Hey Jürgen,
vielen Dank dank dafür, dass du dich meinem Problem annimmst.
Hier der ComboFix Log
Combofix Logfile: Code:
ComboFix 16-05-18.01 - Tim 29.05.2016 21:14:57.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8175.5866 [GMT 2:00]
ausgeführt von:: c:\users\Tim\Desktop\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tim\AppData\Roaming\RonKaylight.bin
c:\windows\IsUn0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2016-04-28 bis 2016-05-29 ))))))))))))))))))))))))))))))
.
.
2016-05-29 19:21 . 2016-05-29 19:21 -------- d-----w- c:\users\Miri\AppData\Local\temp
2016-05-29 19:21 . 2016-05-29 19:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-05-26 21:03 . 2016-05-26 21:04 -------- d-----w- C:\FRST
2016-05-25 16:22 . 2016-05-25 00:50 304162 ----a-w- c:\windows\AdBlock.exe
2016-05-25 13:57 . 2016-05-25 15:45 -------- d-----w- c:\users\Tim\AppData\Roaming\Avira
2016-05-25 13:56 . 2016-05-25 15:37 69888 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2016-05-25 13:56 . 2016-05-25 15:37 154816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2016-05-25 13:56 . 2016-05-25 15:37 133168 ----a-w- c:\windows\system32\drivers\avipbb.sys
2016-05-25 13:56 . 2015-03-17 11:01 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2016-05-25 13:56 . 2016-05-25 15:39 -------- d-----w- c:\programdata\Avira
2016-05-25 13:48 . 2016-05-25 15:17 -------- d-----w- c:\users\Tim\AppData\Local\WikiZ
2016-05-25 13:47 . 2016-05-25 00:50 305893 ----a-w- c:\windows\systwin.exe
2016-05-25 13:46 . 2016-05-25 13:46 -------- d-----w- c:\users\Tim\AppData\Roaming\w1iM6
2016-05-25 13:39 . 2016-05-25 13:39 -------- d-----w- c:\programdata\ApppaznoRs
2016-05-25 08:44 . 2016-05-25 15:18 -------- d-----w- c:\program files (x86)\WinZipper
2016-05-25 08:44 . 2016-05-25 08:44 -------- d-----w- c:\users\Tim\AppData\Roaming\eCyber
2016-05-25 08:43 . 2016-05-25 08:43 -------- d-----w- c:\programdata\xwinpx
2016-05-25 08:43 . 2016-05-25 08:43 -------- d-----w- c:\users\Tim\AppData\Roaming\TSv
2016-05-25 08:43 . 2016-05-25 08:43 -------- d-----w- c:\program files (x86)\QQBrowser
2016-05-24 17:20 . 2016-05-24 17:20 -------- d-----w- c:\users\Tim\AppData\Roaming\MCorp
2016-05-24 17:00 . 2016-05-24 17:00 38520 ----a-w- c:\windows\SysWow64\drivers\TS888x64.sys
2016-05-24 16:55 . 2016-05-24 16:55 -------- d-----w- c:\users\Tim\AppData\Roaming\Brotsoft
2016-05-24 16:55 . 2016-05-24 16:55 -------- d-----w- c:\users\Tim\AppData\Local\DeskBar
2016-05-24 16:55 . 2016-05-25 15:54 -------- d-----w- c:\program files (x86)\FastWeb
2016-05-24 13:28 . 2016-05-25 15:25 -------- d-----w- c:\program files\Caster
2016-05-24 13:24 . 2016-05-25 15:58 -------- d-----w- c:\program files (x86)\Prehuph
2016-05-24 13:24 . 2016-05-24 16:53 -------- d-----w- c:\program files (x86)\Sicotion
2016-05-24 13:24 . 2016-05-25 16:21 -------- d-----w- c:\program files (x86)\Clbuyanecut
2016-05-24 12:24 . 2016-05-24 12:24 -------- d-----w- c:\program files\Common Files\Tencent
2016-05-24 12:24 . 2016-05-24 17:06 -------- d-----w- c:\programdata\TXQMPC
2016-05-24 12:24 . 2016-05-24 12:24 54904 ----a-w- c:\windows\system32\drivers\TSSKX64.sys
2016-05-24 12:24 . 2016-05-24 12:24 -------- d-----w- c:\program files (x86)\Common Files\Tencent
2016-05-24 12:24 . 2016-05-24 12:24 97400 ----a-w- c:\windows\system32\drivers\TFsFltX64.sys
2016-05-24 12:24 . 2016-05-24 12:24 -------- d-----w- c:\program files (x86)\Tencent
2016-05-24 12:24 . 2016-05-24 17:06 -------- d-----w- c:\programdata\Tencent
2016-05-24 12:24 . 2016-05-24 12:27 -------- d-----w- c:\users\Tim\AppData\Roaming\Tencent
2016-05-24 12:22 . 2016-05-26 23:06 -------- d-----w- c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C
2016-05-24 12:22 . 2016-05-24 12:22 -------- d-----w- c:\windows\system32\SSL
2016-05-24 12:21 . 2016-05-24 12:21 60136 ----a-w- c:\windows\system32\drivers\MPCKpt.sys
2016-05-24 12:21 . 2016-05-24 16:59 -------- d-----w- c:\program files (x86)\MPC Cleaner
2016-05-24 12:21 . 2016-05-24 12:21 -------- d-----w- c:\programdata\Torrent_Search_PED
2016-05-24 12:21 . 2016-05-25 14:26 -------- d-----w- c:\users\Tim\AppData\Roaming\FreeVPN
2016-05-24 12:21 . 2016-05-24 13:25 -------- d-----w- c:\users\Tim\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-05-24 12:21 . 2016-05-24 13:24 -------- d-----w- C:\extensions
2016-05-24 12:21 . 2016-05-24 16:53 -------- d-----w- c:\program files (x86)\Druigh
2016-05-24 12:21 . 2016-05-24 12:21 -------- d-----w- c:\program files (x86)\Plsesh
2016-05-24 12:21 . 2016-05-24 12:21 -------- d-----w- c:\program files (x86)\Zmghtnaduse
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-04-25 19:47 . 2016-03-14 11:18 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2016-04-25 19:47 . 2016-03-14 11:18 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2016-03-17 01:45 . 2016-04-07 09:52 11686560 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8C4919E4-1845-40D0-BB5E-2364382A375B}\mpengine.dll
2016-03-14 11:18 . 2016-03-14 11:18 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2014-11-22 14:42 323752 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-08-14 12:13 223432 ----a-w- c:\users\Tim\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-08-14 12:13 223432 ----a-w- c:\users\Tim\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-08-14 12:13 223432 ----a-w- c:\users\Tim\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-02-09 13:46 1741096 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-02-09 13:46 1741096 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-02-09 13:46 1741096 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="c:\program files (x86)\Vtune\TBPanel.exe" [2011-08-02 2248704]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-12-12 7394584]
"DeskBar"="c:\users\Tim\AppData\Local\DeskBar\dblaunch.exe" [2015-11-09 239104]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160]
"AVMWlanClient"="c:\program files (x86)\avmwlanstick\wlangui.exe" [2010-10-22 2105344]
"KiesTrayAgent"="e:\programme\Kies\KiesTrayAgent.exe" [2014-06-14 310064]
"avgnt"="e:\programme\AntiVir\Avira\AntiVir Desktop\avgnt.exe" [2016-05-25 807392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"systwin"="systwin.exe" [2016-05-25 305893]
"AdBlock2"="AdBlock.exe" [2016-05-25 304162]
.
c:\users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2016-1-24 0]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R1 QMUdisk;tencent QMUdisk;c:\program files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys;c:\program files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys [x]
R1 softaal;softaal;c:\program files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys;c:\program files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys [x]
R1 SRepairDrv;SRepairDrv;c:\program files (x86)\Tencent\QQPCMGR\SRepairDrv;c:\program files (x86)\Tencent\QQPCMGR\SRepairDrv [x]
R2 5e8491a71a43a11d41af2899d50f1d4f;5e8491a71a43a11d41af2899d50f1d4f;c:\program files\44042da62ded3d77d5588dbb3a07579e\1c43a8a78465d704d56566e1f98abe4a.exe;c:\program files\44042da62ded3d77d5588dbb3a07579e\1c43a8a78465d704d56566e1f98abe4a.exe [x]
R2 AntiVirMailService;Avira Email-Schutz;e:\programme\AntiVir\Avira\AntiVir Desktop\avmailc7.exe;e:\programme\AntiVir\Avira\AntiVir Desktop\avmailc7.exe [x]
R2 AntiVirWebService;Avira Webschutz;e:\programme\AntiVir\Avira\AntiVir Desktop\avwebg7.exe;e:\programme\AntiVir\Avira\AntiVir Desktop\avwebg7.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 dowidoly;Renew Single Click;c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\jnsh255B.tmp;c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\jnsh255B.tmp [x]
R2 plscmmService;Plsesh Community;c:\program files (x86)\Plsesh\plscmmService.exe {79740E79-A383-47A7-B513-3DF6563D007F} {A16B1AF7-982D-40C3-B5C1-633E1A6A6678};c:\program files (x86)\Plsesh\plscmmService.exe {79740E79-A383-47A7-B513-3DF6563D007F} {A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [x]
R2 prhMngSrv;Prehuph Manager;c:\program files (x86)\Prehuph\prhMngSrv.exe {79740E79-A383-47A7-B513-3DF6563D007F} {A16B1AF7-982D-40C3-B5C1-633E1A6A6678};c:\program files (x86)\Prehuph\prhMngSrv.exe {79740E79-A383-47A7-B513-3DF6563D007F} {A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [x]
R2 rijufoze;Reservation Plastic;c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\hnsx5B0D.tmp;c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\hnsx5B0D.tmp [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 tsnethlpx64;TsNetHlpX64.sys;c:\program files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys;c:\program files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys [x]
R2 vihoqidizbt;Repetitive Strain Injury Host;c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\knsrF659.tmpfs;c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\knsrF659.tmpfs [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys;c:\windows\SYSNATIVE\pwdrvio.sys [x]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys;c:\windows\SYSNATIVE\pwdspio.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TSSKX64;TSSKX64;c:\windows\system32\drivers\tsskx64.sys;c:\windows\SYSNATIVE\drivers\tsskx64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 FreemakeVideoCapture;FreemakeVideoCapture;e:\programme\Freemake\CaptureLib\CaptureLibService.exe;e:\programme\Freemake\CaptureLib\CaptureLibService.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 262f2c77661082b8abf257c989fb5696;262f2c77661082b8abf257c989fb5696;c:\windows\system32\DRIVERS\262f2c77661082b8abf257c989fb5696.sys;c:\windows\SYSNATIVE\DRIVERS\262f2c77661082b8abf257c989fb5696.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 MPCKpt;MPCKpt;c:\windows\system32\DRIVERS\MPCKpt.sys;c:\windows\SYSNATIVE\DRIVERS\MPCKpt.sys [x]
S2 AntiVirSchedulerService;Avira Planer;e:\programme\AntiVir\Avira\AntiVir Desktop\sched.exe;e:\programme\AntiVir\Avira\AntiVir Desktop\sched.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 IhPul;IhPul;c:\users\Tim\AppData\Roaming\TSv\TSvr.exe;c:\users\Tim\AppData\Roaming\TSv\TSvr.exe [x]
S2 MPCProtectService;MPC Core Protect Service;c:\program files (x86)\MPC Cleaner\MPCProtectService.exe;c:\program files (x86)\MPC Cleaner\MPCProtectService.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 ss_conn_service;SAMSUNG Mobile Connectivity Service;c:\program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe;c:\program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 WdMan;WFini WdMan Service;c:\programdata\xwinpx\WFini.exe;c:\programdata\xwinpx\WFini.exe [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys;c:\windows\SYSNATIVE\DRIVERS\fwlanusb.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-05-25 19:49 1245848 ----a-w- c:\program files (x86)\Google\Chrome\Application\51.0.2704.63\Installer\chrmstp.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2016-05-03 14:41 287416 ----a-w- c:\program files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll
.
Inhalt des "geplante Tasks" Ordners
.
2016-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-08-15 18:08]
.
2016-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-08-15 18:08]
.
2016-05-25 c:\windows\Tasks\PED_Torrent_Search.job
- c:\programdata\Torrent_Search_PED\rundll32.exe [2016-05-24 01:14]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2014-11-20 13:53 357376 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-08-14 12:13 262344 ----a-w- c:\users\Tim\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-08-14 12:13 262344 ----a-w- c:\users\Tim\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-08-14 12:13 262344 ----a-w- c:\users\Tim\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-08-18 17:22 164760 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-08-18 17:22 164760 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2014-08-18 17:22 164760 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2014-08-18 17:22 164760 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-08-18 17:22 164760 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2014-08-18 17:22 164760 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2014-08-18 17:22 164760 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2014-08-18 17:22 164760 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-01-04 11772520]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-05-01 2685072]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-05-01 1570672]
"Greenshot"="e:\programme\Greenshot\Greenshot.exe" [2015-04-19 540672]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
uDefault_Page_URL = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
mStart Page = about:blank
mDefault_Page_URL = about:blank
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
TCP: DhcpNameServer = 192.168.178.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
.
.
------- Dateityp-Verknüpfung -------
.
inifile="%SystemRoot%\system32\NOTEPAD.EXE" %1
txtfile="%SystemRoot%\system32\NOTEPAD.EXE" %1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-QQPCRTP
AddRemove-TeamSpeak 3 Client - e:\games\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dowidoly]
"ImagePath"="c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\jnsh255B.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rijufoze]
"ImagePath"="c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\hnsx5B0D.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SRepairDrv]
"ImagePath"="\??\c:\program files (x86)\Tencent\QQPCMGR\SRepairDrv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vihoqidizbt]
"ImagePath"="c:\program files (x86)\00000000-1464092568-0000-0000-50E54939456C\knsrF659.tmpfs"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.bmp.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DIB\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.bmp.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ICO\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.ico.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JFIF\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.jpg.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPE\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.jpg.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPEG\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.jpg.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPG\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.jpg.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PNG\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.png.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIF\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.tif.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIFF\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.tif.15.4"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WDP\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.wdp.15.4"
.
[HKEY_USERS\S-1-5-21-2741301082-3115142560-2679980174-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-2741301082-3115142560-2679980174-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2741301082-3115142560-2679980174-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (S-1-5-21-2741301082-3115142560-2679980174-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_20_0_0_286_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_20_0_0_286_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_20_0_0_286_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_20_0_0_286_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_286.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.20"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_286.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_286.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_286.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Time Synchronization\\SynchronizeTime"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,e8,e6,37,9d,
ef,c4,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,e0,21,42,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,2d,35,04,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:17,d3,bd,88,4b,e1,ea,d4,b4,b3,2c,c4,6d,07,07,e4,68,68,8a,3f,cd,e1,
83,55,73,bf,3a,39,2d,0b,f6,5a
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Tcpip\\IpAddressConflict1"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,38,a1,40,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,8d,96,06,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:ce,f4,fd,5d,a0,44,59,b6,0c,16,3c,d7,1d,53,80,78,a6,01,ef,7e,e0,58,
32,ce,cd,2d,d7,9d,52,13,af,22
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Tcpip\\IpAddressConflict2"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,80,29,4e,12,96,
38,c6,01,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,38,a1,40,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,8d,96,06,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:4d,3c,72,ee,9b,73,1b,fc,fc,70,22,53,1b,28,70,de,f2,8f,f1,3f,f8,e0,
f0,89,00,3e,02,aa,0f,40,c0,5d
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Task Manager\\Interactive"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,00,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,85,c0,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,ee,f7,08,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:89,de,49,d1,46,b9,da,8a,3f,68,6f,98,cc,96,57,67,af,cd,97,16,b0,8a,
2f,c6,51,05,dc,7b,0d,dd,c5,19
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2470470F-2634-478E-B181-571E98A789BB}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Multimedia\\SystemSoundsService"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,85,40,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,2b,2a,f1,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:fd,7b,51,b9,fb,6d,dd,39,37,4c,58,66,90,f9,e9,34,ee,65,eb,22,fd,61,
53,1b,54,08,b2,05,91,03,1c,e2
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28011108-68DF-4C73-B91B-57427D501BBA}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Manual)"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,f8,85,40,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,8b,8b,f3,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:62,05,0c,0d,7c,47,49,98,41,4f,a2,c4,7e,4d,34,6e,ce,62,8d,7d,97,4f,
37,7e,e3,b8,ae,2e,60,98,2e,e3
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\WindowsBackup\\ConfigNotification"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,ed,7e,01,00,00,00,00,00,50,d5,04,e3,
8e,cb,01,00,ed,7e,01,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,48,21,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,4e,59,0b,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:5c,2d,4d,fb,0f,1a,10,46,14,69,14,ae,e9,c3,f3,7c,27,0e,3c,a4,4a,a0,
3a,12,8c,e1,4c,71,07,d8,d9,e0
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,9c,9e,e0,73,
a6,c8,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,70,21,c2,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,ae,ba,0d,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:ae,18,62,ba,40,99,24,24,8d,c1,73,6d,23,e3,27,b7,15,40,18,fc,40,a4,
da,69,5b,c7,77,d1,13,5a,52,44
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Shell\\WindowsParentalControlsMigration"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,40,05,82,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,ac,af,fa,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:6d,5d,71,fc,d9,af,69,de,33,a5,e4,7e,6d,e8,94,ca,d1,5a,01,09,44,b2,
ef,58,c0,72,c7,f6,1e,db,87,e8
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\TextServicesFramework\\MsCtfMonitor"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,16,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,16,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,85,c0,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,0c,11,fd,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:f7,cc,b3,90,21,e7,e2,45,ca,dc,d7,5e,42,61,02,52,20,87,dd,3a,c9,1a,
f7,d4,38,7d,8d,70,ed,6d,da,b4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A40E926-9E86-4B89-9CFD-B12311724371}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\UPnP\\UPnPHostConfig"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,00,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,00,00,00,10,21,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,6f,7d,12,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:6a,0c,38,92,08,12,da,be,f6,1f,ed,20,83,d1,4e,9e,08,5c,db,d0,f5,45,
9b,31,59,f0,f4,50,4c,c8,b4,b0
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Shell\\WindowsParentalControls"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,16,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,16,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,40,85,80,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,0c,11,fd,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:88,65,11,e7,de,e4,f4,47,b2,f7,04,a0,40,46,bb,94,2b,d9,bd,a7,61,52,
a1,2b,b0,ae,3d,9b,56,c6,aa,f5
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Defrag\\ScheduledDefrag"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,e8,e6,37,9d,
ef,c4,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,7e,21,42,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,2f,40,17,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:83,6a,0f,9a,79,43,22,0e,6e,69,d4,60,79,28,f3,8f,05,27,87,b2,76,05,
a9,c5,cd,19,df,80,80,48,90,ce
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F5A18EB-DC73-4E45-A11C-B59043598412}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,c0,05,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,c8,bd,db,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:5f,17,41,f0,e3,67,3a,ee,6b,7d,98,3c,db,71,8c,34,64,0a,8c,20,b8,d2,
f6,27,b7,aa,49,1c,12,f1,63,58
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{613612BA-897D-44CE-8DC1-8FC283F9FD51}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Active Directory Rights Management Services Client\\AD RMS Rights Policy Template Management (Automated)"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,c8,85,00,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,6d,72,ff,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:5f,ea,8c,5d,59,0e,39,1f,05,dc,6b,f1,82,ee,76,fa,80,be,1e,c0,3c,9f,
02,43,9f,1a,61,9a,1d,37,1c,bb
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\User Profile Service\\HiveUploadTask"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,40,6a,60,06,
e9,c7,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,c2,21,02,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,b9,72,83,2e,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:22,73,52,40,f6,34,af,52,eb,49,6c,ac,7f,58,e8,5d,9e,d7,af,87,6a,d3,
1d,5a,e4,c1,f5,7c,23,4e,57,28
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72DB7465-BC54-491B-A92A-4637A28C9BBF}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\AppID\\VerifiedPublisherCertStoreCheck"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,16,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,16,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,7e,11,02,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,29,1f,de,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:a8,55,9f,6c,cc,a2,df,09,f1,22,5f,5d,cf,f6,7d,8c,6f,f1,24,fc,5f,85,
dc,df,7f,19,1d,c7,cf,13,ea,de
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Windows Media Sharing\\UpdateLibrary"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,16,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,16,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,40,85,40,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,7a,35,88,2e,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:72,a5,68,3a,40,fa,a2,91,aa,33,cc,4d,d7,1a,02,e9,e6,91,d7,c5,a7,ba,
21,3b,81,7c,75,9f,7d,4e,24,be
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\CertificateServicesClient\\UserTask"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,c0,85,40,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,6d,72,ff,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:db,89,fe,61,b3,8c,f5,41,d5,84,c3,46,12,b8,56,a8,25,ef,9a,28,77,79,
f0,cc,bf,aa,95,a0,18,3e,87,81
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\NetTrace\\GatherNetworkInfo"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,00,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,85,40,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,1c,df,98,2e,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:9e,15,41,71,40,8f,80,e0,d5,ce,b4,d8,f7,75,75,8b,34,5b,3f,d7,05,ad,
0b,30,58,b1,73,28,70,be,80,7f
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\WDI\\ResolutionHost"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,00,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,85,c0,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,7c,40,9b,2e,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:76,78,f2,83,cd,52,82,77,95,1d,59,55,d0,03,19,dc,3e,40,4f,5d,6a,d8,
e0,80,6b,80,dc,78,1e,71,81,ca
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{994C86AD-A929-4B2C-88A0-4E25A107A029}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\SystemRestore\\SR"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,52,21,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,e9,e1,e2,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:a2,28,1a,82,81,4b,04,bf,0a,e2,44,19,91,c4,82,c4,85,9e,a3,bf,f1,9e,
69,5d,72,cd,f0,b8,e2,5a,48,1c
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9979CB83-103A-4105-9E5D-C74B0AF6D198}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\CertificateServicesClient\\UserTask-Roam"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,90,85,00,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,dc,a1,9d,2e,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:f2,ce,6a,b8,c2,2d,cf,17,80,14,18,67,45,5a,46,fa,6d,08,f0,8c,5b,5d,
48,20,02,37,2e,5f,de,05,9b,43
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\WindowsColorSystem\\Calibration Loader"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,91,00,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,cd,d3,01,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:1c,5e,72,cb,82,1b,89,10,81,91,ac,5b,7f,d3,15,7b,5c,ce,04,74,ed,d4,
4c,9d,1c,ec,81,97,87,f2,88,ab
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A48CABBF-24C8-4B87-B00F-9261807C3B43}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\AppID\\PolicyConverter"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,00,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,00,00,00,40,11,02,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,d6,01,7b,2f,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:c6,45,bb,8f,8d,8c,5d,e3,ea,7a,89,3d,78,5b,d9,5f,c0,6f,a4,d7,81,07,
45,fe,4e,78,e3,92,00,9f,ff,b8
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Location\\Notifications"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,16,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,16,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,85,40,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,d6,01,7b,2f,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:e2,ee,c5,dc,63,8b,16,a8,dc,f4,e8,3a,35,14,f2,8d,c7,ff,b5,ca,04,85,
41,76,d2,52,d9,09,5c,29,b3,43
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Application Experience\\AitAgent"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,04,c5,1f,53,
09,c8,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,7e,21,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,57,87,84,2f,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:9a,13,ff,7f,b5,4c,92,12,aa,c3,66,3a,ee,28,89,a6,af,b0,ba,68,98,ab,
c3,f9,a8,11,e6,21,69,87,b8,33
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC668097-4D6B-4093-AC14-014C09DBF820}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Ras\\MobilityManager"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,16,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,16,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,40,05,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,98,cf,92,2f,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:47,2f,2f,6e,40,d8,84,58,d9,2b,94,6c,81,ba,92,25,d6,3c,0b,d0,45,fb,
ab,63,ca,ef,19,04,bc,35,ba,73
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\PerfTrack\\BackgroundConfigSurveyor"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,10,21,82,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,f9,30,95,2f,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:8a,4b,c3,fb,22,e9,43,ed,e5,a9,84,56,cc,af,34,53,d4,dd,d6,13,d1,a3,
26,50,17,96,7a,bc,8c,77,9e,7d
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE669C13-8165-4536-96D0-6D6C39292AAE}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Diagnosis\\Scheduled"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,68,b6,94,02,
d0,c3,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,72,89,c0,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,41,9a,dc,2f,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:82,eb,d6,01,08,50,0f,cd,35,7b,f2,8c,ce,59,52,ef,b6,ff,94,3b,38,e8,
25,0a,3a,f3,45,07,c6,16,2f,ae
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C016366B-7126-46CA-B36B-592A3D95A60B}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,c0,5b,5d,c3,
d0,c3,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,40,21,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,02,5d,e1,2f,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:55,5c,d3,77,ba,0a,05,32,a5,63,0e,be,96,ae,9d,b1,84,3e,64,2b,2a,15,
ba,07,c4,0c,8b,67,be,00,e8,7f
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Registry\\RegIdleBackup"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,c0,76,40,09,
4c,c8,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,4e,20,c2,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,a8,1c,18,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:ae,0d,b2,f3,1a,30,b2,08,e0,c5,0e,f6,4c,29,94,8a,82,86,12,ac,60,5c,
a8,f6,b3,e4,2f,51,ea,6c,09,e1
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\RemoteAssistance\\RemoteAssistanceTask"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,28,11,c2,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,08,7e,1a,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:40,f4,a1,b4,cb,f3,46,72,0b,7a,18,6a,ae,91,2f,ce,a1,fb,e0,dd,82,f4,
8f,51,fc,b9,ad,1a,76,bf,25,25
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\MemoryDiagnostic\\CorruptionDetector"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,a0,c0,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,68,df,1c,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:39,d0,b0,4f,35,6d,f6,65,0e,07,60,76,25,5c,e2,6c,e2,75,91,42,87,40,
c7,59,24,1d,2b,1a,ee,37,f6,12
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0250F3F-6480-484F-B719-42F659AC64D5}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,16,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,16,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,40,85,40,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,2d,35,04,2d,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:6e,b7,d5,0a,0f,0e,81,3e,f3,90,52,14,6b,2a,b5,86,92,ed,68,d8,2e,0e,
8e,73,30,43,ec,c9,33,4d,16,d1
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Autochk\\Proxy"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,42,21,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,4a,43,e5,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:02,e6,03,f0,f0,b9,82,21,f0,70,dd,81,a8,8b,3d,b6,7c,e5,da,31,5b,c5,
68,42,37,32,f9,ee,d1,5f,3f,79
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Maintenance\\WinSAT"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,31,f8,01,00,00,00,00,00,28,3b,a2,11,
4c,c8,01,00,31,f8,01,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,3a,a1,40,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,c9,40,1f,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:9b,40,05,4f,df,c9,71,dd,00,55,1e,a1,f0,55,1c,c9,b9,9c,1e,38,23,ca,
4b,ac,18,0d,f0,aa,81,ad,3e,b1
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,00,f2,32,fa,
cf,c3,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,40,21,82,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,29,a2,21,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:fd,59,aa,8f,a7,e6,d6,c6,81,94,51,35,c9,9b,ce,ac,82,f3,db,23,b0,37,
25,3c,8d,ad,16,17,f5,c5,e4,25
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStartTypeChange"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,10,c2,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,29,a2,21,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:cd,35,89,98,7e,9b,5e,1e,6b,4e,ec,84,9a,5a,db,be,ec,ea,05,cb,35,bb,
86,b0,7a,c6,6c,40,29,eb,0d,6d
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3163C33-301D-4730-A266-5518C5ED3967}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Bluetooth\\UninstallDeviceTask"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,00,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,00,00,00,10,05,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,89,03,24,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:90,a6,90,3c,07,9d,e7,96,e0,b7,2c,7c,3b,74,0e,a1,ad,65,58,83,df,0a,
c5,46,8e,3e,b7,03,11,b7,e7,f7
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\RAC\\RacTask"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,40,21,c2,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,89,03,24,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:e5,98,79,e1,ff,87,cb,7d,11,14,26,64,c9,19,e0,ad,f6,1f,5a,96,87,d6,
97,c3,f1,c2,04,fa,4c,56,e3,03
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB02381F-D652-4B1C-894A-712498C62C51}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\MUI\\LPRemove"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,12,21,42,03,48,48,\
"DynamicInfo"=hex:03,00,00,00,4a,43,e5,2c,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:47,d4,5b,03,1c,19,94,b3,9c,49,ef,36,d6,fe,80,fb,ec,11,1f,7d,6e,f3,
e2,82,47,6e,f5,d7,7e,09,7d,ab
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\MemoryDiagnostic\\DecompressionFailureDetector"
"Triggers"=hex:15,00,00,00,00,00,00,00,00,1c,24,fb,fe,07,00,00,00,00,00,00,00,
00,00,00,00,1c,24,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,a0,c0,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,e9,64,26,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:cb,b1,2f,1e,d1,29,86,18,18,01,a3,65,a6,f7,50,01,d3,1d,2b,b3,cf,74,
41,ba,85,41,89,42,67,d4,cc,42
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB3C354D-297A-4EB2-9B58-090F6361906B}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,30,11,8b,3b,
4c,c8,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,42,21,42,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,aa,27,2b,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:94,23,b2,65,cb,ab,42,6f,81,67,2f,08,4e,7d,98,66,f6,85,d9,83,b6,22,
24,71,2f,f0,db,c4,ff,ef,e3,74
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}]
@DACL=(02 0000)
"Path"="\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask"
"Triggers"=hex:15,00,00,00,00,00,00,00,01,12,72,fb,fe,07,00,00,00,2c,71,03,e3,
0b,c9,01,00,12,72,fb,fe,07,00,00,ff,ff,ff,ff,ff,ff,ff,ff,52,21,c2,02,48,48,\
"DynamicInfo"=hex:03,00,00,00,aa,27,2b,30,41,04,ca,01,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
"Hash"=hex:ae,b0,3f,1b,c1,69,23,6f,2c,3b,f0,19,f9,d9,ed,3c,21,3d,1e,4a,56,8f,
8c,67,f1,fc,3f,2e,c0,86,49,a6
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
e:\programme\AntiVir\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\avmwlanstick\WlanNetService.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\MPC Cleaner\MPCTray.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2016-05-29 21:28:48 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2016-05-29 19:28
.
Vor Suchlauf: 11 Verzeichnis(se), 19.808.579.584 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 19.806.445.568 Bytes frei
.
- - End Of File - - 77B9340C0F2BEA71407F34357BC682FD --- --- --- |