 = hWnd = 0x00030078; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
0:11:56 = hWnd = 0x00980038; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
9:11:39 = Process Attach
9:11:39 = end process attach

9:11:39 = ***** NULL == SampleProvider *****

9:11:39 = ##### Begin waiting Mutex to release process #####

9:11:39 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
9:11:39 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
9:11:39 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
9:11:39 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
9:11:39 = Need to re-create objects.

9:11:39 = s1.

9:11:39 = s2.

9:11:39 = find user name
9:11:39 = Start show animate
9:11:41 = Shell Excutute VerifyHost
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:11:41 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:10 = find user name
9:15:11 = find user name
9:15:11 = find user name
9:15:11 = find user name
9:15:18 = begin close Process
9:15:18 = Terminate Process
9:15:19 = end close Process
9:15:19 = DLL_PROCESS_DETACH

12:31:1 = Process Attach
12:31:1 = end process attach

12:31:1 = ##### Begin waiting Mutex to release process #####

12:31:1 = hWnd = 0x0002041a; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
12:31:1 = hWnd = 0x00040440; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
12:31:1 = hWnd = 0x000203c0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
12:31:1 = hWnd = 0x000803b0; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
12:31:1 = Need to re-create objects.

12:31:1 = s1.

12:31:1 = s2.

12:31:1 = find user name
12:31:1 = Start show animate
12:31:3 = Is Black Sceen wait
12:31:3 = black wait1
12:31:4 = Is Black Sceen wait
12:31:4 = black wait2
12:31:6 = Is Black Sceen wait
12:31:6 = black wait3
12:37:11 = Shell Excutute VerifyHost
12:37:14 = find user name
12:37:14 = find user name
12:37:14 = find user name
12:37:16 = find user name
12:37:16 = find user name
12:37:16 = find user name
12:37:16 = find user name
12:37:16 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:34 = find user name
12:37:35 = begin close Process
12:37:35 = Terminate Process
12:37:36 = end close Process
12:37:36 = DLL_PROCESS_DETACH

13:26:50 = Process Attach
13:26:50 = end process attach

13:26:50 = ***** NULL == SampleProvider *****

13:26:50 = hWnd = 0x000b0434; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
13:26:50 = hWnd = 0x000a0472; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
13:26:50 = hWnd = 0x000b03f6; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x00070490; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x000f0432; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x001003ec; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=154, width=466, height=399
13:26:50 = hWnd = 0x0004046c; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
13:26:50 = hWnd = 0x001003fa; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
13:26:50 = hWnd = 0x000a045a; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
13:26:50 = hWnd = 0x000b033a; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
13:26:50 = hWnd = 0x002203d0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x00100428; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x000f03bc; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:50 = hWnd = 0x00100476; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:50 = Need to re-create objects.

13:26:50 = s1.

13:26:50 = s2.

13:26:50 = find user name
13:26:50 = Start show animate
13:26:52 = Shell Excutute VerifyHost
13:26:52 = begin close Process
13:26:52 = end close Process
13:26:52 = DLL_PROCESS_DETACH

13:26:55 = Process Attach
13:26:55 = end process attach

13:26:55 = ***** NULL == SampleProvider *****

13:26:55 = hWnd = 0x000503a6; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
13:26:55 = ##### Begin waiting Mutex to release process #####

13:26:55 = hWnd = 0x000b0454; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
13:26:55 = hWnd = 0x00110428; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=154, width=466, height=399
13:26:55 = hWnd = 0x001103d8; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
13:26:55 = hWnd = 0x00110412; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x000e044e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x000c033a; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
13:26:55 = hWnd = 0x000c0434; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
13:26:55 = hWnd = 0x001203bc; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
13:26:55 = hWnd = 0x000d03e4; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x00110476; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x0005046c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:55 = hWnd = 0x00080398; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
13:26:55 = Need to re-create objects.

13:26:55 = s1.

13:26:55 = s2.

13:26:55 = find user name
13:26:55 = Start show animate
13:26:57 = Shell Excutute VerifyHost
13:26:57 = find user name
13:26:58 = begin close Process
13:26:58 = Terminate Process
13:26:59 = end close Process
13:26:59 = DLL_PROCESS_DETACH

14:11:3 = Process Attach
14:11:3 = end process attach

14:11:3 = ##### Begin waiting Mutex to release process #####

14:11:3 = ***** NULL == SampleProvider *****

14:11:3 = hWnd = 0x000703b2; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:11:3 = hWnd = 0x0005031e; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:11:3 = hWnd = 0x000403a8; ClassName: #32770; Title: Benutzerkontensteuerung.
x=c5, y=42, width=466, height=399
14:11:3 = hWnd = 0x000303ac; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=64, y=100, width=677, height=342
14:11:3 = hWnd = 0x001803a0; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x002d03ce; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x00030324; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:11:3 = hWnd = 0x00030310; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:11:3 = hWnd = 0x0003032e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:11:3 = hWnd = 0x0006032c; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x00030326; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x0004035a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:3 = hWnd = 0x0003031c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:3 = Need to re-create objects.

14:11:3 = s1.

14:11:3 = s2.

14:11:3 = find user name
14:11:3 = Start show animate
14:11:4 = Shell Excutute VerifyHost
14:11:4 = find user name
14:11:4 = find user name
14:11:5 = begin close Process
14:11:5 = end close Process
14:11:5 = DLL_PROCESS_DETACH

14:11:5 = Process Attach
14:11:5 = end process attach

14:11:5 = ##### Begin waiting Mutex to release process #####

14:11:5 = ***** NULL == SampleProvider *****

14:11:5 = hWnd = 0x0006031e; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:11:5 = hWnd = 0x001a03ea; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:11:5 = hWnd = 0x0016046c; ClassName: #32770; Title: Benutzerkontensteuerung.
x=c5, y=42, width=466, height=399
14:11:5 = hWnd = 0x000403ac; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=64, y=100, width=677, height=342
14:11:5 = hWnd = 0x00040320; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x00030322; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x001c03a0; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:11:5 = hWnd = 0x00040324; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:11:5 = hWnd = 0x00060334; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:11:5 = hWnd = 0x0007032c; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x000803b2; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x00140476; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:5 = hWnd = 0x0004032e; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:5 = Need to re-create objects.

14:11:5 = s1.

14:11:5 = s2.

14:11:5 = find user name
14:11:5 = Start show animate
14:11:6 = Shell Excutute VerifyHost
14:11:6 = find user name
14:11:7 = find user name
14:11:7 = begin close Process
14:11:7 = Terminate Process
14:11:8 = end close Process
14:11:8 = DLL_PROCESS_DETACH

14:11:8 = Process Attach
14:11:8 = end process attach

14:11:8 = ##### Begin waiting Mutex to release process #####

14:11:8 = ***** NULL == SampleProvider *****

14:11:8 = hWnd = 0x00070334; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:11:8 = hWnd = 0x002303bc; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:11:8 = hWnd = 0x00050326; ClassName: #32770; Title: Benutzerkontensteuerung.
x=c5, y=42, width=466, height=399
14:11:8 = hWnd = 0x001b03ea; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=64, y=100, width=677, height=342
14:11:8 = hWnd = 0x0005018e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x000703aa; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x0005032e; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:11:8 = hWnd = 0x001d03a0; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:11:8 = hWnd = 0x00160476; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:11:8 = hWnd = 0x0007031e; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x0005031c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x0008032c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:8 = hWnd = 0x00070318; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:8 = Need to re-create objects.

14:11:8 = s1.

14:11:8 = s2.

14:11:8 = find user name
14:11:8 = Start show animate
14:11:10 = Shell Excutute VerifyHost
14:11:10 = find user name
14:11:11 = find user name
14:11:11 = begin close Process
14:11:11 = Terminate Process
14:11:12 = end close Process
14:11:12 = DLL_PROCESS_DETACH

14:11:19 = Process Attach
14:11:19 = end process attach

14:11:19 = ##### Begin waiting Mutex to release process #####

14:11:19 = ***** NULL == SampleProvider *****

14:11:19 = hWnd = 0x00060310; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:11:19 = hWnd = 0x0007035a; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:11:19 = hWnd = 0x00110396; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x00190480; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x00080318; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=154, width=466, height=399
14:11:19 = hWnd = 0x002403e0; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
14:11:19 = hWnd = 0x003203ce; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:11:19 = hWnd = 0x00080324; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:11:19 = hWnd = 0x000e047a; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:11:19 = hWnd = 0x00180476; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x002003a0; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x000a03aa; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:19 = hWnd = 0x0007033c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:11:19 = Need to re-create objects.

14:11:19 = s1.

14:11:19 = s2.

14:11:19 = find user name
14:11:19 = Start show animate
14:11:20 = Shell Excutute VerifyHost
14:11:20 = find user name
14:11:21 = begin close Process
14:11:21 = Terminate Process
14:11:22 = end close Process
14:11:22 = DLL_PROCESS_DETACH

14:15:45 = Process Attach
14:15:45 = end process attach

14:15:45 = ***** NULL == SampleProvider *****

14:15:45 = hWnd = 0x001b03ca; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
14:15:45 = hWnd = 0x001c0480; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:15:45 = hWnd = 0x00090340; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:15:45 = hWnd = 0x000b0324; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:15:49 = Process Attach
14:15:49 = ## ERR ## Setevent

14:15:49 = ##### Get event and release process #####

14:15:49 = begin close Process
14:15:49 = end close Process
14:15:49 = ##### Get event and release process end #####

14:15:49 = ***** NULL == SampleProvider *****

14:15:49 = hWnd = 0x0002010e; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1024, height=768
14:15:49 = hWnd = 0x0002012a; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:15:49 = hWnd = 0x000200b0; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:15:49 = hWnd = 0x00020128; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:17:17 = Process Attach
14:17:17 = end process attach

14:17:17 = ***** NULL == SampleProvider *****

14:17:17 = ##### Begin waiting Mutex to release process #####

14:17:17 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
14:17:17 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:17:17 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:17:17 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:17:20 = Need to re-create objects.

14:17:20 = s1.

14:17:20 = s2.

14:17:20 = find user name
14:17:20 = Start show animate
14:17:21 = Shell Excutute VerifyHost
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:21 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:17:38 = find user name
14:18:10 = begin close Process
14:18:10 = Terminate Process
14:18:11 = end close Process
14:18:11 = DLL_PROCESS_DETACH

14:20:6 = Process Attach
14:20:6 = end process attach

14:20:6 = ##### Begin waiting Mutex to release process #####

14:20:6 = ***** NULL == SampleProvider *****

14:20:6 = hWnd = 0x00050324; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:20:6 = hWnd = 0x00050322; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:20:6 = hWnd = 0x00010342; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x00010346; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x0001034a; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x0006031e; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
14:20:6 = hWnd = 0x00050330; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
14:20:6 = hWnd = 0x0005031a; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:20:6 = hWnd = 0x000302d8; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:20:6 = hWnd = 0x0005032e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:20:6 = hWnd = 0x000302d6; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x00050316; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x0006032c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:6 = hWnd = 0x0005031c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:6 = Need to re-create objects.

14:20:6 = s1.

14:20:6 = s2.

14:20:6 = find user name
14:20:6 = Start show animate
14:20:7 = Shell Excutute VerifyHost
14:20:7 = find user name
14:20:8 = find user name
14:20:8 = begin close Process
14:20:8 = Terminate Process
14:20:9 = end close Process
14:20:9 = DLL_PROCESS_DETACH

14:20:13 = Process Attach
14:20:13 = end process attach

14:20:13 = ##### Begin waiting Mutex to release process #####

14:20:13 = ***** NULL == SampleProvider *****

14:20:13 = hWnd = 0x00060314; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:20:13 = hWnd = 0x0008032c; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:20:13 = hWnd = 0x0002033e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x0002033a; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x0004030e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x00030348; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
14:20:13 = hWnd = 0x00060320; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
14:20:13 = hWnd = 0x0006032e; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:20:13 = hWnd = 0x00030356; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:20:13 = hWnd = 0x00040346; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:20:13 = hWnd = 0x0008031e; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x0006031c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x00060322; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:13 = hWnd = 0x000d002a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:20:13 = Need to re-create objects.

14:20:13 = s1.

14:20:13 = s2.

14:20:13 = find user name
14:20:13 = Start show animate
14:20:15 = Shell Excutute VerifyHost
14:20:15 = find user name
14:20:16 = begin close Process
14:20:16 = Terminate Process
14:20:17 = end close Process
14:20:17 = DLL_PROCESS_DETACH

14:39:11 = Process Attach
14:39:11 = end process attach

14:39:11 = ***** NULL == SampleProvider *****

14:39:11 = ##### Begin waiting Mutex to release process #####

14:39:11 = hWnd = 0x0001001c; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
14:39:11 = hWnd = 0x00010018; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:39:11 = hWnd = 0x00010022; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:39:11 = hWnd = 0x0001001a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:39:35 = Need to re-create objects.

14:39:35 = s1.

14:39:35 = s2.

14:39:37 = find user name
14:39:37 = Start show animate
14:39:38 = Shell Excutute VerifyHost
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:38 = find user name
14:39:39 = find user name
14:39:39 = find user name
14:39:39 = find user name
14:39:39 = find user name
14:39:39 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:40 = find user name
14:39:55 = begin close Process
14:39:55 = Terminate Process
14:39:56 = end close Process
14:39:56 = DLL_PROCESS_DETACH

14:41:18 = Process Attach
14:41:18 = end process attach

14:41:18 = ***** NULL == SampleProvider *****

14:41:18 = hWnd = 0x000202d2; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:41:18 = hWnd = 0x000302d0; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:41:18 = hWnd = 0x00020322; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x00020326; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x0002031e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x00030316; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=127, width=466, height=378
14:41:18 = hWnd = 0x000202d8; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=19a, y=164, width=546, height=363
14:41:18 = hWnd = 0x000202d4; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:41:18 = hWnd = 0x000202de; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:41:18 = hWnd = 0x0003013e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:41:18 = hWnd = 0x000202dc; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x000202d6; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x00030300; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:18 = hWnd = 0x00060372; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:18 = Need to re-create objects.

14:41:18 = s1.

14:41:18 = s2.

14:41:19 = find user name
14:41:19 = Start show animate
14:41:20 = Shell Excutute VerifyHost
14:41:20 = find user name
14:41:22 = find user name
14:41:22 = begin close Process
14:41:22 = Terminate Process
14:41:23 = end close Process
14:41:23 = DLL_PROCESS_DETACH

14:41:30 = Process Attach
14:41:30 = end process attach

14:41:30 = ***** NULL == SampleProvider *****

14:41:30 = ##### Begin waiting Mutex to release process #####

14:41:30 = hWnd = 0x000402c8; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
14:41:30 = hWnd = 0x000302ec; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
14:41:30 = hWnd = 0x0004013e; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=165, width=466, height=378
14:41:30 = hWnd = 0x000402de; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=0, y=0, width=1366, height=768
14:41:30 = hWnd = 0x00030344; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x0004031a; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x0003033c; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x000302cc; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
14:41:30 = hWnd = 0x00040326; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
14:41:30 = hWnd = 0x000700e0; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
14:41:30 = hWnd = 0x00050324; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x000302ca; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x000302b2; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:30 = hWnd = 0x000602ee; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
14:41:30 = Need to re-create objects.

14:41:30 = s1.

14:41:30 = s2.

14:41:30 = find user name
14:41:30 = Start show animate
14:41:32 = Shell Excutute VerifyHost
14:41:32 = find user name
14:41:33 = begin close Process
14:41:33 = Terminate Process
14:41:34 = end close Process
14:41:34 = DLL_PROCESS_DETACH

15:45:40 = Process Attach
15:45:40 = end process attach

15:45:40 = ***** NULL == SampleProvider *****

15:45:40 = ##### Begin waiting Mutex to release process #####

15:45:40 = hWnd = 0x00030498; ClassName: AUTHUI.DLL: LogonUI Logon Window; Title: Windows-Anmeldung.
x=0, y=0, width=1366, height=768
15:45:40 = hWnd = 0x00050450; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
15:45:40 = hWnd = 0x0002042c; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
15:45:40 = hWnd = 0x000b027c; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
15:45:40 = Need to re-create objects.

15:45:40 = s1.

15:45:40 = s2.

15:45:41 = find user name
15:45:41 = Start show animate
15:45:42 = Is Black Sceen wait
15:45:42 = black wait1
15:45:44 = Is Black Sceen wait
15:45:44 = black wait2
15:45:45 = Is Black Sceen wait
15:45:45 = black wait3
15:45:47 = Shell Excutute VerifyHost
15:45:47 = find user name
15:45:47 = find user name
15:45:47 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
16:45:53 = find user name
17:25:38 = Bypass the object creation.

17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:38 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:42 = find user name
17:25:43 = begin close Process
17:25:43 = Terminate Process
17:25:44 = end close Process
17:25:44 = DLL_PROCESS_DETACH

17:29:51 = Process Attach
17:29:51 = end process attach

17:29:51 = ##### Begin waiting Mutex to release process #####

17:29:51 = ***** NULL == SampleProvider *****

17:29:51 = hWnd = 0x0003053c; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
17:29:51 = hWnd = 0x00030528; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
17:29:51 = hWnd = 0x000304e2; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x00030522; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x0002054e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x0003054a; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1ba, y=145, width=466, height=378
17:29:51 = hWnd = 0x0003053a; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=11b, y=84, width=800, height=560
17:29:51 = hWnd = 0x00040520; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
17:29:51 = hWnd = 0x00030546; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
17:29:51 = hWnd = 0x00060496; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
17:29:51 = hWnd = 0x00030542; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x00030538; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x0003053e; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
17:29:51 = hWnd = 0x0003052a; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
17:29:51 = Need to re-create objects.

17:29:51 = s1.

17:29:51 = s2.

17:29:51 = find user name
17:29:51 = Start show animate
17:29:53 = Shell Excutute VerifyHost
17:29:53 = find user name
17:29:54 = begin close Process
17:29:54 = Terminate Process
17:29:55 = end close Process
17:29:55 = DLL_PROCESS_DETACH

18:3:25 = Process Attach
18:3:25 = end process attach

18:3:25 = ***** NULL == SampleProvider *****

18:3:25 = hWnd = 0x001302d4; ClassName: CiceroUIWndFrame; Title: CiceroUIWndFrame.
x=c8, y=200, width=200, height=200
18:3:25 = hWnd = 0x000602dc; ClassName: CiceroUIWndFrame; Title: TF_FloatingLangBar_WndTitle.
x=232, y=0, width=0, height=6
18:3:25 = hWnd = 0x0008030e; ClassName: CtrlNotifySink; Title: .
x=0, y=0, width=0, height=0
18:3:25 = hWnd = 0x00050320; ClassName: #32770; Title: Benutzerkontensteuerung.
x=1c6, y=158, width=466, height=378
18:3:25 = hWnd = 0x000a03b2; ClassName: $$$Secure UAP Background Fake Client Window Class; Title: $$$Secure UAP Background Fake Client Window.
x=1e7, y=276, width=416, height=201
18:3:25 = hWnd = 0x000902d6; ClassName: $$$Secure UAP Background Window Class; Title: $$$Secure UAP Background Window.
x=0, y=0, width=1366, height=768
18:3:25 = hWnd = 0x00060342; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:3:25 = hWnd = 0x0006033e; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:3:25 = hWnd = 0x00060390; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:3:25 = hWnd = 0x000a02d2; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:25 = hWnd = 0x000b02c0; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:25 = hWnd = 0x00070322; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:25 = Need to re-create objects.

18:3:25 = s1.

18:3:25 = s2.

18:3:25 = find user name
18:3:25 = Start show animate
18:3:26 = Shell Excutute VerifyHost
18:3:30 = begin close Process
18:3:30 = Terminate Process
18:3:31 = end close Process
18:3:31 = DLL_PROCESS_DETACH

18:3:58 = Process Attach
18:3:58 = end process attach

18:3:58 = ##### Begin waiting Mutex to release process #####

18:3:58 = hWnd = 0x00070538; ClassName: GDI+ Hook Window Class; Title: GDI+ Window.
x=0, y=0, width=1, height=1
18:3:58 = hWnd = 0x000802dc; ClassName: CicLoaderWndClass; Title: .
x=0, y=0, width=132, height=38
18:3:58 = hWnd = 0x00090316; ClassName: MSCTFIME UI; Title: MSCTFIME UI.
x=0, y=0, width=0, height=0
18:3:58 = hWnd = 0x000902c6; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:58 = hWnd = 0x001502d4; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:58 = hWnd = 0x000802da; ClassName: IME; Title: Default IME.
x=0, y=0, width=0, height=0
18:3:58 = Need to re-create objects.

18:3:58 = s1.

18:3:58 = s2.

18:3:58 = find user name
18:3:58 = Start show animate
18:4:0 = Shell Excutute VerifyHost
18:4:0 = find user name
18:4:0 = find user name
18:4:0 = find user name
18:4:0 = find user name
18:4:0 = begin close Process
18:4:0 = Terminate Process
18:4:1 = end close Process
18:4:1 = DLL_PROCESS_DETACH

Code:

Zoek.exe v5.0.0.1 Updated 12-November-2015
Tool run by Notebook on 15.11.2015 at 14:11:25,98.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Nora\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

15.11.2015 14:12:32 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97    rhino.acme.com          # source server
#      38.25.63.10    x.acme.com              # x client host
 
# localhost name resolution is handled within DNS itself.
127.0.0.1      localhost
::1            localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32004B8A-44A9-43E7-84E9-808838809519} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");

Added to C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Nora\AppData\Roaming\Thunderbird\Profiles\zxuoypxh.default\prefs.js:

Added to C:\Users\Nora\AppData\Roaming\Thunderbird\Profiles\zxuoypxh.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\prefs.js:

Added to C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Notebook\AppData\Roaming\Thunderbird\Profiles\d9933684.default\prefs.js:

Added to C:\Users\Notebook\AppData\Roaming\Thunderbird\Profiles\d9933684.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Uwelchen\AppData\Roaming\Mozilla\Firefox\Profiles\eh4mrhim.default\prefs.js:
user_pref("browser.startup.homepage", "google.de");

Added to C:\Users\Uwelchen\AppData\Roaming\Mozilla\Firefox\Profiles\eh4mrhim.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Uwelchen\AppData\Roaming\Thunderbird\Profiles\0qsprsjc.default\prefs.js:

Added to C:\Users\Uwelchen\AppData\Roaming\Thunderbird\Profiles\0qsprsjc.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Nora\AppData\Roaming\Thunderbird\Profiles\zxuoypxh.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Notebook\AppData\Roaming\Thunderbird\Profiles\d9933684.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Uwelchen\AppData\Roaming\Mozilla\Firefox\Profiles\eh4mrhim.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Uwelchen\AppData\Roaming\Thunderbird\Profiles\0qsprsjc.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\3hw6nczf.default
- Adblock Plus Pop-up Addon - %ProfilePath%\extensions\adblockpopups@jessehakanen.net.xpi
- Ghostery - %ProfilePath%\extensions\firefox@ghostery.com.xpi
- Google Analytics Opt-out Browser Add-on - %ProfilePath%\extensions\{6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}.xpi
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\Notebook\AppData\Roaming\Thunderbird\Profiles\d9933684.default
- Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi

ProfilePath: C:\Users\Uwelchen\AppData\Roaming\Mozilla\Firefox\Profiles\eh4mrhim.default
- Adblock Plus Pop-up Addon - %ProfilePath%\extensions\adblockpopups@jessehakanen.net.xpi
- Ghostery - %ProfilePath%\extensions\firefox@ghostery.com.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\Uwelchen\AppData\Roaming\Thunderbird\Profiles\0qsprsjc.default
- Lightning - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default
2C82D753EF779945977C82A3908DA20A        - C:\windows\SysWOW64\npDeployJava1.dll -        Java Deployment Toolkit 7.0.90.5
1BFD18699636B8F1AA26675BA43D2F8F        - C:\windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll -        Shockwave for Director / Shockwave for Director
F114FBA6246530B89DD1E04351E0EAC5        - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll -        Shockwave Flash
15E298B5EC5B89C5994A59863969D9FF        - C:\windows\SysWOW64\npmproxy.dll -        Microsoft® Windows® Operating System


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
"Start Page"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
"Start Page"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
HKLM\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
HKLM\Wow6432Node\SearchScopes "DefaultScope"=""
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
HKCU\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN_deDE506

==== Reset Google Chrome ======================

Nothing found to reset

==== shortcuts on Users Desktops ======================

C:\Users\Default\Desktop\Cyberlink Power2Go.lnk - C:\Program Files (x86)\Lenovo\Power2Go\Power2Go.exe
C:\Users\Default\Desktop\OneKey Recovery.lnk - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\OneKey Recovery.exe
C:\Users\Default User\Desktop\Cyberlink Power2Go.lnk - C:\Program Files (x86)\Lenovo\Power2Go\Power2Go.exe
C:\Users\Default User\Desktop\OneKey Recovery.lnk - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\OneKey Recovery.exe
C:\Users\Nora\Desktop\Avira PC Cleaner.lnk - C:\Users\Notebook\AppData\Local\Temp\cleaner\avwebloader.exe
C:\Users\Nora\Desktop\Cyberlink Power2Go.lnk - C:\Program Files (x86)\Lenovo\Power2Go\Power2Go.exe
C:\Users\Nora\Desktop\Entfernen des Avira PC Cleaners.lnk - C:\Users\Notebook\AppData\Local\Temp\cleaner\cleaner-install.exe /remove
C:\Users\Nora\Desktop\OneKey Recovery.lnk - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\OneKey Recovery.exe
C:\Users\Nora\Desktop\Uni\Handout - interkulturelle Erziehung und Pädagogik - Verknüpfung.lnk - C:\Users\Nora\Documents\Handout - interkulturelle Erziehung und Pädagogik.docx
C:\Users\Notebook\Desktop\Cyberlink Power2Go.lnk - C:\Program Files (x86)\Lenovo\Power2Go\Power2Go.exe
C:\Users\Notebook\Desktop\Download Zusammenfassung.lnk - C:\Users\Notebook\AppData\Local\SpaceKace\Setup_FileViewPro_[2015_Editi\Setup_FileViewPro_[2015_Edition].exe
C:\Users\Notebook\Desktop\OneKey Recovery.lnk - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\OneKey Recovery.exe
C:\Users\Uwelchen\Desktop\Adobe Reader XI.lnk - C:\windows\Installer\{AC76BA86-7AD7-1031-7B44-AB0000000001}\SC_Reader.ico
C:\Users\Uwelchen\Desktop\Microsoft Word 2010.lnk - C:\windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\wordicon.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe
C:\Users\Public\Desktop\Free DWG Viewer.lnk - C:\Program Files (x86)\IGC\Free DWG Viewer\FreeDWGViewer.exe
C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Public\Desktop\Microsoft Security Essentials.lnk - C:\Program Files (x86)\Microsoft Security Client\msseces.exe
C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Public\Desktop\Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Energy Management\Help file.Lnk - C:\Program Files (x86)\Lenovo\Energy Management\Deu.chm
C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Energy Management\Power management options.Lnk - C:\Program Files (x86)\Lenovo\Energy Management\Open EnergyManagement.exe
C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr
C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Energy Management\Help file.Lnk - C:\Program Files (x86)\Lenovo\Energy Management\Deu.chm
C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Energy Management\Power management options.Lnk - C:\Program Files (x86)\Lenovo\Energy Management\Open EnergyManagement.exe
C:\Users\Uwelchen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Energy Management\Help file.Lnk - C:\Program Files (x86)\Lenovo\Energy Management\Deu.chm
C:\Users\Uwelchen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Energy Management\Power management options.Lnk - C:\Program Files (x86)\Lenovo\Energy Management\Open EnergyManagement.exe

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free DWG Viewer\Free DWG Viewer Help.lnk - C:\Program Files (x86)\IGC\Free DWG Viewer\BravaActiveX.DWG_ENU.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free DWG Viewer\Free DWG Viewer.lnk - C:\Program Files (x86)\IGC\Free DWG Viewer\FreeDWGViewer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware entfernen.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Nora\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Nora\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Nora\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Nora\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Nora\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Users\Nora\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Nora\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\windows\system32\control.exe
C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Uwelchen\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Uwelchen\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Uwelchen\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Uwelchen\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Users\Uwelchen\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyEnable"=dword:00000000

Value(s) after fix:
"ProxyEnable"=dword:00000000

==== Reset WMI ======================

Die folgenden Dienste h„ngen vom Dienst Windows-Verwaltungsinstrumentation ab.
Das Beenden des Dienstes Windows-Verwaltungsinstrumentation beendet auch diese Dienste.

  Sicherheitscenter
  IP-Hilfsdienst
  Intel(R) Rapid Storage Technology

Sicherheitscenter wird beendet.
Sicherheitscenter wurde erfolgreich beendet.

IP-Hilfsdienst wird beendet.
IP-Hilfsdienst wurde erfolgreich beendet.

Intel(R) Rapid Storage Technology wird beendet.
Intel(R) Rapid Storage Technology wurde erfolgreich beendet.

Windows-Verwaltungsinstrumentation wird beendet.
Windows-Verwaltungsinstrumentation wurde erfolgreich beendet.

C:\windows\system32\wbem\repository renamed to repository.old
C:\windows\syswow64\wbem\repository renamed to repository.old

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)


M-K-D-B 16.11.2015 15:15

Servus,


nochmal HitmanPro und FRST bitte:



Schritt 1
Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
  • Starte die HitmanPro.exe
  • Klicke auf
  • Entferne den Haken bei
  • Klicke auf
    und
  • Akzeptiere die Lizenzbedingungen und klicke auf
  • Klicke auf

    und auf
  • Wenn der Scan beendet wurde, nichts löschen lassen etc. sondern wähle unten links auf der Button-Leiste
    und speichere die Logdatei auf Deinem Desktop.
  • Schließe HitmanPro und poste mir das Log.

 











Schritt 2
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Untersuchen.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei von HitmanPro,
  • die beiden neuen Logdateien von FRST.

nora.s 16.11.2015 17:48

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hallo Mathias!
Seit dem letzten Mal läuft der PC schon wieder viel besser :) Der Adobe Reader öffnet die Dateien wieder richtig und die Interneteinstellungen funktionieren auch wieder..

Die Hitman Textdatei konnte ich wieder nicht auf dem Desktop speicher, jedoch auf dem Stick. Hoffe das ist auch in Ordnung..

Hier die Dateien:

Code:


       
Code:

       
HitmanPro 3.7.10.251
www.hitmanpro.com

   Computer name . . . . : NOTEBOOK-PC
   Windows . . . . . . . : 6.1.1.7601.X64/2
   User name . . . . . . : Notebook-PC\Notebook
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Free

   Scan date . . . . . . : 2015-11-16 17:19:44
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 7m 15s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 23

   Objects scanned . . . : 1.623.781
   Files scanned . . . . : 37.320
   Remnants scanned  . . : 367.272 files / 1.219.189 keys

Suspicious files ____________________________________________________________

   C:\Users\Nora\Desktop\Downloads\FRST64.exe
      Size . . . . . . . : 2.198.528 bytes
      Age  . . . . . . . : 4.3 days (2015-11-12 11:17:50)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 6E8BF313C850728328088C2DC10FB5369B9C938F71F58EC7EB8D51374EB1CA51
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.


Potential Unwanted Programs _________________________________________________

   HKLM\SOFTWARE\Classes\Interface\{0510789C-5E5D-4FA3-A3EF-2D56FDE5090A}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{1E34EA93-600B-4CBC-9858-59BE04C1A581}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{32CC4D2E-999C-4853-9D3E-5DE4C02D57C6}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{34A117AD-7F43-4859-BF97-ADC46488953F}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{5A06A37E-F036-42EC-9D51-E738FACBFEB5}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{7007FA4C-E372-4485-ADFA-213B9E38D87F}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{7AE769DF-F151-4541-B820-031726E76E06}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{844C2331-94DF-431E-9A67-426ED861D27F}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{8684A596-308C-4872-ACA7-FF6093BBEEF7}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{934063FB-A81D-4849-B02C-478446DF3219}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{93A55DA3-83ED-4090-91B6-904C44647639}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{993161E3-CF87-46CF-A702-3FD05D3DEDDD}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{9DFFAA5F-44C6-4FF2-80EE-76368D0A2E75}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{AA8714C4-294D-47FB-BCE0-BC12445CFBD4}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{B34A6A15-1F6F-4A19-A9DD-8B44C874A20B}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{C242AC08-2AE7-46A5-A62D-E7F1B9BE489C}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{F3EC3AFF-8FD8-4253-ABA2-F2ABE0A5524A}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{F85503FF-ED21-4493-9A4A-B6765EB45D94}\ (TelevisionFanatic)
   HKLM\SOFTWARE\Classes\Interface\{FEEAF56C-C91B-4D1C-9FC8-BAFD85F5F2B3}\ (TelevisionFanatic)
   HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Program Files (x86)\Mobogenie\ (Rocketfuel)
   HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QSqlDriverFactoryInterface:\C:\Program Files (x86)\Mobogenie\ (Rocketfuel)
   HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Program Files (x86)\Mobogenie\ (Rocketfuel)



Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
durchgeführt von Notebook (Administrator) auf NOTEBOOK-PC (16-11-2015 17:31:28)
Gestartet von E:\
Geladene Profile: Notebook & Nora & Uwelchen (Verfügbare Profile: Notebook & Nora & Uwelchen)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
() C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2012-05-23] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2012-05-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2012-05-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-05-23] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-10-05] (Malwarebytes)
HKLM-x32\...\runonceex: [Flags] => 8
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[C10].txt
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\MountPoints2: {72c6dce6-520b-11e3-9d67-446d57e77fa7} - E:\LaunchU3.exe -a
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll [2012-05-23] ()
Startup: C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2015-11-12]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2013-12-06]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0434AB00-3F7C-4291-91FB-BFB1A7FBC4E6}: [DhcpNameServer] 10.63.210.254
Tcpip\..\Interfaces\{0EA6BB07-2FF3-4059-B5F3-5A19971BFC92}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-1146881843-1855949487-4122649668-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-1146881843-1855949487-4122649668-1003\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-1146881843-1855949487-4122649668-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN_deDE506
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1003 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-10-21] (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-10-21] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)

FireFox:
========
FF ProfilePath: C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Session Restore: -> ist aktiviert.
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\windows\system32\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-15] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [296400 2009-03-03] ()

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-14] (Malwarebytes)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
U3 BcmSqlStartupSvc; kein ImagePath
U2 CLKMSVC10_3A60B698; kein ImagePath
U2 CLKMSVC10_C3B3B687; kein ImagePath
U2 DriverService; kein ImagePath
U2 iATAgentService; kein ImagePath
U2 idealife Update Service; kein ImagePath
U3 IGRS; kein ImagePath
U2 IviRegMgr; kein ImagePath
U2 nvUpdatusService; kein ImagePath
U2 Oasis2Service; kein ImagePath
U2 PCCarerService; kein ImagePath
U2 ReadyComm.DirectRouter; kein ImagePath
U2 RichVideo; kein ImagePath
U2 RtLedService; kein ImagePath
U2 SoftwareService; kein ImagePath
U3 SQLWriter; kein ImagePath
U2 Stereo Service; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-16 17:27 - 2015-11-16 17:27 - 00008286 _____ C:\Users\Notebook\Desktop\HitmanPro_20151116_1727.log
2015-11-16 17:17 - 2015-11-16 17:17 - 11337112 _____ (SurfRight B.V.) C:\Users\Nora\Desktop\HitmanPro_x64.exe
2015-11-16 12:46 - 2015-11-16 12:46 - 00003408 ____N C:\bootsqm.dat
2015-11-15 18:10 - 2015-11-16 17:31 - 00013271 _____ C:\FaceProv.log
2015-11-15 14:34 - 2015-11-15 14:34 - 00008288 _____ C:\Users\Notebook\Desktop\HitmanPro_20151115_1434.log
2015-11-15 14:34 - 2015-11-15 14:34 - 00007386 _____ C:\Users\Notebook\Desktop\HitmanPro_20151115_1433.xml
2015-11-15 14:33 - 2015-11-15 14:33 - 00008288 _____ C:\Users\Notebook\Desktop\HitmanPro_20151115_1433.log
2015-11-15 14:20 - 2015-11-15 14:35 - 00000000 ____D C:\ProgramData\HitmanPro
2015-11-15 14:15 - 2015-11-15 14:15 - 23664130 _____ C:\windows\repository.backup
2015-11-15 14:15 - 2015-11-15 14:11 - 00024064 _____ C:\windows\zoek-delete.exe
2015-11-15 14:11 - 2015-11-15 14:11 - 00000000 ____D C:\zoek_backup
2015-11-15 14:09 - 2015-11-16 17:22 - 00000000 ____D C:\Users\Nora\Desktop\TxtDokumente
2015-11-15 14:00 - 2015-11-15 14:00 - 01309184 _____ C:\Users\Nora\Desktop\zoek.exe
2015-11-14 21:46 - 2015-11-14 21:46 - 00001074 _____ C:\Users\Notebook\Desktop\JRT.txt
2015-11-14 21:43 - 2015-10-05 23:26 - 01801288 _____ (Malwarebytes) C:\Users\Notebook\Desktop\JRT.exe
2015-11-14 17:38 - 2015-11-14 17:39 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-14 17:38 - 2015-11-14 17:38 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-14 17:38 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2015-11-14 17:38 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-11-14 17:38 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2015-11-14 17:25 - 2015-11-14 17:25 - 01798976 _____ (Malwarebytes) C:\Users\Nora\Desktop\JRT.exe
2015-11-14 17:24 - 2015-11-14 17:25 - 22908888 _____ (Malwarebytes ) C:\Users\Nora\Desktop\mbam-setup-2.2.0.1024.exe
2015-11-14 17:18 - 2015-11-14 17:18 - 01729536 _____ C:\Users\Nora\Desktop\AdwCleaner_5.020.exe
2015-11-13 16:28 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe
2015-11-13 16:28 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe
2015-11-13 16:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe
2015-11-13 16:21 - 2015-11-13 16:22 - 00000000 ____D C:\Qoobox
2015-11-13 16:20 - 2015-11-13 16:38 - 00000000 ____D C:\windows\erdnt
2015-11-12 16:58 - 2015-11-12 16:58 - 00059877 _____ C:\Users\Notebook\Desktop\FRST.txt
2015-11-12 16:43 - 2015-11-12 16:43 - 00000000 ____D C:\Users\Notebook\AppData\Local\GWX
2015-11-12 12:28 - 2015-11-12 12:28 - 00000000 ____D C:\Users\Nora\Documents\OneNote-Notizbücher
2015-11-12 12:20 - 2015-11-12 12:21 - 00004120 _____ C:\Users\Notebook\Desktop\gmertxt.log
2015-11-12 12:06 - 2015-11-12 12:06 - 00280320 _____ C:\windows\Minidump\111215-26395-01.dmp
2015-11-12 11:18 - 2015-11-16 17:31 - 00000000 ____D C:\FRST
2015-11-12 11:17 - 2015-11-12 11:17 - 00000000 _____ C:\Users\Notebook\defogger_reenable
2015-11-12 10:52 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-11-11 17:49 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-11-11 17:49 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-11-11 17:49 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-11-11 17:49 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-11-11 17:49 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-11-11 17:49 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-11-11 17:49 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-11-11 17:49 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-11-11 17:49 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-11-11 17:49 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-11-11 17:49 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-11-11 17:49 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-11-11 17:49 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-11-11 17:49 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-11-11 17:49 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-11-11 17:49 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-11-11 17:49 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-11-11 17:49 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-11-11 17:49 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-11-11 17:49 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-11-11 17:49 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-11-11 17:49 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-11-11 17:49 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-11-11 17:49 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-11-11 17:49 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-11-11 17:49 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-11-11 17:49 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-11-11 17:48 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-11-11 17:48 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-11-11 17:48 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-11-11 17:48 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-11-11 17:48 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-11-11 17:48 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-11-11 17:48 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-11-11 17:48 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-11-11 17:48 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-11-11 17:48 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-11-11 17:48 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-11-11 17:48 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-11-11 17:48 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-11-11 17:48 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2015-11-11 17:48 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\jnwmon.dll
2015-11-11 17:46 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2015-11-11 17:45 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-11-11 17:45 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-11-11 17:40 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\windows\system32\aelupsvc.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-11-11 17:40 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-11-11 17:39 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-11-10 15:06 - 2015-11-10 15:06 - 00280320 _____ C:\windows\Minidump\111015-24726-01.dmp
2015-11-07 19:23 - 2015-11-07 19:23 - 00280320 _____ C:\windows\Minidump\110715-27315-01.dmp
2015-11-06 21:49 - 2015-11-07 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-05 09:25 - 2015-11-05 09:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-16 17:30 - 2012-05-23 02:58 - 00699440 _____ C:\windows\system32\perfh007.dat
2015-11-16 17:30 - 2012-05-23 02:58 - 00149548 _____ C:\windows\system32\perfc007.dat
2015-11-16 17:30 - 2009-07-14 06:13 - 01619700 _____ C:\windows\system32\PerfStringBackup.INI
2015-11-16 17:28 - 2009-07-14 04:20 - 00000000 ____D C:\windows\tracing
2015-11-16 17:15 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-16 17:15 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-16 17:10 - 2012-05-23 11:17 - 01800201 _____ C:\windows\WindowsUpdate.log
2015-11-16 17:06 - 2012-10-24 14:24 - 00065536 _____ C:\windows\system32\Ikeext.etl
2015-11-16 17:06 - 2012-05-23 12:12 - 00204435 _____ C:\windows\system32\fastboot.set
2015-11-16 17:06 - 2012-05-23 12:11 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-16 17:06 - 2012-05-23 12:03 - 00000000 ____D C:\ProgramData\VeriFace
2015-11-16 17:06 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-11-16 17:05 - 2014-02-23 22:07 - 00110698 _____ C:\windows\setupact.log
2015-11-16 14:42 - 2012-10-21 11:18 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-11-16 14:06 - 2012-05-23 12:11 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-15 19:00 - 2014-10-07 20:27 - 00000000 ____D C:\Users\Uwelchen
2015-11-15 14:41 - 2012-08-30 14:16 - 00000000 ____D C:\Users\Notebook
2015-11-15 14:17 - 2014-03-19 12:38 - 42562106 _____ C:\windows\system32\PsBoot.log
2015-11-15 14:17 - 2014-02-23 22:06 - 00155978 _____ C:\windows\PFRO.log
2015-11-15 14:16 - 2014-03-19 12:38 - 00000000 _____ C:\windows\system32\defragLog.log
2015-11-15 13:32 - 2014-03-19 13:39 - 00000000 ____D C:\AdwCleaner
2015-11-15 12:26 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2015-11-14 18:04 - 2009-07-14 06:32 - 00000000 ____D C:\windows\addins
2015-11-14 17:30 - 2013-12-18 12:54 - 00000000 ____D C:\Users\Nora
2015-11-14 14:47 - 2015-03-17 11:18 - 00000000 ____D C:\Users\Nora\Desktop\Uwe
2015-11-13 16:37 - 2014-06-14 21:18 - 00000000 ____D C:\Users\Notebook\AppData\Local\Adobe
2015-11-13 09:03 - 2009-07-14 06:08 - 00032632 _____ C:\windows\Tasks\SCHEDLGU.TXT
2015-11-12 16:39 - 2009-07-14 05:45 - 00337808 _____ C:\windows\system32\FNTCACHE.DAT
2015-11-12 12:06 - 2014-07-24 11:21 - 00000000 ____D C:\windows\Minidump
2015-11-12 12:06 - 2014-07-24 11:20 - 1018855042 _____ C:\windows\MEMORY.DMP
2015-11-11 18:49 - 2012-10-21 17:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 18:42 - 2012-10-21 11:18 - 00780488 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-11-11 18:42 - 2012-10-21 11:18 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-11 18:42 - 2012-10-21 11:18 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-11-11 18:41 - 2011-09-29 04:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 17:32 - 2014-02-26 12:38 - 01593980 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2015-11-07 17:43 - 2012-10-21 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-30 06:22 - 2015-07-10 18:40 - 00003886 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2015-10-18 10:35 - 2014-01-31 14:51 - 00000000 ____D C:\Users\Nora\Desktop\Uni Praktikum

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2013-04-05 17:01 - 2013-04-05 17:01 - 0002528 _____ () C:\Users\Notebook\AppData\Roaming\$_hpcst$.hpc
2014-01-29 13:34 - 2014-01-29 13:34 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-11-15 12:19

==================== Ende von FRST.txt ============================

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:07-11-2015
durchgeführt von Notebook (2015-11-16 17:32:09)
Gestartet von E:\
Windows 7 Home Premium Service Pack 1 (X64) (2012-08-30 13:16:26)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-1146881843-1855949487-4122649668-500 - Administrator - Disabled)
Gast (S-1-5-21-1146881843-1855949487-4122649668-501 - Limited - Disabled)
Nora (S-1-5-21-1146881843-1855949487-4122649668-1001 - Limited - Enabled) => C:\Users\Nora
Notebook (S-1-5-21-1146881843-1855949487-4122649668-1000 - Administrator - Enabled) => C:\Users\Notebook
Uwelchen (S-1-5-21-1146881843-1855949487-4122649668-1003 - Limited - Enabled) => C:\Users\Uwelchen

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.7.637 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
Benutzerhandbuch (x32 Version: 1.0.0.6 - Lenovo) Hidden
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CBR (HKLM\...\{A8305DB2-3F6A-43CF-8CE3-EFD3D0F1C352}) (Version: 0.7 - G.Waser)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.2.3442 - CDBurnerXP)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.4.51 - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.0 - Lenovo)
Energy Management (x32 Version: 6.0.2.0 - Lenovo) Hidden
Free DWG Viewer 7.3 (HKLM-x32\...\{16CF668C-104D-479F-88A9-739137AEF3AD}) (Version: 7.3.0.176 - IGC)
GeoGebra 4.4 (HKLM-x32\...\GeoGebra 4.4) (Version: 4.4.6.0 - International GeoGebra Institute)
Google Chrome (HKLM-x32\...\{73187774-F274-39D6-80A4-33778B3CBBD4}) (Version: 65.51.16478 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
HP Deskjet 1000 J110 series - Grundlegende Software für das Gerät (HKLM\...\{CED47C99-8892-4956-BCA7-CC3123531371}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1000 J110 series Hilfe (HKLM-x32\...\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3341 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 9 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.10.1209.1 - Lenovo EasyCamera)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo Games Console (HKLM-x32\...\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3728 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden
Lexmark S410 Series Deinstallationsprogamm (HKLM\...\Lexmark S410 Series) (Version:  - Lexmark International, Inc.)
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
Mozilla Thunderbird 31.7.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 de)) (Version: 31.7.0 - Mozilla)
Mozilla Thunderbird 38.2.0 (x86 de) (HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\Mozilla Thunderbird 38.2.0 (x86 de)) (Version: 38.2.0 - Mozilla)
Mozilla Thunderbird 38.3.0 (x86 de) (HKU\S-1-5-21-1146881843-1855949487-4122649668-1003\...\Mozilla Thunderbird 38.3.0 (x86 de)) (Version: 38.3.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.0 - Frank Heindörfer, Philip Chinery)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10003 - Realtek Semiconductor Corp.)
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version:  - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Studie zur Verbesserung von HP Deskjet 1000 J110 series Produkten (HKLM\...\{28F4BC72-75AE-47DD-B5B3-2A027BCA48A7}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.0.0 - Synaptics Incorporated)
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.14563 - TeamViewer)
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo)
Verbindungsassistent (HKLM-x32\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent)
VeriFace (HKLM-x32\...\VeriFace) (Version: 4.0.0.1224 - Lenovo)
VLC media player 2.0.4 (HKLM-x32\...\VLC media player) (Version: 2.0.4 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Wiederherstellungspunkte =========================

08-11-2015 20:31:36 Windows-Sicherung
09-11-2015 22:00:44 Windows Update
11-11-2015 12:41:21 Windows Update
11-11-2015 17:21:37 Windows Update
11-11-2015 18:40:28 Windows Update
12-11-2015 14:53:27 Windows Update
14-11-2015 18:12:10 JRT Pre-Junkware Removal
14-11-2015 21:37:48 JRT Pre-Junkware Removal
14-11-2015 21:43:11 JRT Pre-Junkware Removal
15-11-2015 14:12:24 zoek.exe restore point
15-11-2015 14:34:41 Prüfpunkt von HitmanPro
16-11-2015 13:01:01 Windows Update

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2015-11-15 14:12 - 00000841 ____A C:\windows\system32\Drivers\etc\hosts

 127.0.0.1      localhost
::1            localhost

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {0193F86E-DCBA-4717-984F-AAED2657012C} - System32\Tasks\{58CA7212-3668-4514-BF70-A38EF0598722} => pcalua.exe -a F:\Install.exe -d F:\
Task: {05871FC2-EF84-4424-BD51-9E9784F25D1F} - System32\Tasks\HpWebReg.exe => C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\HpWebReg.exe
Task: {06839B91-58C1-43B2-AE96-615A676350F7} - System32\Tasks\{561E282B-989B-43CF-9923-7E78F5100D85} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {1AA4CBE5-A1A1-4E11-96FF-D3DA11C5C67F} - System32\Tasks\{6E897720-0C00-426B-82A9-06A27072CBE8} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2015-11-05] (Mozilla Corporation)
Task: {1AE35477-E386-4ED0-B716-C799EEAF3CB7} - System32\Tasks\{3C4A0741-2782-49C1-B191-6DD27182317B} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {1C4D16D4-59A3-4E90-8322-C42381835A6B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {2619407E-888E-4EDB-9CE9-7900016E616C} - \HQ-Video-Profession-1.3-firefoxinstaller -> Keine Datei <==== ACHTUNG
Task: {39607F30-B624-48CA-8B74-B64E766204B9} - System32\Tasks\HPCustParticipation HP Deskjet 1000 J110 series => C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
Task: {424B4465-B5BC-419C-AFE9-BDA0BE1CD8ED} - \HQ-Video-Profession-1.3-codedownloader -> Keine Datei <==== ACHTUNG
Task: {4481CAAD-E5FF-4DBC-B33A-485DD1E033AB} - \HQ-Video-Profession-1.3-enabler -> Keine Datei <==== ACHTUNG
Task: {53FB169C-39A0-4725-8274-49E0E8AE700F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {54BAB1DA-AAD2-480D-A51B-2789094B968F} - System32\Tasks\{B33CE333-4158-42C2-A582-ACC2CD8B4AB7} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2015-11-05] (Mozilla Corporation)
Task: {5A749EF4-BEEB-41AB-BB09-09E906F144D9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {66168DDB-F850-4953-8BBA-6CDDE814EDB1} - \HQ-Video-Profession-1.3-chromeinstaller -> Keine Datei <==== ACHTUNG
Task: {72CCA424-D111-4F99-AFF8-A5D8C3352C89} - \MediaPlayerEnhance-enabler -> Keine Datei <==== ACHTUNG
Task: {73634F6A-9129-42B3-81CF-310EE8F0857A} - \MediaPlayerEnhance-codedownloader -> Keine Datei <==== ACHTUNG
Task: {73FCE9BB-49FA-4071-AD14-1CAD5E829A43} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29] (CyberLink)
Task: {79CEC219-88D1-49B9-9BFB-F6AABB262CC6} - \MediaPlayerEnhance-firefoxinstaller -> Keine Datei <==== ACHTUNG
Task: {7F31B36B-C59C-422E-B4AF-24CFC4B301C8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {8841015E-BB01-4BB5-B20E-F48C76D70890} - System32\Tasks\{941C066D-C974-4F3B-8FB9-C313C1B1E452} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {8D3ECFEB-ECC6-43C7-9FD1-6167CEBE303A} - System32\Tasks\{DD783E30-083B-47F0-BD39-C0DDA32A49E5} => pcalua.exe -a "C:\Program Files (x86)\Verbindungsassistent\Uninstaller.exe"
Task: {A1EB24AA-BBC1-4663-B6AE-C8687A2FDA4F} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated)
Task: {B432F1D6-FBFA-4641-836A-6D21416BE178} - \MediaPlayerEnhance-chromeinstaller -> Keine Datei <==== ACHTUNG
Task: {C701C00E-FF7B-424B-983A-3386728205B3} - System32\Tasks\{3D5593A9-5F78-4469-B743-0BD6634616C8} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2015-11-05] (Mozilla Corporation)
Task: {D9E7D8F2-A3D2-4CCF-A63C-DFB19020869B} - \HQ-Video-Profession-1.3-updater -> Keine Datei <==== ACHTUNG
Task: {DBCE4CED-3DB9-46B7-A285-39BCC483CD7C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {E4C899FF-E8F7-4AF1-A6A7-A04010BC08CB} - \MediaPlayerEnhance-updater -> Keine Datei <==== ACHTUNG

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2012-05-23 12:03 - 2012-05-23 12:03 - 01508192 _____ () C:\windows\system32\IcnOvrly.dll
2012-05-23 12:03 - 2012-05-23 12:03 - 00628064 _____ () C:\windows\system32\SimpleExt.dll
2008-12-20 04:20 - 2012-05-23 12:15 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2008-12-20 04:20 - 2012-05-23 12:15 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2012-05-23 11:36 - 2011-03-25 10:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-10-23 17:07 - 2009-03-03 11:45 - 00296400 ____N () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
2014-02-12 19:58 - 2014-02-12 19:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 19:58 - 2014-02-12 19:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-05-23 12:03 - 2012-05-23 12:03 - 00013664 _____ () C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
2014-10-16 21:04 - 2014-10-16 21:04 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\17c296575fad30d021e6370dc70cf800\IsdiInterop.ni.dll
2012-05-23 11:35 - 2011-02-18 09:16 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\ProgramData\Temp:373E1720

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-1146881843-1855949487-4122649668-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Uwelchen\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{C06D5DF8-3461-4042-8F52-7EBCDE9FE5EB}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{A01CE26B-13D2-49C9-A92D-9B7D46120EAD}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{23CFB686-0B7E-4480-A9A3-CB0C2F765BAA}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{85C74DA7-449E-44C7-8E4E-1F4912152D42}] => (Allow) LPort=2869
FirewallRules: [{877B58CB-8D65-442A-8AF5-5FA372C19F10}] => (Allow) LPort=1900
FirewallRules: [{8D40A53C-4335-417B-9C4A-CB4692B6701D}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{17F942C8-12AD-4AA5-9463-4D84ED86C64F}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{494CA055-1977-42EC-B8BF-AE2174875BDB}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{7FB6858F-ED36-454A-8F9F-DF9A80AA76BF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{58AE4ECC-80E0-4F0D-BDC7-2CC30B8636BE}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{5C3FAB83-0355-4B03-8DC1-B8E0A07D7802}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{0C353832-0069-4E0E-9DC5-C406A89ED5BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C3FD3DA4-E429-4DDB-8AF6-37BB69E5EC76}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{DB0BA175-6DF7-49FB-BC0E-EB66246A1ACB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CD7CBA5A-1320-4B8A-86ED-D18730A7E38D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6DCD0473-2BF8-47E3-9577-F22D90E33E6C}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{1848B09C-A7F2-4E06-84AF-903D2D0CFCF1}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{600BE599-5822-48F3-B869-82DC5C62233C}] => (Allow) C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\USBSetup.exe
FirewallRules: [{795730CF-A64E-4915-8384-9C4A4D8606B1}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS0049\HPDiagnosticCoreUI.exe
FirewallRules: [{96963478-4C91-4FAA-A42F-C0519527DA88}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS0049\HPDiagnosticCoreUI.exe
FirewallRules: [{66F54DF8-0774-4E55-800F-073B4E8BB050}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS5C88\HPDiagnosticCoreUI.exe
FirewallRules: [{58ED8715-7D7E-4764-A2F4-1DC940D46FB9}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS5C88\HPDiagnosticCoreUI.exe
FirewallRules: [{2CF02080-21D3-4222-81D1-30FAE88FA2F6}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{E2CA7EE2-6A42-4951-B9E5-9C5E1FF1376A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A7998D86-49F1-4F44-886A-7F2D4CAE5C0A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{5488F4E7-619C-40F9-867A-5BE99F507EB9}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{4429A93B-8E63-407C-9B8A-3187FFC606B1}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{0F6DDD45-F3D6-43D5-B986-E7E4425ED8D6}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{6A2A115F-CFA8-4679-9084-9FDE758DE08E}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [{364D57E1-9EF3-4CC4-AA8F-B0113BACBDBD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DCD7E537-A65D-45B1-A414-9576213BC1E8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{193C3EDE-369F-49A2-A07D-C92D79A23A67}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (11/15/2015 08:17:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 16068

Error: (11/15/2015 08:17:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 16068

Error: (11/15/2015 08:17:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (11/15/2015 07:00:19 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Alle in der Sicherung enthaltenen Laufwerke wurden ausgelassen. Vergewissern Sie sich, dass die Laufwerke angeschlossen und funktionsfähig sind. (0x810000FF)"

Error: (11/15/2015 06:41:35 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/15/2015 06:07:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/15/2015 06:07:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/15/2015 04:46:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15741

Error: (11/15/2015 04:46:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15741

Error: (11/15/2015 04:46:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


Systemfehler:
=============
Error: (11/16/2015 05:28:53 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (11/16/2015 05:28:52 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (11/16/2015 05:28:52 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (11/16/2015 05:28:51 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (11/15/2015 06:04:54 PM) (Source: Ntfs) (EventID: 55) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "\Device\HarddiskVolume2" den Befehl "chkdsk" aus.

Error: (11/15/2015 05:52:12 PM) (Source: Ntfs) (EventID: 55) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "\Device\HarddiskVolume2" den Befehl "chkdsk" aus.

Error: (11/15/2015 05:52:12 PM) (Source: Ntfs) (EventID: 55) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "\Device\HarddiskVolume2" den Befehl "chkdsk" aus.

Error: (11/15/2015 05:52:12 PM) (Source: Ntfs) (EventID: 55) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "\Device\HarddiskVolume2" den Befehl "chkdsk" aus.

Error: (11/15/2015 05:52:12 PM) (Source: Ntfs) (EventID: 55) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "\Device\HarddiskVolume2" den Befehl "chkdsk" aus.

Error: (11/15/2015 05:52:12 PM) (Source: Ntfs) (EventID: 55) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "\Device\HarddiskVolume2" den Befehl "chkdsk" aus.


CodeIntegrity:
===================================
  Date: 2015-11-13 16:37:33.753
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-11-13 16:37:33.675
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Pentium(R) CPU B960 @ 2.20GHz
Prozentuale Nutzung des RAM: 23%
Installierter physikalischer RAM: 8135.86 MB
Verfügbarer physikalischer RAM: 6236.27 MB
Summe virtueller Speicher: 16269.93 MB
Verfügbarer virtueller Speicher: 14429.66 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:254.14 GB) (Free:173.14 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:26.82 GB) NTFS
Drive e: () (Removable) (Total:7.37 GB) (Free:4.51 GB) FAT32

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 68E1532F)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=254.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7.4 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7.4 GB) - (Type=0B)

==================== Ende von Addition.txt ============================


M-K-D-B 17.11.2015 14:25

Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:

start
CloseProcesses:
HKLM-x32\...\runonceex: [Flags] => 8
Task: {0193F86E-DCBA-4717-984F-AAED2657012C} - System32\Tasks\{58CA7212-3668-4514-BF70-A38EF0598722} => pcalua.exe -a F:\Install.exe -d F:\
Task: {06839B91-58C1-43B2-AE96-615A676350F7} - System32\Tasks\{561E282B-989B-43CF-9923-7E78F5100D85} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {1AE35477-E386-4ED0-B716-C799EEAF3CB7} - System32\Tasks\{3C4A0741-2782-49C1-B191-6DD27182317B} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {2619407E-888E-4EDB-9CE9-7900016E616C} - \HQ-Video-Profession-1.3-firefoxinstaller -> Keine Datei <==== ACHTUNG
Task: {424B4465-B5BC-419C-AFE9-BDA0BE1CD8ED} - \HQ-Video-Profession-1.3-codedownloader -> Keine Datei <==== ACHTUNG
Task: {4481CAAD-E5FF-4DBC-B33A-485DD1E033AB} - \HQ-Video-Profession-1.3-enabler -> Keine Datei <==== ACHTUNG
Task: {66168DDB-F850-4953-8BBA-6CDDE814EDB1} - \HQ-Video-Profession-1.3-chromeinstaller -> Keine Datei <==== ACHTUNG
Task: {72CCA424-D111-4F99-AFF8-A5D8C3352C89} - \MediaPlayerEnhance-enabler -> Keine Datei <==== ACHTUNG
Task: {73634F6A-9129-42B3-81CF-310EE8F0857A} - \MediaPlayerEnhance-codedownloader -> Keine Datei <==== ACHTUNG
Task: {79CEC219-88D1-49B9-9BFB-F6AABB262CC6} - \MediaPlayerEnhance-firefoxinstaller -> Keine Datei <==== ACHTUNG
Task: {8841015E-BB01-4BB5-B20E-F48C76D70890} - System32\Tasks\{941C066D-C974-4F3B-8FB9-C313C1B1E452} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {B432F1D6-FBFA-4641-836A-6D21416BE178} - \MediaPlayerEnhance-chromeinstaller -> Keine Datei <==== ACHTUNG
Task: {D9E7D8F2-A3D2-4CCF-A63C-DFB19020869B} - \HQ-Video-Profession-1.3-updater -> Keine Datei <==== ACHTUNG
Task: {E4C899FF-E8F7-4AF1-A6A7-A04010BC08CB} - \MediaPlayerEnhance-updater -> Keine Datei <==== ACHTUNG
C:\Program Files (x86)\Uniblue
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{0510789C-5E5D-4FA3-A3EF-2D56FDE5090A}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{1E34EA93-600B-4CBC-9858-59BE04C1A581}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{32CC4D2E-999C-4853-9D3E-5DE4C02D57C6}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{34A117AD-7F43-4859-BF97-ADC46488953F}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{5A06A37E-F036-42EC-9D51-E738FACBFEB5}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{7007FA4C-E372-4485-ADFA-213B9E38D87F}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{7AE769DF-F151-4541-B820-031726E76E06}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{844C2331-94DF-431E-9A67-426ED861D27F}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{8684A596-308C-4872-ACA7-FF6093BBEEF7}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{934063FB-A81D-4849-B02C-478446DF3219}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{93A55DA3-83ED-4090-91B6-904C44647639}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{993161E3-CF87-46CF-A702-3FD05D3DEDDD}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{9DFFAA5F-44C6-4FF2-80EE-76368D0A2E75}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{AA8714C4-294D-47FB-BCE0-BC12445CFBD4}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{B34A6A15-1F6F-4A19-A9DD-8B44C874A20B}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{C242AC08-2AE7-46A5-A62D-E7F1B9BE489C}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{F3EC3AFF-8FD8-4253-ABA2-F2ABE0A5524A}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{F85503FF-ED21-4493-9A4A-B6765EB45D94}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{FEEAF56C-C91B-4D1C-9FC8-BAFD85F5F2B3}
DeleteKey: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Trolltech
RemoveProxy:
EmptyTemp:
end


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.







Schritt 2
Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.






Schritt 3
Downloade dir bitte Farbar Service Scanner Farbar Service Scanner
  • Starte das Tool mit Doppelklick auf die FSS.exe
  • Gehe sicher, dass folgende Optionen angehakt sind.
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Klicke auf Scan.
  • Wenn das Tool fertig ist, wird es eine FSS.txt in dem Verzeichnis erstellen, wo das Tool gelaufen ist.

Poste bitte den Inhalt hier.








Schritt 4
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Untersuchen.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei des FRST-Fix,
  • die Logdatei desSecurityCheck,
  • die Logdatei von FSS,
  • die beiden neuen Logdateien von FRST.

nora.s 17.11.2015 16:46

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hallo!

Ausversehen habe ich FRST beim Entfernen-Durchlauf nicht als Administrator gestartet. Habe dann einen zweiten Durchlauf gemacht, allerdings hat das Programm keine neue Fixlog gespeichert..

Hier schon mal die Dateien von Security Ceck und die Fixlog:

Code:

Results of screen317's Security Check version 1.009 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Security Center service is not running! This report may not be accurate!
Microsoft Security Essentials 
 Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````
 Java 7 Update 9 
 Java version 32-bit out of Date!
 Adobe Flash Player 19.0.0.245 
 Adobe Reader XI 
 Mozilla Firefox (42.0)
 Mozilla Thunderbird 31.7.0 Thunderbird out of Date! 
 Google Chrome (46.0.2490.80)
 Google Chrome (46.0.2490.86)
````````Process Check: objlist.exe by Laurent```````` 
 Microsoft Security Essentials MSMpEng.exe
 Microsoft Security Essentials msseces.exe
 Malwarebytes Anti-Malware mbamservice.exe 
 Malwarebytes Anti-Malware mbam.exe 
 Malwarebytes Anti-Malware mbamscheduler.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:16-11-2015
durchgeführt von Notebook (2015-11-17 16:05:31) Run:3
Gestartet von E:\
Geladene Profile: Notebook & Nora (Verfügbare Profile: Notebook & Nora & Uwelchen)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
start
CloseProcesses:
HKLM-x32\...\runonceex: [Flags] => 8
Task: {0193F86E-DCBA-4717-984F-AAED2657012C} - System32\Tasks\{58CA7212-3668-4514-BF70-A38EF0598722} => pcalua.exe -a F:\Install.exe -d F:\
Task: {06839B91-58C1-43B2-AE96-615A676350F7} - System32\Tasks\{561E282B-989B-43CF-9923-7E78F5100D85} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {1AE35477-E386-4ED0-B716-C799EEAF3CB7} - System32\Tasks\{3C4A0741-2782-49C1-B191-6DD27182317B} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {2619407E-888E-4EDB-9CE9-7900016E616C} - \HQ-Video-Profession-1.3-firefoxinstaller -> Keine Datei <==== ACHTUNG
Task: {424B4465-B5BC-419C-AFE9-BDA0BE1CD8ED} - \HQ-Video-Profession-1.3-codedownloader -> Keine Datei <==== ACHTUNG
Task: {4481CAAD-E5FF-4DBC-B33A-485DD1E033AB} - \HQ-Video-Profession-1.3-enabler -> Keine Datei <==== ACHTUNG
Task: {66168DDB-F850-4953-8BBA-6CDDE814EDB1} - \HQ-Video-Profession-1.3-chromeinstaller -> Keine Datei <==== ACHTUNG
Task: {72CCA424-D111-4F99-AFF8-A5D8C3352C89} - \MediaPlayerEnhance-enabler -> Keine Datei <==== ACHTUNG
Task: {73634F6A-9129-42B3-81CF-310EE8F0857A} - \MediaPlayerEnhance-codedownloader -> Keine Datei <==== ACHTUNG
Task: {79CEC219-88D1-49B9-9BFB-F6AABB262CC6} - \MediaPlayerEnhance-firefoxinstaller -> Keine Datei <==== ACHTUNG
Task: {8841015E-BB01-4BB5-B20E-F48C76D70890} - System32\Tasks\{941C066D-C974-4F3B-8FB9-C313C1B1E452} => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ACHTUNG
Task: {B432F1D6-FBFA-4641-836A-6D21416BE178} - \MediaPlayerEnhance-chromeinstaller -> Keine Datei <==== ACHTUNG
Task: {D9E7D8F2-A3D2-4CCF-A63C-DFB19020869B} - \HQ-Video-Profession-1.3-updater -> Keine Datei <==== ACHTUNG
Task: {E4C899FF-E8F7-4AF1-A6A7-A04010BC08CB} - \MediaPlayerEnhance-updater -> Keine Datei <==== ACHTUNG
C:\Program Files (x86)\Uniblue
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{0510789C-5E5D-4FA3-A3EF-2D56FDE5090A}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{1E34EA93-600B-4CBC-9858-59BE04C1A581}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{32CC4D2E-999C-4853-9D3E-5DE4C02D57C6}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{34A117AD-7F43-4859-BF97-ADC46488953F}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{5A06A37E-F036-42EC-9D51-E738FACBFEB5}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{7007FA4C-E372-4485-ADFA-213B9E38D87F}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{7AE769DF-F151-4541-B820-031726E76E06}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{844C2331-94DF-431E-9A67-426ED861D27F}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{8684A596-308C-4872-ACA7-FF6093BBEEF7}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{934063FB-A81D-4849-B02C-478446DF3219}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{93A55DA3-83ED-4090-91B6-904C44647639}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{993161E3-CF87-46CF-A702-3FD05D3DEDDD}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{9DFFAA5F-44C6-4FF2-80EE-76368D0A2E75}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{AA8714C4-294D-47FB-BCE0-BC12445CFBD4}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{B34A6A15-1F6F-4A19-A9DD-8B44C874A20B}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{C242AC08-2AE7-46A5-A62D-E7F1B9BE489C}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{F3EC3AFF-8FD8-4253-ABA2-F2ABE0A5524A}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{F85503FF-ED21-4493-9A4A-B6765EB45D94}
DeleteKey: HKLM\SOFTWARE\Classes\Interface\{FEEAF56C-C91B-4D1C-9FC8-BAFD85F5F2B3}
DeleteKey: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Trolltech
RemoveProxy:
EmptyTemp:
end
*****************

Prozess erfolgreich geschlossen.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\runonceex\\Flags => Wert erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0193F86E-DCBA-4717-984F-AAED2657012C}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0193F86E-DCBA-4717-984F-AAED2657012C}" => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\{58CA7212-3668-4514-BF70-A38EF0598722} => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{58CA7212-3668-4514-BF70-A38EF0598722}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06839B91-58C1-43B2-AE96-615A676350F7}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06839B91-58C1-43B2-AE96-615A676350F7}" => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\{561E282B-989B-43CF-9923-7E78F5100D85} => nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{561E282B-989B-43CF-9923-7E78F5100D85}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1AE35477-E386-4ED0-B716-C799EEAF3CB7}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1AE35477-E386-4ED0-B716-C799EEAF3CB7}" => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\{3C4A0741-2782-49C1-B191-6DD27182317B} => nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3C4A0741-2782-49C1-B191-6DD27182317B}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2619407E-888E-4EDB-9CE9-7900016E616C}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2619407E-888E-4EDB-9CE9-7900016E616C}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HQ-Video-Profession-1.3-firefoxinstaller => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{424B4465-B5BC-419C-AFE9-BDA0BE1CD8ED}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424B4465-B5BC-419C-AFE9-BDA0BE1CD8ED}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HQ-Video-Profession-1.3-codedownloader => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4481CAAD-E5FF-4DBC-B33A-485DD1E033AB}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4481CAAD-E5FF-4DBC-B33A-485DD1E033AB}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HQ-Video-Profession-1.3-enabler => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{66168DDB-F850-4953-8BBA-6CDDE814EDB1}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66168DDB-F850-4953-8BBA-6CDDE814EDB1}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HQ-Video-Profession-1.3-chromeinstaller => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{72CCA424-D111-4F99-AFF8-A5D8C3352C89}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72CCA424-D111-4F99-AFF8-A5D8C3352C89}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MediaPlayerEnhance-enabler => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{73634F6A-9129-42B3-81CF-310EE8F0857A}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73634F6A-9129-42B3-81CF-310EE8F0857A}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MediaPlayerEnhance-codedownloader => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{79CEC219-88D1-49B9-9BFB-F6AABB262CC6}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79CEC219-88D1-49B9-9BFB-F6AABB262CC6}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MediaPlayerEnhance-firefoxinstaller => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8841015E-BB01-4BB5-B20E-F48C76D70890}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8841015E-BB01-4BB5-B20E-F48C76D70890}" => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\{941C066D-C974-4F3B-8FB9-C313C1B1E452} => nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{941C066D-C974-4F3B-8FB9-C313C1B1E452}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B432F1D6-FBFA-4641-836A-6D21416BE178}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B432F1D6-FBFA-4641-836A-6D21416BE178}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MediaPlayerEnhance-chromeinstaller => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D9E7D8F2-A3D2-4CCF-A63C-DFB19020869B}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D9E7D8F2-A3D2-4CCF-A63C-DFB19020869B}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HQ-Video-Profession-1.3-updater => Schlüssel nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E4C899FF-E8F7-4AF1-A6A7-A04010BC08CB}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E4C899FF-E8F7-4AF1-A6A7-A04010BC08CB}" => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MediaPlayerEnhance-updater => Schlüssel nicht gefunden.
"C:\Program Files (x86)\Uniblue" => nicht gefunden.
HKLM\SOFTWARE\Classes\Interface\{0510789C-5E5D-4FA3-A3EF-2D56FDE5090A} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{0510789C-5E5D-4FA3-A3EF-2D56FDE5090A} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{1E34EA93-600B-4CBC-9858-59BE04C1A581} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{1E34EA93-600B-4CBC-9858-59BE04C1A581} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{32CC4D2E-999C-4853-9D3E-5DE4C02D57C6} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{32CC4D2E-999C-4853-9D3E-5DE4C02D57C6} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{34A117AD-7F43-4859-BF97-ADC46488953F} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{34A117AD-7F43-4859-BF97-ADC46488953F} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{5A06A37E-F036-42EC-9D51-E738FACBFEB5} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{5A06A37E-F036-42EC-9D51-E738FACBFEB5} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{7007FA4C-E372-4485-ADFA-213B9E38D87F} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{7007FA4C-E372-4485-ADFA-213B9E38D87F} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{7AE769DF-F151-4541-B820-031726E76E06} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{7AE769DF-F151-4541-B820-031726E76E06} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{844C2331-94DF-431E-9A67-426ED861D27F} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{844C2331-94DF-431E-9A67-426ED861D27F} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{8684A596-308C-4872-ACA7-FF6093BBEEF7} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{8684A596-308C-4872-ACA7-FF6093BBEEF7} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{934063FB-A81D-4849-B02C-478446DF3219} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{934063FB-A81D-4849-B02C-478446DF3219} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{93A55DA3-83ED-4090-91B6-904C44647639} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{93A55DA3-83ED-4090-91B6-904C44647639} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{993161E3-CF87-46CF-A702-3FD05D3DEDDD} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{993161E3-CF87-46CF-A702-3FD05D3DEDDD} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{9DFFAA5F-44C6-4FF2-80EE-76368D0A2E75} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{9DFFAA5F-44C6-4FF2-80EE-76368D0A2E75} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{AA8714C4-294D-47FB-BCE0-BC12445CFBD4} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{AA8714C4-294D-47FB-BCE0-BC12445CFBD4} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{B34A6A15-1F6F-4A19-A9DD-8B44C874A20B} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{B34A6A15-1F6F-4A19-A9DD-8B44C874A20B} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{C242AC08-2AE7-46A5-A62D-E7F1B9BE489C} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{C242AC08-2AE7-46A5-A62D-E7F1B9BE489C} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{F3EC3AFF-8FD8-4253-ABA2-F2ABE0A5524A} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{F3EC3AFF-8FD8-4253-ABA2-F2ABE0A5524A} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{F85503FF-ED21-4493-9A4A-B6765EB45D94} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{F85503FF-ED21-4493-9A4A-B6765EB45D94} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Classes\Interface\{FEEAF56C-C91B-4D1C-9FC8-BAFD85F5F2B3} => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKLM\SOFTWARE\Classes\Interface\{FEEAF56C-C91B-4D1C-9FC8-BAFD85F5F2B3} => Schlüssel erfolgreich entfernt
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Trolltech => konnte nicht entfernt werden im ersten Versuch (ErrorCode: C0000121), siehe nächste Zeile.
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Trolltech => Schlüssel erfolgreich entfernt

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt


========= Ende von RemoveProxy: =========

EmptyTemp: => 176.7 MB temporäre Dateien entfernt.


Das System musste neu gestartet werden.

==== Ende von Fixlog 16:05:48 ====

Code:

Farbar Service Scanner Version: 26-07-2015
Ran by Notebook (administrator) on 17-11-2015 at 16:34:30
Running from "C:\Users\Nora\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:16-11-2015
durchgeführt von Notebook (2015-11-17 16:37:01)
Gestartet von E:\
Windows 7 Home Premium Service Pack 1 (X64) (2012-08-30 13:16:26)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-1146881843-1855949487-4122649668-500 - Administrator - Disabled)
Gast (S-1-5-21-1146881843-1855949487-4122649668-501 - Limited - Disabled)
Nora (S-1-5-21-1146881843-1855949487-4122649668-1001 - Limited - Enabled) => C:\Users\Nora
Notebook (S-1-5-21-1146881843-1855949487-4122649668-1000 - Administrator - Enabled) => C:\Users\Notebook
Uwelchen (S-1-5-21-1146881843-1855949487-4122649668-1003 - Limited - Enabled) => C:\Users\Uwelchen

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.7.637 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
Benutzerhandbuch (x32 Version: 1.0.0.6 - Lenovo) Hidden
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CBR (HKLM\...\{A8305DB2-3F6A-43CF-8CE3-EFD3D0F1C352}) (Version: 0.7 - G.Waser)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.2.3442 - CDBurnerXP)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.4.51 - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.0 - Lenovo)
Energy Management (x32 Version: 6.0.2.0 - Lenovo) Hidden
Free DWG Viewer 7.3 (HKLM-x32\...\{16CF668C-104D-479F-88A9-739137AEF3AD}) (Version: 7.3.0.176 - IGC)
GeoGebra 4.4 (HKLM-x32\...\GeoGebra 4.4) (Version: 4.4.6.0 - International GeoGebra Institute)
Google Chrome (HKLM-x32\...\{73187774-F274-39D6-80A4-33778B3CBBD4}) (Version: 65.51.16478 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
HP Deskjet 1000 J110 series - Grundlegende Software für das Gerät (HKLM\...\{CED47C99-8892-4956-BCA7-CC3123531371}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1000 J110 series Hilfe (HKLM-x32\...\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3341 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 9 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.10.1209.1 - Lenovo EasyCamera)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo Games Console (HKLM-x32\...\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3728 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden
Lexmark S410 Series Deinstallationsprogamm (HKLM\...\Lexmark S410 Series) (Version:  - Lexmark International, Inc.)
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
Mozilla Thunderbird 31.7.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 de)) (Version: 31.7.0 - Mozilla)
Mozilla Thunderbird 38.2.0 (x86 de) (HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\Mozilla Thunderbird 38.2.0 (x86 de)) (Version: 38.2.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.0 - Frank Heindörfer, Philip Chinery)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10003 - Realtek Semiconductor Corp.)
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version:  - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Studie zur Verbesserung von HP Deskjet 1000 J110 series Produkten (HKLM\...\{28F4BC72-75AE-47DD-B5B3-2A027BCA48A7}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.0.0 - Synaptics Incorporated)
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.14563 - TeamViewer)
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo)
Verbindungsassistent (HKLM-x32\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent)
VeriFace (HKLM-x32\...\VeriFace) (Version: 4.0.0.1224 - Lenovo)
VLC media player 2.0.4 (HKLM-x32\...\VLC media player) (Version: 2.0.4 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Wiederherstellungspunkte =========================

08-11-2015 20:31:36 Windows-Sicherung
09-11-2015 22:00:44 Windows Update
11-11-2015 12:41:21 Windows Update
11-11-2015 17:21:37 Windows Update
11-11-2015 18:40:28 Windows Update
12-11-2015 14:53:27 Windows Update
14-11-2015 18:12:10 JRT Pre-Junkware Removal
14-11-2015 21:37:48 JRT Pre-Junkware Removal
14-11-2015 21:43:11 JRT Pre-Junkware Removal
15-11-2015 14:12:24 zoek.exe restore point
15-11-2015 14:34:41 Prüfpunkt von HitmanPro
16-11-2015 13:01:01 Windows Update

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2015-11-15 14:12 - 00000841 ____A C:\windows\system32\Drivers\etc\hosts

 127.0.0.1      localhost
::1            localhost

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {05871FC2-EF84-4424-BD51-9E9784F25D1F} - System32\Tasks\HpWebReg.exe => C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\HpWebReg.exe
Task: {1AA4CBE5-A1A1-4E11-96FF-D3DA11C5C67F} - System32\Tasks\{6E897720-0C00-426B-82A9-06A27072CBE8} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2015-11-05] (Mozilla Corporation)
Task: {1C4D16D4-59A3-4E90-8322-C42381835A6B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {39607F30-B624-48CA-8B74-B64E766204B9} - System32\Tasks\HPCustParticipation HP Deskjet 1000 J110 series => C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
Task: {53FB169C-39A0-4725-8274-49E0E8AE700F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {54BAB1DA-AAD2-480D-A51B-2789094B968F} - System32\Tasks\{B33CE333-4158-42C2-A582-ACC2CD8B4AB7} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2015-11-05] (Mozilla Corporation)
Task: {5A749EF4-BEEB-41AB-BB09-09E906F144D9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {73FCE9BB-49FA-4071-AD14-1CAD5E829A43} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29] (CyberLink)
Task: {7F31B36B-C59C-422E-B4AF-24CFC4B301C8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {8D3ECFEB-ECC6-43C7-9FD1-6167CEBE303A} - System32\Tasks\{DD783E30-083B-47F0-BD39-C0DDA32A49E5} => pcalua.exe -a "C:\Program Files (x86)\Verbindungsassistent\Uninstaller.exe"
Task: {A1EB24AA-BBC1-4663-B6AE-C8687A2FDA4F} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated)
Task: {C701C00E-FF7B-424B-983A-3386728205B3} - System32\Tasks\{3D5593A9-5F78-4469-B743-0BD6634616C8} => C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [2015-11-05] (Mozilla Corporation)
Task: {DBCE4CED-3DB9-46B7-A285-39BCC483CD7C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2012-05-23 12:03 - 2012-05-23 12:03 - 01508192 _____ () C:\windows\system32\IcnOvrly.dll
2012-05-23 12:03 - 2012-05-23 12:03 - 00628064 _____ () C:\windows\system32\SimpleExt.dll
2008-12-20 04:20 - 2012-05-23 12:15 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2008-12-20 04:20 - 2012-05-23 12:15 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2012-05-23 11:36 - 2011-03-25 10:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-10-23 17:07 - 2009-03-03 11:45 - 00296400 ____N () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
2014-02-12 19:58 - 2014-02-12 19:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 19:58 - 2014-02-12 19:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-05-23 12:03 - 2012-05-23 12:03 - 00013664 _____ () C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
2014-10-16 21:04 - 2014-10-16 21:04 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\17c296575fad30d021e6370dc70cf800\IsdiInterop.ni.dll
2012-05-23 11:35 - 2011-02-18 09:16 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\ProgramData\Temp:373E1720

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [{C06D5DF8-3461-4042-8F52-7EBCDE9FE5EB}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{A01CE26B-13D2-49C9-A92D-9B7D46120EAD}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{23CFB686-0B7E-4480-A9A3-CB0C2F765BAA}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{85C74DA7-449E-44C7-8E4E-1F4912152D42}] => (Allow) LPort=2869
FirewallRules: [{877B58CB-8D65-442A-8AF5-5FA372C19F10}] => (Allow) LPort=1900
FirewallRules: [{8D40A53C-4335-417B-9C4A-CB4692B6701D}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{17F942C8-12AD-4AA5-9463-4D84ED86C64F}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{494CA055-1977-42EC-B8BF-AE2174875BDB}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{7FB6858F-ED36-454A-8F9F-DF9A80AA76BF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{58AE4ECC-80E0-4F0D-BDC7-2CC30B8636BE}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{5C3FAB83-0355-4B03-8DC1-B8E0A07D7802}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{0C353832-0069-4E0E-9DC5-C406A89ED5BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C3FD3DA4-E429-4DDB-8AF6-37BB69E5EC76}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{DB0BA175-6DF7-49FB-BC0E-EB66246A1ACB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CD7CBA5A-1320-4B8A-86ED-D18730A7E38D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6DCD0473-2BF8-47E3-9577-F22D90E33E6C}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{1848B09C-A7F2-4E06-84AF-903D2D0CFCF1}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{600BE599-5822-48F3-B869-82DC5C62233C}] => (Allow) C:\Program Files\HP\HP Deskjet 1000 J110 series\Bin\USBSetup.exe
FirewallRules: [{795730CF-A64E-4915-8384-9C4A4D8606B1}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS0049\HPDiagnosticCoreUI.exe
FirewallRules: [{96963478-4C91-4FAA-A42F-C0519527DA88}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS0049\HPDiagnosticCoreUI.exe
FirewallRules: [{66F54DF8-0774-4E55-800F-073B4E8BB050}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS5C88\HPDiagnosticCoreUI.exe
FirewallRules: [{58ED8715-7D7E-4764-A2F4-1DC940D46FB9}] => (Allow) C:\Users\Notebook\AppData\Local\Temp\7zS5C88\HPDiagnosticCoreUI.exe
FirewallRules: [{2CF02080-21D3-4222-81D1-30FAE88FA2F6}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{E2CA7EE2-6A42-4951-B9E5-9C5E1FF1376A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A7998D86-49F1-4F44-886A-7F2D4CAE5C0A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{5488F4E7-619C-40F9-867A-5BE99F507EB9}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{4429A93B-8E63-407C-9B8A-3187FFC606B1}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{0F6DDD45-F3D6-43D5-B986-E7E4425ED8D6}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{6A2A115F-CFA8-4679-9084-9FDE758DE08E}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [{364D57E1-9EF3-4CC4-AA8F-B0113BACBDBD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DCD7E537-A65D-45B1-A414-9576213BC1E8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{193C3EDE-369F-49A2-A07D-C92D79A23A67}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (11/16/2015 08:34:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: 448: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.)

Error: (11/16/2015 08:34:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: mDNSPlatformReadTCP - recv: 10053

Error: (11/15/2015 08:17:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 16068

Error: (11/15/2015 08:17:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 16068

Error: (11/15/2015 08:17:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (11/15/2015 07:00:19 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Alle in der Sicherung enthaltenen Laufwerke wurden ausgelassen. Vergewissern Sie sich, dass die Laufwerke angeschlossen und funktionsfähig sind. (0x810000FF)"

Error: (11/15/2015 06:41:35 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/15/2015 06:07:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/15/2015 06:07:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (11/15/2015 04:46:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15741


Systemfehler:
=============
Error: (11/17/2015 04:06:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Apple Mobile Device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%3

Error: (11/17/2015 04:06:01 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
%%1056

Error: (11/17/2015 04:05:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/17/2015 04:05:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/17/2015 04:05:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/17/2015 04:05:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Intel(R) Management and Security Application Local Management Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/17/2015 04:05:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Live ID Sign-in Assistant" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/17/2015 04:05:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Management and Security Application User Notification Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/17/2015 04:05:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Rapid Storage Technology" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/17/2015 04:05:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "iPod-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


CodeIntegrity:
===================================
  Date: 2015-11-13 16:37:33.753
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-11-13 16:37:33.675
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Pentium(R) CPU B960 @ 2.20GHz
Prozentuale Nutzung des RAM: 27%
Installierter physikalischer RAM: 8135.86 MB
Verfügbarer physikalischer RAM: 5931.16 MB
Summe virtueller Speicher: 16269.93 MB
Verfügbarer virtueller Speicher: 14007.93 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:254.14 GB) (Free:173.18 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:26.82 GB) NTFS
Drive e: () (Removable) (Total:7.37 GB) (Free:4.51 GB) FAT32

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 68E1532F)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=254.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7.4 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7.4 GB) - (Type=0B)

==================== Ende von Addition.txt ============================

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:16-11-2015
durchgeführt von Notebook (Administrator) auf NOTEBOOK-PC (17-11-2015 16:36:27)
Gestartet von E:\
Geladene Profile: Notebook & Nora (Verfügbare Profile: Notebook & Nora & Uwelchen)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2012-05-23] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2012-05-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2012-05-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-05-23] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM\...\RunOnce: [*EmptyTemp] => cmd /c rd /q/s C:\FRST\Temp
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-10-05] (Malwarebytes)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[C10].txt
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\...\MountPoints2: {72c6dce6-520b-11e3-9d67-446d57e77fa7} - E:\LaunchU3.exe -a
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll [2012-05-23] ()
Startup: C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2015-11-12]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Notebook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2013-12-06]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0434AB00-3F7C-4291-91FB-BFB1A7FBC4E6}: [DhcpNameServer] 10.63.210.254
Tcpip\..\Interfaces\{0EA6BB07-2FF3-4059-B5F3-5A19971BFC92}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1146881843-1855949487-4122649668-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-1146881843-1855949487-4122649668-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN_deDE506
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1146881843-1855949487-4122649668-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-10-21] (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-10-21] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)

FireFox:
========
FF ProfilePath: C:\Users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\kr5q6a4y.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Session Restore: -> ist aktiviert.
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\windows\system32\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-10-21] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-15] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [296400 2009-03-03] ()

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-14] (Malwarebytes)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
U3 BcmSqlStartupSvc; kein ImagePath
U2 CLKMSVC10_3A60B698; kein ImagePath
U2 CLKMSVC10_C3B3B687; kein ImagePath
U2 DriverService; kein ImagePath
U2 iATAgentService; kein ImagePath
U2 idealife Update Service; kein ImagePath
U3 IGRS; kein ImagePath
U2 IviRegMgr; kein ImagePath
U2 nvUpdatusService; kein ImagePath
U2 Oasis2Service; kein ImagePath
U2 PCCarerService; kein ImagePath
U2 ReadyComm.DirectRouter; kein ImagePath
U2 RichVideo; kein ImagePath
U2 RtLedService; kein ImagePath
U2 SoftwareService; kein ImagePath
U3 SQLWriter; kein ImagePath
U2 Stereo Service; kein ImagePath

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-17 16:34 - 2015-11-17 16:34 - 00002750 _____ C:\Users\Nora\Desktop\FSS.txt
2015-11-17 16:26 - 2015-11-17 16:26 - 00001219 _____ C:\Users\Notebook\Desktop\checkup.txt
2015-11-17 15:45 - 2015-11-17 15:45 - 00899072 _____ (Farbar) C:\Users\Nora\Desktop\FSS.exe
2015-11-17 15:45 - 2015-11-17 15:45 - 00852720 _____ C:\Users\Nora\Desktop\SecurityCheck.exe
2015-11-16 17:27 - 2015-11-16 17:27 - 00008286 _____ C:\Users\Notebook\Desktop\HitmanPro_20151116_1727.log
2015-11-16 17:17 - 2015-11-16 17:17 - 11337112 _____ (SurfRight B.V.) C:\Users\Nora\Desktop\HitmanPro_x64.exe
2015-11-16 12:46 - 2015-11-16 12:46 - 00003408 ____N C:\bootsqm.dat
2015-11-15 18:10 - 2015-11-17 16:36 - 00040917 _____ C:\FaceProv.log
2015-11-15 14:34 - 2015-11-15 14:34 - 00008288 _____ C:\Users\Notebook\Desktop\HitmanPro_20151115_1434.log
2015-11-15 14:34 - 2015-11-15 14:34 - 00007386 _____ C:\Users\Notebook\Desktop\HitmanPro_20151115_1433.xml
2015-11-15 14:33 - 2015-11-15 14:33 - 00008288 _____ C:\Users\Notebook\Desktop\HitmanPro_20151115_1433.log
2015-11-15 14:20 - 2015-11-15 14:35 - 00000000 ____D C:\ProgramData\HitmanPro
2015-11-15 14:15 - 2015-11-15 14:15 - 23664130 _____ C:\windows\repository.backup
2015-11-15 14:15 - 2015-11-15 14:11 - 00024064 _____ C:\windows\zoek-delete.exe
2015-11-15 14:11 - 2015-11-15 14:11 - 00000000 ____D C:\zoek_backup
2015-11-15 14:09 - 2015-11-16 17:22 - 00000000 ____D C:\Users\Nora\Desktop\TxtDokumente
2015-11-15 14:00 - 2015-11-15 14:00 - 01309184 _____ C:\Users\Nora\Desktop\zoek.exe
2015-11-14 21:46 - 2015-11-14 21:46 - 00001074 _____ C:\Users\Notebook\Desktop\JRT.txt
2015-11-14 21:43 - 2015-10-05 23:26 - 01801288 _____ (Malwarebytes) C:\Users\Notebook\Desktop\JRT.exe
2015-11-14 17:38 - 2015-11-14 17:39 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-14 17:38 - 2015-11-14 17:38 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-11-14 17:38 - 2015-11-14 17:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-14 17:38 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2015-11-14 17:38 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-11-14 17:38 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2015-11-14 17:25 - 2015-11-14 17:25 - 01798976 _____ (Malwarebytes) C:\Users\Nora\Desktop\JRT.exe
2015-11-14 17:24 - 2015-11-14 17:25 - 22908888 _____ (Malwarebytes ) C:\Users\Nora\Desktop\mbam-setup-2.2.0.1024.exe
2015-11-14 17:18 - 2015-11-14 17:18 - 01729536 _____ C:\Users\Nora\Desktop\AdwCleaner_5.020.exe
2015-11-13 16:28 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe
2015-11-13 16:28 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe
2015-11-13 16:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe
2015-11-13 16:28 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe
2015-11-13 16:21 - 2015-11-13 16:22 - 00000000 ____D C:\Qoobox
2015-11-13 16:20 - 2015-11-13 16:38 - 00000000 ____D C:\windows\erdnt
2015-11-12 16:58 - 2015-11-12 16:58 - 00059877 _____ C:\Users\Notebook\Desktop\FRST.txt
2015-11-12 16:43 - 2015-11-12 16:43 - 00000000 ____D C:\Users\Notebook\AppData\Local\GWX
2015-11-12 12:28 - 2015-11-12 12:28 - 00000000 ____D C:\Users\Nora\Documents\OneNote-Notizbücher
2015-11-12 12:20 - 2015-11-12 12:21 - 00004120 _____ C:\Users\Notebook\Desktop\gmertxt.log
2015-11-12 12:06 - 2015-11-12 12:06 - 00280320 _____ C:\windows\Minidump\111215-26395-01.dmp
2015-11-12 11:18 - 2015-11-17 16:36 - 00000000 ____D C:\FRST
2015-11-12 11:17 - 2015-11-12 11:17 - 00000000 _____ C:\Users\Notebook\defogger_reenable
2015-11-12 10:52 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-11-11 17:49 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-11-11 17:49 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-11-11 17:49 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-11-11 17:49 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-11-11 17:49 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-11-11 17:49 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-11-11 17:49 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-11-11 17:49 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-11-11 17:49 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-11-11 17:49 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-11-11 17:49 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-11-11 17:49 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-11-11 17:49 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-11-11 17:49 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-11-11 17:49 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-11-11 17:49 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-11-11 17:49 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-11-11 17:49 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-11-11 17:49 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-11-11 17:49 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-11-11 17:49 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-11-11 17:49 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-11-11 17:49 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-11-11 17:49 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-11-11 17:49 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-11-11 17:49 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-11-11 17:49 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 17:49 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-11-11 17:49 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-11-11 17:49 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-11-11 17:49 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2015-11-11 17:49 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-11-11 17:49 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-11-11 17:49 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-11-11 17:49 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-11-11 17:49 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-11-11 17:49 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-11-11 17:49 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-11-11 17:49 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-11-11 17:49 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-11-11 17:49 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-11-11 17:49 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-11-11 17:49 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-11-11 17:49 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-11-11 17:49 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-11-11 17:48 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-11-11 17:48 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-11-11 17:48 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-11-11 17:48 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-11-11 17:48 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-11-11 17:48 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-11-11 17:48 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-11-11 17:48 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-11-11 17:48 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-11-11 17:48 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-11-11 17:48 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-11-11 17:48 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-11-11 17:48 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-11-11 17:48 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-11-11 17:48 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-11-11 17:48 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-11-11 17:48 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-11-11 17:48 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-11-11 17:48 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-11-11 17:48 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-11-11 17:48 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-11-11 17:48 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 17:48 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 17:48 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-11-11 17:48 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2015-11-11 17:48 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2015-11-11 17:46 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\jnwmon.dll
2015-11-11 17:46 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2015-11-11 17:45 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-11-11 17:45 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-11-11 17:40 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\windows\system32\aelupsvc.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-11-11 17:40 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\shimeng.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
2015-11-11 17:40 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-11-11 17:39 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-11-10 15:06 - 2015-11-10 15:06 - 00280320 _____ C:\windows\Minidump\111015-24726-01.dmp
2015-11-07 19:23 - 2015-11-07 19:23 - 00280320 _____ C:\windows\Minidump\110715-27315-01.dmp
2015-11-06 21:49 - 2015-11-07 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-05 09:25 - 2015-11-05 09:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-11-17 16:16 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-17 16:16 - 2009-07-14 05:45 - 00028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-17 16:15 - 2012-05-23 02:58 - 00699440 _____ C:\windows\system32\perfh007.dat
2015-11-17 16:15 - 2012-05-23 02:58 - 00149548 _____ C:\windows\system32\perfc007.dat
2015-11-17 16:15 - 2009-07-14 06:13 - 01619700 _____ C:\windows\system32\PerfStringBackup.INI
2015-11-17 16:14 - 2012-05-23 11:17 - 01905484 _____ C:\windows\WindowsUpdate.log
2015-11-17 16:07 - 2014-02-23 22:07 - 00111090 _____ C:\windows\setupact.log
2015-11-17 16:07 - 2012-10-24 14:24 - 00065536 _____ C:\windows\system32\Ikeext.etl
2015-11-17 16:07 - 2012-05-23 12:12 - 00154437 _____ C:\windows\system32\fastboot.set
2015-11-17 16:07 - 2012-05-23 12:11 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-17 16:07 - 2012-05-23 12:03 - 00000000 ____D C:\ProgramData\VeriFace
2015-11-17 16:07 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-11-17 16:06 - 2012-05-23 12:11 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-17 15:42 - 2012-10-21 11:18 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-11-17 15:33 - 2009-07-14 04:20 - 00000000 ____D C:\windows\tracing
2015-11-16 20:33 - 2014-03-19 12:38 - 42579609 _____ C:\windows\system32\PsBoot.log
2015-11-16 20:33 - 2014-03-19 12:38 - 00000000 _____ C:\windows\system32\defragLog.log
2015-11-15 19:00 - 2014-10-07 20:27 - 00000000 ____D C:\Users\Uwelchen
2015-11-15 14:41 - 2012-08-30 14:16 - 00000000 ____D C:\Users\Notebook
2015-11-15 14:17 - 2014-02-23 22:06 - 00155978 _____ C:\windows\PFRO.log
2015-11-15 13:32 - 2014-03-19 13:39 - 00000000 ____D C:\AdwCleaner
2015-11-15 12:26 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2015-11-14 18:04 - 2009-07-14 06:32 - 00000000 ____D C:\windows\addins
2015-11-14 17:30 - 2013-12-18 12:54 - 00000000 ____D C:\Users\Nora
2015-11-14 14:47 - 2015-03-17 11:18 - 00000000 ____D C:\Users\Nora\Desktop\Uwe
2015-11-13 16:37 - 2014-06-14 21:18 - 00000000 ____D C:\Users\Notebook\AppData\Local\Adobe
2015-11-13 09:03 - 2009-07-14 06:08 - 00032632 _____ C:\windows\Tasks\SCHEDLGU.TXT
2015-11-12 16:39 - 2009-07-14 05:45 - 00337808 _____ C:\windows\system32\FNTCACHE.DAT
2015-11-12 12:06 - 2014-07-24 11:21 - 00000000 ____D C:\windows\Minidump
2015-11-12 12:06 - 2014-07-24 11:20 - 1018855042 _____ C:\windows\MEMORY.DMP
2015-11-11 18:49 - 2012-10-21 17:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 18:42 - 2012-10-21 11:18 - 00780488 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-11-11 18:42 - 2012-10-21 11:18 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-11 18:42 - 2012-10-21 11:18 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-11-11 18:41 - 2011-09-29 04:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 17:32 - 2014-02-26 12:38 - 01593980 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2015-11-07 17:43 - 2012-10-21 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-30 06:22 - 2015-07-10 18:40 - 00003886 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2015-10-18 10:35 - 2014-01-31 14:51 - 00000000 ____D C:\Users\Nora\Desktop\Uni Praktikum

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2013-04-05 17:01 - 2013-04-05 17:01 - 0002528 _____ () C:\Users\Notebook\AppData\Roaming\$_hpcst$.hpc
2014-01-29 13:34 - 2014-01-29 13:34 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-11-15 12:19

==================== Ende von FRST.txt ============================

Konntest du eigentlich feststellen woher ich mir den/die Viren eingefangen habe? Waren das denn Trojaner?
Bis hierhin schon mal vielen, vielen Dank für die Hilfe!!
Grüße Nora

M-K-D-B 18.11.2015 14:56

Zitat:

Zitat von nora.s (Beitrag 1536100)
Konntest du eigentlich feststellen woher ich mir den/die Viren eingefangen habe? Waren das denn Trojaner?

Kein Trojaner, nur Adware.







Wenn du keine Probleme mehr mit Malware hast, dann sind wir hier fertig. Deine Logdateien sind sauber. :daumenhoc
Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern.



http://deeprybka.trojaner-board.de/b...cleanupneu.png
Cleanup:
(Die Reihenfolge ist hier entscheidend)

Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken.

Falls Combofix verwendet wurde:
http://deeprybka.trojaner-board.de/b.../combofix2.pngCombofix deinstallieren
  • Wichtig: Bitte Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke bitte die http://deeprybka.trojaner-board.de/b...ne/revo/w7.png + R Taste und schreibe Combofix /Uninstall in das Ausführen-Fenster.
  • Klicke auf OK.
    Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert.
  • Nun die eben deaktivierten Programme wieder aktivieren.

Alle Logs gepostet? Dann lade Dir bitte http://filepony.de/icon/tiny/delfix.pngDelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner anschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...:dankeschoen:und/oder das Forum mit einer kleinen Spende http://www.trojaner-board.de/extra/spende.png unterstützen. :applaus:




http://deeprybka.trojaner-board.de/b...ast/schild.png
Absicherung:
Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen:

Browser
Java
Flash-Player
PDF-Reader

Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.
Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.

Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.


Sofern du noch unentschieden bist, verwende ein einziges der folgenden Antivirusprogramme mit Echtzeitscanner und stets aktueller Signaturendatenbank:

   
   



Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen.

Optional:
http://filepony.de/icon/adblock_firefox.pngAdblock Plus Kann Banner, Pop-ups, Videowerbung, Tracking und Malware-Seiten blockieren.
http://filepony.de/icon/noscript.png NoScript Verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen.
http://filepony.de/icon/malwarebytes_anti_exploit.pngMalwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.



Lade Software von einem sauberen Portal wie http://filepony.de/images/microbanner.gif.
Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwcleaner .



Abschließend noch ein paar grundsätzliche Bemerkungen:
  • Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
  • Lade keine Software von Chip, Softonic oder SourceForge. Die dort angebotene Software wird häufig mit einem sog. "Installer" verteilt, mit dem man sich nur unerwünschte Software oder Adware installiert.
  • Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Selbst Microsoft unterstützt sog. Registry-Cleaner nicht. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.



Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

nora.s 19.11.2015 11:47

Win 7 Rechner mit Trojaner TR/AD.Gamarue.Y.1144 infiziert
 
Hallo!
Habe delfix gestartet, als es fertig war und die Logdatei aufgegangen ist, haben sich meine Desktopeinstellungen komplett verändert. Die meisten Dateien waren verschwunden und das Hintergrundbild war viel größer. Habe dann bei der Nachfrage, ob ich möchte dass das Programm die PC-Einstellungen ändert auf "Nein" geklickt. Jetzt ist alles so wie vorher. Soll ich das Programm noch einmal durchlaufen lassen?

Grüße Nora

Combofix kann ich auch nicht wie vorgegeben löschen. Während des Checks war der PC doch abgestürzt und ich habe das Programm im gesicherten Modus entfernt. Im Papierkorb ist es allerdings zu finden (nur wenn ich in das "Ausführen" Fenster den Text kopiere, kommt die Rückmeldung das Programm wäre nicht zu finden). Soll ich es jetzt dabei belassen?

M-K-D-B 19.11.2015 19:38

Servus,

Delfix löscht ComboFix eigentlich mit, sonst per Hand löschen.


Ich bin froh, dass wir helfen konnten :abklatsch:

In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest:
Lob, Kritik und Wünsche
Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! :)

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:17 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131